cFocus Software Incorporated logo

HHS - Application Security Engineer

cFocus Software Incorporated
Department:Software Engineer
Type:REMOTE
Region:Washington, D.C
Location:Rockville, MD
Experience:Mid-Senior level
Estimated Salary:$110,000 - $150,000
Skills:
APPLICATION SECURITYSASTDASTDEPENDENCY SCANNINGCODE REVIEWOWASPSECURE CODINGVULNERABILITY REMEDIATIONDEVSECOPSCI/CDNIST SP 800-53RMFFISMAAPI SECURITY TESTINGPENETRATION TESTING
Share this job:

Job Description

Posted on: January 28, 2026

cFocus Software seeks a Application Security Engineer to join our program supporting the Department of Health and Human Services (HHS) This position is remote. This position requires the ability a Public Trust clearance. Qualifications:

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or related field.
  • 5+ years of experience in application security or secure software development.
  • Hands-on experience with SAST/DAST tools, dependency scanning, and code review.
  • Knowledge of OWASP Top 10, secure coding practices, and vulnerability remediation.
  • Experience supporting DevSecOps and CI/CD security integration.
  • Familiarity with federal security standards (NIST SP 800-53, RMF, FISMA).
  • Strong written and verbal communication skills.
  • CSSLP, GWAPT, CEH, or equivalent (preferred)
  • AWS/Azure security certifications (preferred)

Duties:  

  • Conduct application security assessments including SAST, DAST, SCA, SBOM analysis, and secure code reviews.
  • Analyze vulnerability scan results and determine applicability, severity, and business risk.
  • Provide remediation guidance to developers based on secure coding standards (OWASP, NIST, HHS guidance).
  • Support integration of automated security testing within CI/CD pipelines.
  • Perform API security testing including authentication, authorization, and endpoint validation.
  • Validate remediation through follow-up testing and evidence review.
  • Support penetration testing activities related to application and web services.
  • Maintain application security documentation, reports, and dashboards.
  • Support zero-day and KEV-based vulnerability response activities.
  • Coordinate with ISSOs, system owners, and developers to ensure vulnerabilities are tracked and remediated within SLA.
Originally posted on LinkedIn

Apply now

Please let the company know that you found this position on our job board. This is a great way to support us, so we can keep posting cool jobs every day!

cFocus Software Incorporated logo

cFocus Software Incorporated

View company page
USARemoteJobs.app logo

USARemoteJobs.app

Get USARemoteJobs.app on your phone!

SIMILAR JOBS
Brain Corp logo

Senior Staff Software Engineer, Cloud

Brain Corp
Just now
Software Engineer
Remote (San Diego, CA)
San Diego, CA
GOOGLE CLOUD PLATFORMGOPYTHON+17 more
Alignerr logo

C++ Engineer - High Performance Computing (HPC)

Alignerr
2 days ago
Software Engineer
Remote (New York, NY)
New York, NY
C++C++17C++20+7 more
Affirm logo

Software Engineer II, Frontend (Purchasing Integrations)

Affirm
2 days ago
Software Engineer
Remote (Los Angeles, CA)
Los Angeles, CA
REACTVUEJAVASCRIPT+6 more
Cognizant logo

Senior Facets Product Specialist – G6 AWS DevOps Implementation

Cognizant
2 days ago
Software Engineer
Remote (Denver, CO)
Englewood, CO
FACETS G6AWSEKS+9 more
Jobs via Dice logo

Senior AI Native Software Engineer (Agentic AI)

Jobs via Dice
2 days ago
Software Engineer
Remote (New York, NY)
New York, NY
PYTHONJAVACLOUD-NATIVE+14 more