Sobre esta vaga de Application Security Engineer na Accenture Federal Services
The work
The Senior Application Security Engineer (DevSecOps) serves as a strategic partner bridging security governance, software delivery velocity, and modern engineering practices. In this role, you will collaborate closely with development teams to design, implement, and maintain secure application pathways that empower engineering teams—and AI‑assisted development—to deliver code confidently at scale.
As the technical leader of the Application Security Scrum Team, you will participate in sprint ceremonies, oversee security backlog prioritization, and ensure security initiatives are fully integrated into the development lifecycle. You will design security controls that enhance developer productivity, creating an environment where secure development becomes seamless and frictionless.
This position requires deep technical expertise across application security, CI/CD pipeline architecture, threat modeling, and supply chain integrity, combined with strong leadership skills to influence engineering culture and drive security automation in federal environments.
Key responsibilities:
- Prioritize and manage the security backlog, mentoring team members on secure development practices
- Test web and AI applications for vulnerabilities, triage findings, and provide actionable technical resolutions
- Architect and maintain secure, automated CI/CD pipelines using GitLab CI/CD and Jenkins
- Design hardened build processes and implement secure software supply chain controls
- Implement and maintain SBOM lifecycle processes to ensure full dependency visibility
- Ensure security-by-design for AI agents, development workflows, and CI/CD pipelines
- Integrate security tools (Snyk, Nexus, JFrog) into developer workflows and manage complex dependency lifecycles
- Ensure build artifacts are properly verified, signed, and compliant with federal requirements
- Facilitate cross-functional collaboration to maintain security without slowing innovation
- Act as a strategic security partner who understands the realities of shipping code in federal environments
Here’s what you need:
- 3+ years of hands-on software engineering and application/infrastructure security experience
- Proven experience securing CI/CD pipelines and delivering production-quality code
Technical proficiency:
- Deep expertise with build systems such as Gradle, Maven, Docker, and Kubernetes
- Strong CI/CD orchestration skills using GitLab CI/CD and Jenkins
- Hands-on experience with artifact signing (Sigstore/Cosign)
- Experience generating and analyzing SBOMs (CycloneDX or SPDX)
- Strong understanding of modern AppSec principles, including SSDF
- Expertise in threat modeling, secrets management (HashiCorp Vault), and container hardening
Preferred qualifications:
- Experience automating compliance mapping pipeline controls to federal frameworks (NIST 800-53, FedRAMP, SSDF)
- Professional certifications such as CSSLP, CISSP, or CCSP
Eligibility Requirement:
- US Citizen required
- Eligible to obtain a government public trust clearance
As required by local law, Accenture Federal Services provides reasonable ranges of compensation for hired roles based on labor costs in the states of California, Colorado, Hawaii, Illinois, Maine, Maryland, Massachusetts, Minnesota, New Jersey, New York, Vermont, Virginia, Washington, and the District of Columbia, and the city of Cleveland. The base pay range for this position in these locations is shown below. Compensation for roles at Accenture Federal Services varies depending on a wide array of factors, including but not limited to office location, role, skill set, and level of experience. Accenture Federal Services offers a wide variety of benefits. You can find more information on benefits here. We accept applications on an on-going basis and there is no fixed deadline to apply.