Source description
About the role
Interview process: 2 rounds of interviews. 2nd round will be in-person.
Role : Cyber Security Engineer
Location : Hybrid, onsite monthly or quarterly in the Reston, VA office. Candidates MUST reside in the DMV area.
Duration : 6-month contract with potential for extension
Candidate Status Requirement: None
Summary : Client is seeking a DevSecOps Engineer to build and enhance application security throughout the CI/CD pipeline as part of the organization's migration from on-premises Java-based applications to AWS-hosted containerized environments running on Amazon EKS and EC2. The role will focus on integrating security into the software development lifecycle, automating security controls, and supporting secure deployments across cloud-native applications and infrastructure.
5+ years of overall IT security experience
Background in Java development
Experience with EKS vulnerability management
Experience with any tools for:
SAST (Static Application Security Testing) – e.g., Checkmarx, Fortify SCA, Veracode, SonarQube, Semgrep, GitHub CodeQL, Coverity
DAST (Dynamic Application Security Testing) – e.g., OWASP ZAP, Burp Suite Enterprise, Invicti (Netsparker), Acunetix, HCL AppScan, Veracode DAST
IAST (Interactive Application Security Testing) – e.g., Contrast Security, HCL AppScan IAST, Synopsys Seeker, Veracode IAST
SCA (Software Composition Analysis) – e.g., Snyk, Mend (WhiteSource), Black Duck, OWASP Dependency-Check, JFrog Xray, Veracode SCA, GitHub Dependabot
Understanding of OWASP Top 10 or API security top 10
Experience with Jenkins
Nice to have:
CISSP or AWS certified for Cybersecurity
More at 3B Staffing