← all jobs

[Remote] Lead Application Security Engineer

Work from home Full-time role Hiring

Note: The job is a remote job and is open to candidates in USA. phia, LLC is a Northern Virginia based small business focused on Cyber Intelligence and Cyber Security. They are seeking a Lead Application Security Engineer to drive the dynamic application security testing program for a federal civilian client, overseeing the Burp Suite Enterprise program and ensuring robust application security practices.

Responsibilities

  • Run a Federal Burp Suite Enterprise Program
  • Architect, operate, and continuously improve scheduled authenticated DAST scanning
  • Write and maintain extensions (Python/Jython or Java/Montoya API)
  • Authenticate scanning against hard targets
  • Verify remediations, kill false positives with evidence
  • Lead and drive discussions with DevOps, platform, and identity stakeholders
  • Administer the team’s Linux servers in AWS
  • Support the migration to OpenShift
  • Convert legacy Python/shell tooling into Ansible roles and playbooks
  • Integrate security tooling into GitHub Actions or comparable CI/CD pipelines

Skills

  • 8+ years in engineering/security, with deep, recent, hands-on Burp Suite Enterprise and Burp Suite Professional operations — you have configured authenticated scans, not just reviewed their output
  • Demonstrated experience writing or significantly modifying custom Burp extensions (Python/Jython, Java, or Montoya API)
  • Strong Linux/Unix command-line fluency — comfortable diagnosing services, disk, memory, and network from a shell, daily
  • Python and Bash scripting; Ansible exposure; experience with Docker/Kubernetes (OpenShift a plus) and AWS
  • Experience integrating security tooling into GitHub Actions or comparable CI/CD pipelines
  • Proven technical leadership: you have driven programs or technical decisions across teams and can hold your own — energetically — in a room of senior engineers
  • An active, visible interest in AppSec and DevSecOps research: you test new techniques, follow the field, and bring ideas to the team unprompted
  • U.S. citizenship and the ability to complete federal Public Trust vetting (no security clearance required)
  • Published Burp extensions (BAppStore or GitHub), conference talks, blog posts, or open-source security tooling
  • Experience scripting around OTP/TOTP, PIV, or certificate-based authentication for automated scanning
  • Veracode SAST, Contrast IAST, or bug bounty validation experience (HackerOne or similar)
  • Prior federal or regulated-environment AppSec work (NIST 800-53 / FISMA familiarity)

Benefits

  • Medical Insurance
  • Dental Insurance
  • Vision Insurance
  • Life Insurance
  • Short Term & Long-Term Disability
  • 401k Retirement Savings Plan with Company Match
  • Paid Holidays
  • Paid Time Off (PTO)
  • Tuition and Professional Development Assistance

Company Overview

  • phia LLC is a Northern Virginia based small business that was established in 2011. It was founded in 2011, and is headquartered in Fairfax, Virginia, USA, with a workforce of 11-50 employees. Its website is http://phiatech.com.
  • More open positions

    [Remote] Senior Databricks Engineering Lead

    Work from home Full-time role

    [Remote] AI Engineer

    Work from home Full-time role

    [Remote] Implementation Project Manager

    Work from home Full-time role

    [Remote] Enterprise Account Executive

    Work from home Full-time role

    [Remote] Project Administrator

    Work from home Full-time role

    Backend Engineer (Data)- (Remote or Pittsburgh)

    Work from home Full-time role

    Sr Product Manager

    Work from home Full-time role

    Senior Cloud Engineer - GCP (f/m/n)

    Work from home Full-time role

    Senior Headhunter / Independent Recruiter Remote | Commission Only | U.S. Recruiting

    Work from home Full-time role

    Senior Manager, Project Management

    Work from home Full-time role

    [Remote] Staff Accountant - Remote

    Work from home Full-time role

    Manager, Finance Site Liaison (Controller)

    Work from home Full-time role

    Affiliate Relationship Manager - LATAM

    Work from home Full-time role

    Infection Preventionist - ICAP Grant

    Work from home Full-time role

    Experienced Night Shift Remote Live Chat Agent – Non-Phone Role | $25–$35/hr

    Work from home Full-time role

    Experienced Data Entry Associate – Work From Home Opportunity with careerzynith

    Work from home Full-time role

    English Adjunct Instructor

    Work from home Full-time role

    Work from Home Customer Service Representative – Phone, Email & Chat Support for Leading Brands (Flexible Hours, Competitive Pay)

    Work from home Full-time role

    Fund Development Coordinator

    Work from home Full-time role

    Technical Sales Representative - Trenton, NJ

    Work from home Full-time role

    Remote Customer Service Associate – Full‑Time, Entry‑Level Position with Comprehensive Training at careerzynith

    Work from home Full-time role