Cybersecurity Engineer II
Cybersecurity Engineer II
BAM is a dynamic, multi-disciplinary firm with leading-edge skills in information technology, software development and applied research. Serving government and commercial markets, BAM is committed to its customers and to delivering strong leadership, sound solutions, and innovative thinking. BAM is seeking a Cybersecurity Engineer II to join its team. The Cybersecurity Engineer II is a mid-level technical role responsible for implementing, maintaining, and enhancing security measures to protect organizational systems, networks, and data. This role focuses on threat detection, vulnerability management, incident response, and secure system design. The engineer collaborates with IT, DevOps, and compliance teams to ensure that security controls are effective, scalable, and aligned with regulatory requirements and industry best practices. Key Responsibilities:- Design, implement, and manage application security solutions including SAST/DAST/IAST tools, dependency scanning, container security, and security orchestration platforms.
- Conduct application security assessments, code reviews, and penetration testing; coordinate remediation efforts with development teams.
- Implement and maintain secure CI/CD pipelines with automated security testing and policy enforcement.
- Support incident response activities for application security events, including investigation, containment, and recovery.
- Develop and maintain secure coding standards, DevSecOps policies, and technical documentation.
- Collaborate with development and infrastructure teams to ensure secure application configurations and deployment practices.
- Assist in compliance efforts for standards such as RMF, NIST SP 800-53, and CMMC as they relate to application security.
- Participate in threat modeling, security architecture reviews, and secure design sessions.
- Stay current with emerging application threats, vulnerabilities, and secure development practices.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
- 5+ years of experience in application security engineering or DevSecOps roles.
- Hands-on experience with application security tools and platforms (e.g., Veracode, Checkmarx, SonarQube, Snyk, Aqua Security).
- Strong understanding of secure software development lifecycle (SDLC), application security principles, and container security.
- Familiarity with security frameworks and compliance standards (e.g., NIST, ISO, CIS) and their application to software development.
- Excellent analytical and problem-solving skills with a focus on application-layer security.
- Certifications such as CISSP, CSSLP, Security+, or GIAC (GWEB, GWAPT).
- Experience with cloud security (AWS, Azure, GCP) and cloud-native application security.
- Deep knowledge of DevSecOps practices, CI/CD security, and infrastructure as code security.
- Experience in government contracting or regulated industries with secure development requirements.
- Familiarity with scripting languages (e.g., Python, PowerShell) for automation.
This is a remote role.
SBIR
Recommended Jobs
Actors for Live Emergency Training Simulation
Casting Call: Realistic Acting Roles for Live Emergency Training Simulation Location: Fairfax, VA (Fair Oaks Mall area). Date: Tuesday, October 14th, 2025. Pay: $25-$35/hour.…
Civil Project Manager
Job Title: Civil Project Manager Job Description We are seeking a highly motivated Project Manager to join our growing Civil/Site Design team in Richmond, VA. The ideal candidate will have experience …
Project Manager - Ports & Maritime
At Jacobs, we're challenging today to reinvent tomorrow by solving the world's most critical problems for thriving cities, resilient environments, mission-critical outcomes, operational advancement, s…
Ultrasound Technologist PRN
**Description** **Introduction** Do you have the PRN career opportunities as an Ultrasound Technologist PRN you want with your current employer? We have an exciting opportunity for you to join Henrico…
Foreman - Specialty Construction (Fall Protection Systems)
ITAC serves Process & Industrial clients with integrated engineering and construction services for complex capital projects. We also offer specialty services including power systems services and prod…
Project and Contract Coordinator (Remote)
The Project and Contract Coordinator will play a key role in supporting operational efficiency, risk mitigation, and revenue realization across client engagements. This role combines project coordi…
Receptionist
TekSystems is currently hiring for a Receptionist position that is FULLY on site in Alexandria, VA. MUST HAVE: Be able to start ASAP, have any administrative, data entry, or anything related to th…
Information System Security Specialist (RMF) - TS-SCI
Program Overview Delivers configurable, scalable, and adaptable cybersecurity solutions to meet the evolving needs of the warfighting customer. This program supports a range of key roles, includin…
Clinical Associate-Per Diem
**When you join the growing BILH team, you're not just taking a job, you're making a difference in people's lives.** Clinical Associate Per Diem - Job_Description_Under_Construction **Job Description:…
Physical Therapist - Outpatient - License Required
ATTENTION: This position requires graduation as a Doctor of Physical Therapy (or equivalent standing) and a state license as a Physical Therapist. Now Hiring: Physical Therapist Outpatient Orth…