Federal Vulnerability Mgmt & App Security Engineer (US Citizen)
PSI Services · Atlanta, GA
$125,000from the description
Jul 24, 2026
Atlanta, GA
Jul 26, 2026
What this job asks for AI summary
A dual-focus security role covering both enterprise vulnerability management and application security. Day-to-day work spans running vulnerability assessments across infrastructure and cloud environments, integrating SAST/DAST/SCA tooling into CI/CD pipelines, conducting secure code reviews, and partnering with engineering and DevOps teams to embed security into the software development lifecycle. Suits a practitioner with a background spanning AppSec and vulnerability management who is comfortable advising both technical teams and executive stakeholders.
Mid level · 3+ years · Remote · Full-time
“or” means any one of them counts — you don't need all of them.
Posted 10 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 1,100 people nationally plausibly meet what this posting asks for (information security analysts). range 330–2,400
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
The job title includes 'Manager' but the role is clearly an individual-contributor security analyst/practitioner — no direct reports, hiring authority, or budget ownership are described. Classified as Mid-level based on the 3–5+ years requirement and the scope of the role.
The posting states a flat $125K annual salary with no range.
The role is fully remote (Remote-US).
SDLC is listed as a contextual responsibility (embedding security into the development lifecycle) rather than a named tool; it is included as preferred to reflect the strong emphasis on DevOps/engineering partnership.
Qualys, Tenable, and CrowdStrike are listed together as examples of equivalent vulnerability scanning tools ('or equivalent'); Qualys is used as the primary name with the others as alternatives.
NIST CSF/800-53 and ISO 27001 are listed together as examples of security frameworks; NIST CSF is used as the primary with the others as alternatives.
'Prior experience working closely with software engineering or DevOps teams' is explicitly called 'strongly preferred' — not a hard gate.
No formal degree requirement is stated anywhere in the posting.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.