PSI Services LLC logo
PSI Services LLC
Posted 1 day agoVerified live 13h ago

Federal Vulnerability Mgmt & App Security Engineer (US Citizen)

Brief overview

Remote
UndergradOr in progress
$125k/yrStated minimum
3+ yrsMinimum
Application SecurityVulnerability ManagementSASTDASTSoftware Composition Analysis (SCA)OWASP Top 10Threat ModelingCI/CD Pipeline IntegrationSecure Application DevelopmentInformation Security Risk MeasurementNIST CSF/800-53ISO 27001Vulnerability ScanningCyber Threat Intelligence

About the company

PSI Services LLC logo
PSI Services LLCpsiexams.com

PSI has over 70 years of experience providing worldwide testing solutions to corporations, federal and state government agencies, professional associations, certifying bodies and leading academic institutions.

Job description

Summary

PSI Services LLC provides workforce solutions that combine technology and science to support testing and certification journeys. The Federal Vulnerability Management and Application Security Engineer will identify, assess, and reduce security risk across infrastructure, cloud, and application environments while managing vulnerability and application security programs. The role partners with engineering, DevOps, and product teams to embed security into the SDLC, improve remediation, and meet security and compliance requirements.

Responsibilities

  • Drive continuous improvements in vulnerability management processes and tools by leveraging industry-leading technologies, automation, and data-driven insights
  • Stay current on industry trends, emerging threats and best practices in vulnerability management and adapt the program accordingly
  • Evaluate and recommend vulnerability management tools and technologies, ensuring the optimal balance of effectiveness and efficiency
  • Develop and deliver regular metrics, reports, KPIs and presentations to executive leadership and key stakeholders, communicating the status and effectiveness of the vulnerability management program
  • Assist in building a diverse vulnerability management program that covers secure software development lifecycle, patch governance, and application security
  • Perform technical threat/risk and vulnerability assessments and manage vulnerabilities throughout their lifecycle
  • Provide support and maintain tools required for the vulnerability management program
  • Provide consultative support to operational teams on how to fix identified vulnerabilities
  • Own and evolve the Application Security program, integrating findings into the broader vulnerability management lifecycle
  • Perform and oversee application security assessments, including static (SAST), dynamic (DAST), software composition analysis (SCA), and manual secure code reviews where appropriate
  • Partner with development and DevOps teams to embed security into the SDLC, including CI/CD pipeline integrations and secure design reviews
  • Define and maintain application risk prioritization that considers exploitability, business impact, data sensitivity, and threat context
  • Review application architectures and threat models to proactively identify design-level security weaknesses
  • Establish and maintain secure coding standards aligned to OWASP Top 10 and industry best practices
  • Triage, validate, and manage application vulnerabilities through remediation and verification
  • Enable developer success through consultative AppSec support, clear remediation guidance, and security-by-design recommendations

Skills

  • Strong understanding of information security risk measurement (qualitative and quantitative) to support effective prioritization
  • Working knowledge of industry security frameworks and standards (e.g., NIST CSF/800-53, ISO 27001, OWASP)
  • Ability to correlate threat intelligence with vulnerability and application risk
  • Solid understanding of **secure application development**, including common programming languages, frameworks, and architectural patterns
  • Hands-on experience with **Application Security testing methodologies**, including:
  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Software Composition Analysis (SCA)
  • Familiarity with **OWASP Top 10**, API Security Top 10, and common application attack patterns
  • Experience integrating security scanning tools into **CI/CD pipelines**
  • Ability to perform **threat modeling** and design-level security assessments
  • Strong understanding of authentication, authorization, session management, and data protection controls within applications
  • Expertise in vulnerability management programs, including lifecycle management and remediation governance
  • Experience with vulnerability scanning and reporting tools (e.g., Qualys, Tenable, CrowdStrike, or equivalent)
  • Familiarity with cyber threat intelligence services and the application of threat data to prioritization decisions
  • Broad technical knowledge of networks, operating systems, cloud platforms, and web applications
  • 3+ years of combined experience in cybersecurity, application security, or vulnerability management
  • Ability to pass an IRS Clearance and Background Check REQUIRED
  • Prior experience working closely with software engineering or DevOps teams is strongly preferred

Qualifications

Must Haves

  • Strong understanding of information security risk measurement (qualitative and quantitative) to support effective prioritization
  • Working knowledge of industry security frameworks and standards (e.g., NIST CSF/800-53, ISO 27001, OWASP)
  • Ability to correlate threat intelligence with vulnerability and application risk
  • Solid understanding of **secure application development**, including common programming languages, frameworks, and architectural patterns
  • Hands-on experience with **Application Security testing methodologies**, including:
  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Software Composition Analysis (SCA)
  • Familiarity with **OWASP Top 10**, API Security Top 10, and common application attack patterns
  • Experience integrating security scanning tools into **CI/CD pipelines**
  • Ability to perform **threat modeling** and design-level security assessments
  • Strong understanding of authentication, authorization, session management, and data protection controls within applications
  • Expertise in vulnerability management programs, including lifecycle management and remediation governance
  • Experience with vulnerability scanning and reporting tools (e.g., Qualys, Tenable, CrowdStrike, or equivalent)
  • Familiarity with cyber threat intelligence services and the application of threat data to prioritization decisions
  • Broad technical knowledge of networks, operating systems, cloud platforms, and web applications
  • 3+ years of combined experience in cybersecurity, application security, or vulnerability management
  • Ability to pass an IRS Clearance and Background Check REQUIRED

Nice to Haves

  • Prior experience working closely with software engineering or DevOps teams is strongly preferred

Benefits

  • 401(k), pension, or country-specific retirement plans with employer contributions
  • Enhanced paid time off/annual leave policies
  • Medical insurance tailored to your region
  • US: Dental, vision, life, and short-term disability insurance
  • Flexible Spending Accounts (US)
  • Employee Assistance Program (EAP): Confidential support whenever you need it
  • Work-Life Balance: We understand life happens outside of work, and we fully support flexibility
  • Regular global wellness initiatives to help you stay healthy and inspired
  • Tools and support to help you grow personally and professionally
  • A Volunteer Day each year and opportunities to support our communities and industry

More jobs like this