Talent.com
Security Specialist / Application Security Lead
Security Specialist / Application Security LeadZantech • Camp Springs, Maryland, United States
Security Specialist / Application Security Lead

Security Specialist / Application Security Lead

Zantech • Camp Springs, Maryland, United States
[job_card.30_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

Are you looking for your next challenge? Are you ready to work with a performance-based small company? At Zantech, we are a dynamic Woman Owned Small Business focused on providing complex, mission-focused solutions with a proven track record of outstanding customer performance and high employee satisfaction. We would love to talk with you regarding the next step in your career. Come join our team!

Zantech is looking for a talented Security Specialist / Application Security Lead to contribute to the success of our upcoming Applied and Emerging Technology Support project for a Hybrid role based out of Camp Springs, MD.

The Security Specialist / Application Security Lead provides expert application security leadership, ensuring secure software delivery through integrated security controls, vulnerability management, and Zero Trust architecture implementation. This role leads Security Engineers and Security Champions in embedding security throughout the software development lifecycle and collaborates with the DevSecOps Lead to implement automated security testing in CI/CD pipelines.

Responsibilities include, but will not be limited to:

  • Application Security Strategy & Architecture
    • Establish and maintain application security standards and best practices for USCIS OIT
    • Define security controls and gates for integration within CI/CD pipelines
    • Design Zero Trust architecture implementations covering identity, workload, network, and data protection
  • Security Integration in CI/CD Pipelines
    • Lead integration of SAST and DAST tools
    • Implement container security scanning and vulnerability management (Aqua Security, Snyk)
    • Establish Infrastructure as Code (IaC) security scanning and policy enforcement
    • Integrate secrets management (HashiCorp Vault) and secure credential handling
  • Vulnerability Management & Threat Assessment
    • Identify threats and measure potential vulnerabilities in systems, applications, and services
    • Conduct security assessments and coordinate penetration testing
    • Track vulnerability remediation SLAs and metrics
  • Zero Trust Architecture Implementation
    • Implement Zero Trust principles across Applications and Workloads realm
    • Design and validate identity-based access controls (Okta, AWS IAM)
    • Establish micro-segmentation and workload isolation patterns
  • Policy-as-Code & Compliance Automation
    • Implement policy-as-code using Open Policy Agent (OPA)
    • Automate enforcement of security and compliance controls
    • Support ATO/Continuous Authorization processes with automated security control validation

Required Experience or Knowledge of the following technologies/functions:

Experience:

  • Minimum 10 years of IT engineering experience
  • Minimum 5 years in DevSecOps, DevOps, or Platform Engineering roles
  • Minimum 3 years of federal government experience, preferably DHS or civilian agencies
  • Demonstrated experience designing and implementing enterprise CI/CD solutions
  • Experience with cloud-native application development and deployment
  • Track record of successful DevSecOps transformations in complex enterprise environments

Technical Skills (Required):

  • Expert-level knowledge of CI/CD tools (Jenkins, GitLab CI/CD, GitHub Actions, or similar)
  • Deep expertise with container orchestration platforms (Kubernetes, OpenShift, EKS, ECS)
  • Advanced proficiency with Infrastructure-as-Code tools (Terraform, CloudFormation, Ansible)
  • Strong scripting abilities (Python, Bash, PowerShell, Go)
  • Extensive experience with AWS cloud services (EC2, S3, Lambda, RDS, VPC, IAM, etc.)
  • Expert knowledge of Git workflows and version control strategies
  • Proficiency with security scanning tools (SonarQube, Veracode, Checkmarx, Twistlock, Aqua)
  • Experience with monitoring and observability tools (Prometheus, Grafana, ELK Stack, Datadog, Splunk)

Technical Skills (Highly Desired):

  • Experience with service mesh technologies (Istio, Linkerd)
  • Knowledge of policy-as-code tools (OPA, Kyverno, Sentinel)
  • Familiarity with Backstage.io (especially relevant for USCIS Backstage)
  • Experience with API gateway and management solutions
  • Knowledge of secrets management tools (Vault, AWS Secrets Manager)
  • Understanding of software bill of materials (SBOM) and supply chain security

Federal & DHS-Specific Knowledge:

  • Understanding of Zero Trust Architecture principles and implementation
  • Knowledge of FedRAMP, FISMA, and NIST frameworks (800-53, 800-171)
  • Familiarity with DHS security requirements and authorization processes
  • Understanding of Section 508 compliance requirements
  • Experience with AWS GovCloud and FedRAMP-authorized services
  • Knowledge of continuous ATO (cATO) processes

Technical Skills:

  • Expert: SAST/DAST tools (Checkmarx, Fortify, SonarQube, Burp Suite, OWASP ZAP)
  • Expert: Container scanning (Aqua Security, Snyk, Twistlock)
  • Expert: AWS Security services (Security Hub, GuardDuty, Config, IAM)
  • Proficient: Open Policy Agent, HashiCorp Vault, Okta
  • Proficient: Kubernetes security, Zero Trust architecture
  • Knowledge: NIST 800-53, OWASP Top 10, FedRAMP

Preferred Experience or Knowledge of the following technologies/functions:

USCIS-Specific Experience (Highly Desired):

  • Experience with DHS or USCIS security requirements and controls
  • Hands-on experience with DHS security authorization processes (ATO/Continuous Authorization)
  • Understanding of immigration data sensitivity and PII protection requirements

Required Education/Certifications:

  • Bachelor's degree in Computer Science, Cybersecurity, Information Assurance, or related field
  • Master's degree preferred
  • Certifications (Recommended - Minimum 1)
    • Certified Information Systems Security Professional (CISSP)
    • AWS Certified Security - Specialty
    • Certified Cloud Security Professional (CCSP)
    • CEH, OSCP, GWAPT, CSSLP (desired)

Required Security Clearance:

  • US Citizenship and the ability to obtain and maintain an active Public Trust or higher clearance, per contract requirements.

Outstanding Performance…Always!”

Our corporate motto represents our commitment to build long-term relationships with both our clients and our employees by providing the highest quality service in everything we do. We strive for excellence for our clients and for each other. We embrace the opportunity to hire individuals with new talents and fresh perspectives. Zantech offers competitive compensation, strong benefits, and a vacation package, as well as a fast-paced and exciting work environment. Come join our team!

[job_alerts.create_a_job]

Security Specialist / Application Security Lead • Camp Springs, Maryland, United States

[internal_linking.similar_jobs]

Healthcare Technology Consulting - IT Security Lead

GuidehouseWashington, DC, United States
[job_card.full_time]

Healthcare Technology Consulting - IT Security Lead.Healthcare Technology Consulting - IT Security Lead.Be among the first 25 applicants.Get AI-powered advice on this job and more exclusive feature...[internal_linking.show_more]

 • [job_card.promoted]

Program Analyst - Security Cooperation

Essnova SolutionsWashington, DC, United States
[job_card.full_time]

The Program Analyst shall analyze existing US military and Republic of Singapore (RoS) defense and capability requirements, identify/assess alternative sustainment and enhancement strategies, provi...[internal_linking.show_more]

 • [job_card.promoted]

Mission-Centric ISSE: Security Architecture & RMF

Spry Methods, Inc.Washington, DC, United States
[job_card.full_time]

A leading cybersecurity firm in Washington, DC is seeking an Information Systems Security Engineer (ISSE) to enhance mission-focused systems in a government setting.The ISSE will design and maintai...[internal_linking.show_more]

 • [job_card.promoted]

Industrial Security Specialist

PalantirWashington, DC, United States
[job_card.full_time]

Palantir builds the world's leading software for data-driven decisions and operations.By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving ...[internal_linking.show_more]

 • [job_card.promoted]

AWS Security Engineer

Mfinite Consulting LLCAdelphi, MD, United States
[job_card.full_time]

Mfinite Consulting is seeking an AWS Security Engineer to support our client by ensuring the security of its AWS cloud infrastructure and applications.This critical role involves designing, impleme...[internal_linking.show_more]

 • [job_card.promoted]

Space Policy Security and Procedures Oversight and Implementation Analyst

System High CorporationWashington, DC, United States
[job_card.full_time]

Space Policy Security and Procedures Oversight and Implementation Analyst.System High Corporation delivers the most advanced protection and secrecy solutions to secure and strengthen critical missi...[internal_linking.show_more]

 • [job_card.promoted]

Application Security - Provisioning Solution Architect (US CITIZEN)

Diligent Consulting IncDC, US
[job_card.full_time]
[filters_job_card.quick_apply]

MUST HAVE IT-II CERT (IE SECURITY+) As the Application Security/Provisioning Solution Architect, you will lead the design and implementation of a comprehensive security architecture that spans mult...[internal_linking.show_more]

Application Security Engineer - Public Trust/Secret Clearance

TOMORROW HIREWashington, DC, US
[filters.remote]
[job_card.full_time]
[filters_job_card.quick_apply]

Public Trust, Secret Clearance preferred.The Application Security Engineer will support the secure development and testing of applications by leveraging specialized tools, implementing security con...[internal_linking.show_more]

Store Security Specialist

Wegmans Food MarketsWASHINGTON D.C., DC, United States
[job_card.full_time]

Morning, Afternoon, Evening (Includes Weekends).EARN A BONUS UP TO $2,500! Hiring immediately!.At Wegmans, our store security teams are committed to keeping our customers and employees safe.Our sec...[internal_linking.show_more]

 • [job_card.promoted] • [job_card.new]

Federal IT Security Lead - CPIC PMO

Integral Federal, Inc.Washington, DC, United States
[job_card.full_time]

A leading cybersecurity firm is seeking an IT Security Manager to oversee the security posture and compliance of GSA applications.You will manage security assessments, coordinate documentation, and...[internal_linking.show_more]

 • [job_card.promoted]

Security Engineer

TekSynapWashington, DC, United States
[job_card.full_time]

Be among the first 25 applicants.Responsibilities & Qualifications.Manage vulnerability scanning, remediation, and POA&M tracking.Support FISMA and NIST SP 800-53 compliance reviews.Implement SIEM ...[internal_linking.show_more]

 • [job_card.promoted]

Federal Security Sales Specialist, Google Public Sector

GoogleWashington, DC, United States
[job_card.full_time]

Federal Security Sales Specialist, Google Public Sector.As a Public Sector Security Sales Specialist, you will help Google grow the cyber security business by building and expanding relationships w...[internal_linking.show_more]

 • [job_card.promoted]

COMSEC Information Security Specialist

MANTECHWashington, DC, United States
[job_card.full_time]

COMSEC Information Security Specialist.Responsibilities include but are not limited to:.Responsible for applying Information Assurance expertise and knowledge to network and/or enterprise security....[internal_linking.show_more]

 • [job_card.promoted]

16 Yrs Information Assurance and Security Specialist

AHU Technologies IncWashington, DC, United States
[job_card.full_time]

Role : Information Assurance and Security Specialist – Master.Identify network problems, and recommend improvements to ensure optional performance;.Ability to monitor and analyze data traffic patte...[internal_linking.show_more]

 • [job_card.promoted]

Lead Security Consultant - Security Assessments

JENSEN HUGHESRockville, MD, United States
[job_card.full_time]

Lead Security Consultant - Security Assessments.Throughout our worldwide network of experts, clients and communities, we are renowned for our leadership in fire protection engineering a legacy of r...[internal_linking.show_more]

 • [job_card.promoted]

Identity & Application Security Leader — Hybrid

PowerToFlyWashington, DC, United States
[job_card.full_time]

A leading consulting firm is seeking an Application Security Manager to lead security solutions in a hybrid environment.This role involves overseeing identity and access management solutions, trans...[internal_linking.show_more]

 • [job_card.promoted]

Security Specialist, SSO with Top Secret & SCI Poly

Advantage SCIWashington, DC, United States
[job_card.full_time]

A security services company is seeking a Security Specialist to join its team in Washington, D.The ideal candidate will have 3-5 years of relevant experience and must possess a Top Secret clearance...[internal_linking.show_more]

 • [job_card.promoted]

Senior Application Security Engineer (WAF) 3956

Tier4 GroupWashington, DC, United States
[job_card.full_time] +1

Senior Application Security Engineer (WAF) 3956.Get AI-powered advice on this job and more exclusive features.Direct message the job poster from Tier4 Group.Greater DC Area (2 days per week onsite ...[internal_linking.show_more]