Application Security Engineer

Client Office: Bethesda, MD, United States

Guidehouse

Guidehouse is the only scaled advisory organization in the world to fully integrate commercial and public or government businesses within each of our industry segments because complex problems require both perspectives to address and outwit.

View all jobs at Guidehouse

Apply now Apply later

Job Family:

IT Cyber Security (Digital)


Travel Required:

Up to 10%


Clearance Required:

Ability to Obtain Public Trust

We are seeking a highly experienced and strategic Application Security Engineer to support the OCCS program at the National Library of Medicine (NLM). This role is critical to advancing the security posture of high-impact applications and ensuring alignment with modern security frameworks and federal compliance standards. The ideal candidate will bring deep technical expertise, leadership in secure development practices, and a proven track record of supporting federal health IT environments.

What You Will Do:

  • Lead the application security program using a shift-left approach to embed security early in the SDLC.
  • Conduct static and dynamic code analysis, penetration testing, and vulnerability assessments.
  • Integrate and maintain security tools within CI/CD pipelines to reduce vulnerabilities and improve developer efficiency.
  • Collaborate with DevOps, cloud, and engineering teams to implement secure-by-default frameworks and hardening standards.
  • Advise senior leadership on strategic initiatives including TIC 3.0, Zero Trust Architecture, and secure use of Generative AI.
  • Utilize AWS WAF and other layered defenses to protect cloud-hosted applications.
  • Evaluate and implement application security tools and best practices aligned with OWASP, SANS-25, and NIST guidance.
  • Support compliance efforts including PCI-DSS, NIST 800-53, and ISO 27001.


What You Will Need:

  • Minimum if EIGHT (8) years of experience in software engineering and application security in enterprise environments.
  • Minimum of FIVE (5) years of experience using Tenable Security Center and validating vulnerabilities.
  • Bachelor’s degree in Computer Science, Information Systems, or related field with formal training in software security.
  • Proven experience addressing web and mobile application security issues (OWASP Top 10, SANS-25).
  • Hands-on experience with application scanning tools like Checkmark, NetSparker
  • Experience with cloud platforms (AWS, Azure, GCP), DevSecOps, and modern security tooling.
  • Hands-on experience with secure coding in Java, Python/Django, PHP.
  • Strong knowledge of securing applications integrated with Oracle, Postgres SQL and MS SQL Server.
  • Experience with manual and automated testing tools (e.g., BurpSuite Pro, Fiddler, ZAP).
  • Familiarity with Linux and Windows environments, middleware (Apache, Tomcat, IIS), and database security.
  • Deep understanding of OWASP code review, ASVS, and secure SDLC practices.


What Would Be Nice To Have:

  • Experience supporting NIH, NLM, or other federal health IT programs.
  • Recognized certifications: CISSP, CSSLP, CISM, CEH, eWPTX, eCPPT.
  • Strong communication and documentation skills with experience presenting to senior leadership.

The annual salary range for this position is $130,000.00-$216,000.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs.


What We Offer:

Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.

Benefits include:

  • Medical, Rx, Dental & Vision Insurance

  • Personal and Family Sick Time & Company Paid Holidays

  • Parental Leave

  • 401(k) Retirement Plan

  • Group Term Life and Travel Assistance

  • Voluntary Life and AD&D Insurance

  • Health Savings Account, Health Care & Dependent Care Flexible Spending Accounts

  • Transit and Parking Commuter Benefits

  • Short-Term & Long-Term Disability

  • Tuition Reimbursement, Personal Development, Certifications & Learning Opportunities

  • Employee Referral Program

  • Corporate Sponsored Events & Community Outreach

  • Care.com annual membership

  • Employee Assistance Program

  • Supplemental Benefits via Corestream (Critical Care, Hospital Indemnity, Accident Insurance, Legal Assistance and ID theft protection, etc.)

  • Position may be eligible for a discretionary variable incentive bonus

About Guidehouse

Guidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.

Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.

If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.

All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com.  Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse.  Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.

If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties.

Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.

Apply now Apply later
Job stats:  0  0  0

Tags: Application security AWS Azure Banking Burp Suite CEH CI/CD CISM CISSP Clearance Clearance Required Cloud Code analysis Compliance Computer Science CSSLP DevOps DevSecOps Django eWPTx GCP Generative AI ISO 27001 Java Linux MSSQL NIST NIST 800-53 Oracle OWASP Pentesting PHP PostgreSQL Python SANS SDLC SQL SQL Server Tomcat Vulnerabilities Windows Zero Trust

Perks/benefits: Career development Competitive pay Flexible spending account Health care Insurance Medical leave Parental leave Salary bonus Startup environment Team events

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.