{"id":1634676,"url":"https://alion.io/job/decisionpoint-application-security-engineer","title":"Application Security Engineer","company":{"id":2982024,"name":"Decisionpoint","domain":"decisionpoint.com","url":"https://alion.io/company/decisionpoint-com","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"iCIMS","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"posting_text","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":[],"countries":[],"hiring_countries":["US"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":122000,"max_usd":222000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":220},"experience_years_min":7,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"CI/CD","optional":false},{"name":"Kubernetes","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Threat Modeling","optional":false}],"status":"live","first_seen_at":"2026-10-01T21:32:28Z","employer_posted_date":"2026-10-01","last_verified_at":"2026-10-01T21:32:28Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"Overview\nDecisionPoint seeks an Application Security Engineer to perform advanced application-layer security assessments, secure coding reviews, vulnerability analysis, and security integration for enterprise applications supporting a federal and DoD-aligned mission environment. This role ensures secure development practices across CMS components, APIs, integrations, CI/CD pipelines, and custom code.\nThe Application Security Engineer supports secure coding standards, threat modeling, static and dynamic testing, and secure secrets management. This position plays a critical role in strengthening application-level defenses, reducing vulnerabilities, and ensuring mission systems meet stringent DoD security requirements.\nThis position is fully remote.\nDuties & Responsibilities\nThe Application Security Engineer will:\nConduct secure code reviews, focusing on application logic, API endpoints, CMS modules, and backend integrations. \nPerform API security assessments to validate authentication, authorization, data handling, and boundary protections. \nSupport CMS hardening by reviewing templates, modules, configurations, and custom components for secure implementation. \nIntegrate security requirements into CI/CD pipelines including SAST/DAST tools, dependency scanning, and automated controls. \nManage secrets handling, encryption policies, and secure storage of API keys, tokens, and credentials. \nConduct static and dynamic application security testing, vulnerability assessments, and remediation validation. \nProvide secure coding guidance to developers, architects, and product teams. \nWork with DevSecOps and cloud engineers to ensure secure build and deployment patterns. \nPerform threat modeling and recommend mitigations for high-risk application features. \nReview and validate authentication flows, SSO integrations, and identity-related protections. \nAssist with security documentation including test results, remediation plans, and secure configuration records. \nSupport continuous monitoring, log analysis, and triage of application-layer security alerts. \nParticipate in sprint teams, code review cycles, and architecture discussions to embed security early. \nQualifications\nClearance Requirement\nMust hold an active Top Secret clearance, supported by a Tier 5 background investigation.\nEducation (Required)\nBachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related technical field.\nExperience (Required)\nMinimum 7 years of experience in application security engineering, secure software development, or cybersecurity. \nExperience conducting code reviews, application penetration testing, or API security testing. \nExperience with static and dynamic testing tools, dependency scanning, and software composition analysis. \nExperience supporting secure CI/CD pipeline integration and DevSecOps practices. \nExperience implementing secure secrets management, encryption, and authentication protections. \nTechnical Knowledge (Required)\nStrong understanding of OWASP Top 10, secure coding principles, and application-layer attack vectors. \nExperience with SAST/DAST tools, dependency scanners, and code review workflows. \nKnowledge of API security, token-based authentication, and secure data handling. \nFamiliarity with CMS structures, template security, and module-level risk considerations. \nUnderstanding of identity and access management, certificate management, and secure authentication flows. \nTechnical Knowledge (Preferred)\nExperience with AWS cloud-native application security tools. \nFamiliarity with container security, Kubernetes workload protections, and microservices security. \nExperience with modern CI/CD platforms and DevSecOps automation. \nCertifications\nRequired:\nSecurity+ or CISSP or CCSP \nPreferred:\nAWS Security Specialty \nGIAC secure coding or cloud security certifications \nCertified Ethical Hacker (CEH) \nSkills\nStrong analytical and problem-solving skills for identifying and remediating application-layer vulnerabilities. \nAbility to clearly communicate technical risks, secure coding guidance, and remediation recommendations. \nStrong attention to detail when reviewing code, configurations, and test results. \nAbility to work collaboratively with developers, cloud engineers, PMO staff, and mission stakeholders. \nCommitment to integrating security early and continuously throughout the development lifecycle. \nOur Equal Employment Opportunity Policy\nEEO and Affirmative Action Policy: DecisionPoint Corporation is an Equal Employment Opportunity and Affirmative Action employer. It is the policy of DecisionPoint Corporation to provide equal employment opportunity in accordance with all applicable Equal Employment Opportunity/Affirmative Action laws, directives and regulations to all employees and qualified applicants without regard to race, ethnicity, color, religion, national origin, sex, age, disability status, pregnancy, sexual orientation, gender identity, genetic information, protected veteran status, or any other protected status under Federal, State or Local laws.\n Pay Transparency Policy: In accordance with Presidential Executive Order 13665, DecisionPoint Corporation will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information.\n Authorization to Share Resume and Personal Information: By expressing your interest and submitting your resume for this position, you authorize DecisionPoint Corporation to share your resume, as well as personal information included on the resume, with its subsidiaries, affiliates and teaming partners for the purpose of considering you for this position and other available positions requiring comparable skills, education and experience. Should DecisionPoint Corporation. or its affiliates and teaming partners wish to initiate pre-employment discussions, you will be asked to complete an employment application and related employment documents.","description_format":"text","description_chars":6564,"description_truncated":false,"requirements":{"experience_years_min":7,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":true,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security"],"lifecycle":[{"event":"open","at":"2026-10-01T21:32:28Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":30,"reasons":["conf:5","win:early","comp:brand"],"computed_at":"2026-10-02T03:15:14Z"},"pay":null,"html_url":"https://alion.io/job/decisionpoint-application-security-engineer","json_url":"https://alion.io/job/decisionpoint-application-security-engineer.json","meta":{"generated_at":"2026-10-02T03:15:14Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4434,"day_limit":5000,"remaining_today":566,"minute_limit":60,"resets_at":"2026-10-03T00:00:00Z"}}}