Veilant is seeking an Application Security Engineer to join the InfoSec team and help validate, secure, and continuously improve software developed by internal and partner engineering teams. This role blends a software engineering foundation with an attacker mindset to review releases before deployment, identify and validate vulnerabilities, create proof-of-concept demonstrations, and provide practical remediation guidance that developers can act on. You will work closely with engineering teams to understand application architecture, business logic, user workflows, data sensitivity, and production environments to ensure findings are accurate and actionable. You will collaborate across Veilant's software, DevSecOps, and infrastructure teams. Your responsibilities include auditing releases, analyzing source code for vulnerabilities, building PoCs, contextualizing findings, and delivering remediation guidance; intercepting and analyzing application-layer network traffic with Burp Suite or equivalent tools; assessing REST APIs, SQL databases, PostgreSQL, JWT/OAuth, identity providers, and token-based authentication; performing threat modeling; improving DevSecOps pipelines with SAST, DAST, SCA, IaC scanning, secrets detection, and container security tooling; supporting container runtime security with tools like Falco or NeuVector; and creating standardized security reports for both engineering teams and executives. Remote work is available, with Tysons, Virginia, United States as the location.
Veilant is seeking an Application Security Engineer to join the InfoSec team and help validate, secure, and continuously improve software developed by internal and partner engineering teams. This role blends a software engineering foundation with an attacker mindset to review releases before deployment, identify and validate vulnerabilities, create proof-of-concept demonstrations, and provide practical remediation guidance that developers can act on. You will work closely with engineering teams to understand application architecture, business logic, user workflows, data sensitivity, and production environments to ensure findings are accurate and actionable. You will collaborate across Veilant's software, DevSecOps, and infrastructure teams. Your responsibilities include auditing releases, analyzing source code for vulnerabilities, building PoCs, contextualizing findings, and delivering remediation guidance; intercepting and analyzing application-layer network traffic with Burp Suite or equivalent tools; assessing REST APIs, SQL databases, PostgreSQL, JWT/OAuth, identity providers, and token-based authentication; performing threat modeling; improving DevSecOps pipelines with SAST, DAST, SCA, IaC scanning, secrets detection, and container security tooling; supporting container runtime security with tools like Falco or NeuVector; and creating standardized security reports for both engineering teams and executives. Remote work is available, with Tysons, Virginia, United States as the location.
Track similar jobs
Get email alerts when new roles like this are posted.
Based on: Application Security Engineer
See how this role matches your resume
Sign in to get an AI match score and personalized feed.
Track similar jobs
Get email alerts when new roles like this are posted.
Based on: Application Security Engineer
See how this role matches your resume
Sign in to get an AI match score and personalized feed.