Status: Active – Funded Position; 4-year base + 2-year option periods
Location: Remote – U.S Only
Schedule: Full-time | Core hours 7:30 AM – 4:30 PM ET | Daily standup 8:30 AM ET | Flexible with advance notice
Focus Areas: Veracode (SAST/DAST), Burp Suite Enterprise, CI/CD Security Integration, Federal Application Security Testing
Overview
At phia we hire talented and passionate people who are focused on collaborative, meaningful work, providing technical and operational subject matter expertise and support services to our partners and clients. phia is seeking a mission-driven Application Security Engineer to act as a dedicated technical partner embedded within a federal agency’s AppSec team.
You will plan, administer, and triage application security testing workflows using Veracode and Burp Suite Enterprise, manage security integrations within a CI/CD pipeline, and serve as a technical resource for development teams navigating vulnerability remediation. You will work directly alongside federal clients and a small, experienced AppSec team in a fast-paced, technically driven environment where clear communication and autonomous execution are expected every day.
What You’ll Do
Who You Are
Preferred Skills
Required Education + Experience
Education: High school diploma or GED required; Bachelor’s degree in Computer Science, Information Technology, Information Security, or related field preferred (experience may substitute for degree)
Experience: 6+ years of IT experience; 3+ years specifically in SAST/DAST application security testing; 2+ years of coding in Python, Java, .NET, or C#; 3+ years designing and implementing enterprise-wide security controls
Clearance: Public Trust / Suitability — U.S. Citizenship required; applicants selected will be subject to a security investigation
GENERAL PROGRAM REQUIREMENTS:
Citizenship: Must be a U.S. Citizen. No exceptions.
Work Hours: Core hours 7:30 AM – 4:30 PM ET, Monday through Friday; daily standup at 8:30 AM ET; schedule is flexible with advance notice
Work Location: Fully remote within the United States
Travel: Minimal
Who We Are
phia LLC ("phia") is a Northern Virginia based, small business established in 2011 with focus in Cyber Intelligence, Cyber Security/Defense, Intrusion Analysis & Incident Response, Cyber Architecture & Capability Analysis, Cyber Policy & Strategy, Information Assurance/Security, Compliance, Certification & Accreditation, Communications Security, Traditional Security, and Facilities Security. phia also provides cyber operations support functions such as: Program and Process Management, Engineering, Development, and Systems Administration that allows for Cyber Operations to efficiently integrate our customer’s missions and objectives. phia supports various agencies and offices within the Department of Defense (DoD), Federal government, and private/commercial entities.
phia offers excellent benefits to enhance work-life balance, including the following:
phia does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity, or any other reason prohibited by law in the provision of employment opportunities and benefits.

Instacart

Fluent Trade Technologies

Zensurance

Ci&T

Fluent Trade Technologies