- Location
- Arlington, VA · Arlington, Virginia, United States
- Workplace
- Onsite
- Department
- 56219060 - AFS Cyber Strategy Risk and Architecture
- Experience
- 7+ years
- Clearance
- Required
- Source
- Greenhouse
Description
The work
The Application Security Lead is responsible for leading the end‑to‑end security readiness of applications, ensuring compliance with federal and enterprise security frameworks, ATO processes, and risk management requirements. The role drives security architecture design, secure configurations, threat modeling, and alignment with enterprise and regulatory standards. Additional responsibilities include coordinating and executing security assessments, vulnerability analyses, penetration testing reviews, and remediation planning. The Application Security Lead partners with product, engineering, cloud, and compliance teams to understand system requirements and implement secure‑by‑design solutions. This role develops and maintains security documentation, establishes best practices for application security and identity management, and provides guidance on secure development practices. The lead oversees the implementation and monitoring of security controls to ensure compliance, resiliency, and ATO sustainment, and drives continuous improvement in security processes, tooling, and engineering workflows.
Key responsibilities:
- Lead and manage the end‑to‑end security readiness of applications, including compliance with federal and enterprise security frameworks, ATO processes, and risk management requirements
- Drive security architecture design, ensuring secure configurations, threat modeling, and alignment with enterprise and regulatory standards
- Coordinate and execute security assessments, vulnerability analyses, penetration testing reviews, and remediation planning
- Partner with product, engineering, cloud, and compliance teams to understand system requirements and implement secure‑by‑design solutions
- Develop and maintain security documentation, including SSPs, POA&Ms, security diagrams, control evidence, and continuous monitoring artifacts
- Establish and enforce best practices for application security, identity and access management, secure CI/CD pipelines, and infrastructure hardening
- Provide guidance and mentorship on secure development practices, helping teams adopt and mature security capabilities across the SDLC
- Oversee the implementation and monitoring of security controls to ensure ongoing compliance, operational resiliency, and ATO sustainment
- Drive continuous improvement in security processes, tooling, and engineering workflows to reduce risk and elevate overall security posture
Here’s what you need:
- 7+ years of professional experience
- Extensive experience leading application or cloud security initiatives, preferably within regulated environments requiring ATO or equivalent compliance frameworks
- Strong practical expertise in security architecture, secure application design, and implementation of technical security controls
- Hands‑on experience with cloud security services (Azure, AWS, or equivalent), IAM models, network segmentation, encryption, and monitoring solutions
- Familiarity with federal, enterprise, or industry security frameworks (NIST 800‑53, FedRAMP, Zero Trust, CIS benchmarks)
- Proficiency with DevSecOps tooling, automated security scanning, and secure pipeline orchestration
- Experience producing high‑quality security documentation, including SSPs, policies, diagrams, and technical control evidence
- Demonstrated ability to collaborate across engineering, compliance, governance, and operational teams to deliver secure and scalable solutions
- Strong understanding of security governance principles, risk management, and continuous monitoring practices
Nice to have:
- Experience serving as a technical security lead on application development or modernization programs
- Knowledge of cloud‑native architectures, container security, and serverless security controls
- Familiarity with enterprise transformation programs and secure cloud adoption frameworks
- Experience with governance, risk, and compliance (GRC) platforms and enterprise security management practices
- Background in automation, security orchestration, and integration of security tooling within CI/CD workflows
Core skills & competencies:
- Security leadership and the ability to influence across diverse technical teams
- Strong analytical reasoning, risk assessment, and problem‑solving capabilities
- Exceptional communication skills for both technical and non‑technical audiences
- Ability to manage multiple security workstreams in fast‑paced and evolving environments
- Commitment to security excellence, compliance discipline, and continuous improvement
Eligibility Requirements:
- U.S. Citizenship required
- Ability to obtain a government TS clearance
As required by local law, Accenture Federal Services provides reasonable ranges of compensation for hired roles based on labor costs in the states of California, Colorado, Hawaii, Illinois, Maine, Maryland, Massachusetts, Minnesota, New Jersey, New York, Vermont, Virginia, Washington, and the District of Columbia, and the city of Cleveland. The base pay range for this position in these locations is shown below. Compensation for roles at Accenture Federal Services varies depending on a wide array of factors, including but not limited to office location, role, skill set, and level of experience. Accenture Federal Services offers a wide variety of benefits. You can find more information on benefits here. We accept applications on an on-going basis and there is no fixed deadline to apply.