← all jobs

[Remote] Lead Application Security Engineer

Work from home Full-time role Hiring

Note: The job is a remote job and is open to candidates in USA. phia, LLC is a Northern Virginia based small business focused on Cyber Intelligence and Cyber Security. They are seeking a Lead Application Security Engineer to drive the dynamic application security testing program for a federal civilian client, overseeing the Burp Suite Enterprise program and ensuring robust application security practices.

Responsibilities

  • Run a Federal Burp Suite Enterprise Program
  • Architect, operate, and continuously improve scheduled authenticated DAST scanning
  • Write and maintain extensions (Python/Jython or Java/Montoya API)
  • Authenticate scanning against hard targets
  • Verify remediations, kill false positives with evidence
  • Lead and drive discussions with DevOps, platform, and identity stakeholders
  • Administer the team’s Linux servers in AWS
  • Support the migration to OpenShift
  • Convert legacy Python/shell tooling into Ansible roles and playbooks
  • Integrate security tooling into GitHub Actions or comparable CI/CD pipelines

Skills

  • 8+ years in engineering/security, with deep, recent, hands-on Burp Suite Enterprise and Burp Suite Professional operations — you have configured authenticated scans, not just reviewed their output
  • Demonstrated experience writing or significantly modifying custom Burp extensions (Python/Jython, Java, or Montoya API)
  • Strong Linux/Unix command-line fluency — comfortable diagnosing services, disk, memory, and network from a shell, daily
  • Python and Bash scripting; Ansible exposure; experience with Docker/Kubernetes (OpenShift a plus) and AWS
  • Experience integrating security tooling into GitHub Actions or comparable CI/CD pipelines
  • Proven technical leadership: you have driven programs or technical decisions across teams and can hold your own — energetically — in a room of senior engineers
  • An active, visible interest in AppSec and DevSecOps research: you test new techniques, follow the field, and bring ideas to the team unprompted
  • U.S. citizenship and the ability to complete federal Public Trust vetting (no security clearance required)
  • Published Burp extensions (BAppStore or GitHub), conference talks, blog posts, or open-source security tooling
  • Experience scripting around OTP/TOTP, PIV, or certificate-based authentication for automated scanning
  • Veracode SAST, Contrast IAST, or bug bounty validation experience (HackerOne or similar)
  • Prior federal or regulated-environment AppSec work (NIST 800-53 / FISMA familiarity)

Benefits

  • Medical Insurance
  • Dental Insurance
  • Vision Insurance
  • Life Insurance
  • Short Term & Long-Term Disability
  • 401k Retirement Savings Plan with Company Match
  • Paid Holidays
  • Paid Time Off (PTO)
  • Tuition and Professional Development Assistance

Company Overview

  • phia LLC is a Northern Virginia based small business that was established in 2011. It was founded in 2011, and is headquartered in Fairfax, Virginia, USA, with a workforce of 11-50 employees. Its website is http://phiatech.com.
  • More open positions

    [Remote] Senior Databricks Engineering Lead

    Work from home Full-time role

    [Remote] AI Engineer

    Work from home Full-time role

    [Remote] Implementation Project Manager

    Work from home Full-time role

    [Remote] Enterprise Account Executive

    Work from home Full-time role

    [Remote] Project Administrator

    Work from home Full-time role

    Nurse Navigator 1, Part Time

    Work from home Full-time role

    Remote Customer Service Representative – Temporary Benefits & Payroll Support at careerzynith – $15.50/hr – Flexible Hours

    Work from home Full-time role

    Experienced Remote Data Entry Clerk – Dynamic Team Member for careerzynith

    Work from home Full-time role

    Remote Data Entry Specialist – Live Chat Support – $40/hr – Join careerzynith’s Global Team

    Work from home Full-time role

    Care Experience Learning and Development Associate

    Work from home Full-time role

    Full Stack Developer (Remote Opportunity)

    Work from home Full-time role

    Risk & Fraud Investigator

    Work from home Full-time role

    Analista de SRE III

    Work from home Full-time role

    Predictive Modeler – P&C Commercial Actuarial Consultant - REMOTE

    Work from home Full-time role

    Rural and Suburban Mail Carrier

    Work from home Full-time role

    Director, New Start Implementation

    Work from home Full-time role

    Respiratory Therapist IV Registered $10,000 Sign On Eligible

    Work from home Full-time role

    People Operations Shared Service Specialist

    Work from home Full-time role

    [Remote] Retention Analyst

    Work from home Full-time role

    Remote Data Entry Specialist – Entry‑Level Home‑Based Role with careerzynith – Flexible Schedule, Career Growth & Competitive Benefits

    Work from home Full-time role

    [Remote] Senior HRIS Analyst, Human Capital Management

    Work from home Full-time role