Perform application security testing and vulnerability assessments
Conduct application security testing using approved tools, processes, and techniques
Assess web applications, APIs, services, containers, dependencies, and delivery environments for security weaknesses
Support automated security scanning
Support automated scanning of applications, APIs, services, software dependencies, containers, and CI/CD pipelines
Assist with configuring and maintaining security scanning tools used during development, build, test, release, and runtime activities
Document, track, and validate vulnerabilities
Document, triage, track, and validate vulnerabilities and security findings through remediation and closure
Maintain accurate vulnerability status, remediation evidence, and closure documentation
Assist development teams with secure coding and remediation
Provide technical guidance to development teams on secure coding practices and remediation of identified weaknesses
Help teams understand scan results, vulnerable dependency reports, policy violations, and recommended fixes
Support DevSecOps tool integration and automation
Support integration and operation of security tools and controls within CI/CD pipelines
Help implement automated security gates, policy enforcement, and reporting workflows
Integrate DevSecOps tools through APIs to improve visibility, automation, and operational efficiency
Develop proof-of-concept secure reference implementations
Design and develop proof-of-concept sample applications using common technology stacks to demonstrate application security best practices
Build reference examples that illustrate secure authentication, authorization, logging, dependency management, secrets handling, containerization, API security, and secure CI/CD workflows
Maintain reusable patterns and examples that development teams can reference when implementing security controls
Ideate and develop security utility applications
Identify process and technology gaps between development and security teams
Design and develop utility applications, scripts, dashboards, integrations, or automation workflows that improve vulnerability management, reporting, remediation tracking, tool interoperability, and DevSecOps operations
Integrate with security, development, repository, observability, and CI/CD tools through available API interfaces
Monitor compliance with application security standards
Monitor security findings and alignment with established application security standards and controls
Support security improvement initiatives aligned to Zero Trust principles and applicable NIST, CISA, and CIS security frameworks
Collect metrics, evidence, and reporting data
Collect and maintain security assessment data, scan results, vulnerability evidence, remediation status, and operational metrics
Support reporting for continuous monitoring, vulnerability reduction, and application security improvement initiatives
Support DevSecOps and vulnerability reduction initiatives
Support enterprise DevSecOps, vulnerability reduction, secure software development, and application security modernization efforts across USCIS programs