Application Security Engineer

Posted 14 Days Ago
Be an Early Applicant
Boulder, CO, USA
In-Office
102K-157K Annually
Junior
Hardware • Database • Defense
The Role
Perform automated and manual application security analysis (SAST, SCA, fuzzing, code reviews), integrate and tune security tooling in CI/CD/DevSecOps pipelines, support developers with remediation and secure design, conduct threat modeling, document findings, and stay current on vulnerabilities and mitigation strategies.
Summary Generated by Built In

SciTec, a wholly owned subsidiary of Firefly Aerospace, is a dynamic non-traditional defense contractor that delivers advanced technologies in support of U.S. National Security and Defense. For the past forty-five plus years, we have supported Department of Defense customers by developing innovative remote sensing algorithms, tools, and techniques to deliver world-class data exploitation capabilities supporting missile defense; intelligence, surveillance, & reconnaissance; space domain awareness; and aircraft survivability missions.

Important Notice: SciTec exclusively works on U.S. government contracts that require U.S. citizenship for all employees. Applicants that do not meet this requirement will not be considered.

SciTec has an immediate opportunity for a talented engineer to support our programs delivering Next-Generation Missile Warning software. This is a unique opportunity to join a business delivering core capabilities for National defense. You will work within a fast-paced team delivering end-to-end software processing of Overhead Persistent InfraRed (OPIR) sensor data for Missile Warning, Missile Defense, Battlespace Awareness, and Technical Intelligence.

We are seeking an Application Security Engineer to help secure mission-critical software systems by identifying, analyzing, and mitigating application-level vulnerabilities. This role focuses on hands-on security analysis, tooling integration, and working directly with software engineers to embed security into the development lifecycle.

The ideal candidate combines strong technical security skills with the ability to collaborate effectively with developers in a DevSecOps environment.

Responsibilities
  • Perform application security analysis using both automated and manual techniques, including:
    • Static code analysis (SAST)
    • Software composition analysis (SCA)
    • Fuzzing
    • Manual code and design reviews
  • Identify, analyze, and help remediate application vulnerabilities
  • Support software engineers in integrating security considerations into system and application designs
  • Integrate and maintain application security tooling within CI/CD and DevSecOps pipelines
  • Design, implement, and improve continuous integration security analysis tooling
  • Tune and maintain security tools to reduce false positives and improve signal quality
  • Assist development teams in understanding findings and implementing effective fixes
  • Support threat modeling and secure design reviews
  • Stay current with emerging vulnerabilities, attack techniques, and mitigation strategies
  • Document findings, recommendations, and best practices
  • Perform other duties as assigned

Requirements
  • Bachelor’s degree plus 2+ years of professional experience in cybersecurity or software development, or equivalent experience
  • 2+ years of experience focused on application/software security
  • Experience analyzing source code for security flaws
  • Familiarity with secure software development practices
  • Strong analytical, problem-solving, and communication skills
  • Detail-oriented with strong written and verbal communication abilities
  • Ability to qualify for and maintain a DoD or DoE Secret security clearance
  • Ability to meet DoD 8140.01 Cyberspace Workforce Management requirements within six months of hire
  • Good verbal and written communication skills
  • Attention to detail

Candidates who have any of the following skills will be preferred:

  • Active DoD Secret clearance or higher
  • Experience identifying, exploiting, and remediating application vulnerabilities
    • Credit for published CVEs is a strong plus
  • Proficiency in one or more programming languages such as C++, Python, JavaScript, Rust
  • Experience configuring and operating static analysis tools (e.g., Coverity, Klocwork, SonarQube)
  • Experience configuring and operating software composition analysis tools (e.g., Snyk, Sonatype, Anchore, JFrog Xray)
  • Experience with fuzzing frameworks (AFL, AFL++, honggfuzz, or similar)
  • Experience with debugging, runtime instrumentation, or reverse engineering, including tools such as:
    • strace
    • eBPF
    • Ghidra or IDA Pro
  • Familiarity with threat modeling methodologies and frameworks such as MITRE ATT&CK
  • Experience working in DevSecOps or Agile development environments

*Resumes, Cover Letters, and Applications which are generated by AI will not be considered for employment.

Colorado Residents: In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.


Benefits

SciTec offers a highly competitive salary and benefits package, including:

  • 4% Safe Harbor 401(k) match
  • 100% company paid HSA Medical insurance, with a choice of 2 buy-up options
  • 80% company paid Dental insurance
  • 100% company paid Vision insurance
  • 100% company paid Life insurance
  • 100% company paid Long-term Disability insurance
  • 100% company paid Hospital Indemnity insurance
  • Voluntary Accident and Critical Illness insurance
  • Short-term Disability insurance
  • Annual Profit-Sharing Plan
  • Discretionary Performance Bonus
  • Paid Parental Leave
  • Generous Paid Time Off, including Holiday, Vacation, and Sick Pay
  • Flexible Work Hours

The pay range for this position is $102,000 - $157,000 / year. SciTec considers several factors when extending an offer of employment, including but not limited to the role and associated responsibilities, a candidate's work experience, education/training, and key skills. This is not a guarantee of compensation.

SciTec is proud to be an Equal Opportunity employer. VET/Disabled.

Skills Required

  • Bachelor's degree or equivalent plus 2+ years professional cybersecurity or software development experience
  • 2+ years focused on application/software security
  • Experience analyzing source code for security flaws
  • Familiarity with secure software development practices
  • Experience integrating and maintaining application security tooling in CI/CD/DevSecOps pipelines
  • Ability to qualify for and maintain a DoD or DoE Secret security clearance
  • Ability to meet DoD 8140.01 Cyberspace Workforce Management requirements within six months
  • Strong analytical, problem-solving, and communication skills
  • Detail-oriented with strong written and verbal communication abilities
  • Experience with manual code and design reviews, fuzzing, and vulnerability remediation
  • Proficiency with programming languages (C++, Python, JavaScript, Rust)
  • Experience configuring/operating static analysis tools (Coverity, Klocwork, SonarQube)
  • Experience with software composition analysis tools (Snyk, Sonatype, Anchore, JFrog Xray)
  • Experience with fuzzing frameworks (AFL, AFL++, honggfuzz)
  • Experience with debugging/runtime instrumentation or reverse engineering tools (strace, eBPF, Ghidra, IDA Pro)
  • Familiarity with threat modeling methodologies and MITRE ATT&CK
  • Experience working in DevSecOps or Agile development environments
  • Active DoD Secret clearance or higher
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Princeton, NJ
194 Employees
Year Founded: 1979

What We Do

The world brings ever-evolving challenges; SciTec builds solutions. Our forward-thinking approach provides a wide range of services and fully integrated technical support to the defense industry, governmental agencies, and industrial system development firm applications. We empower our scientists, engineers, and developers to deliver cutting-edge, advanced sensor systems, tailor innovative technologies to our customers’ needs quickly from concept to operational reality, and custom-build scientific instrumentation for testing and validation. As we develop best-in-class hardware, we also evolve data-processing algorithms and physics-based observable models. We are busy changing the world, and can’t do it without the talent, dedication, and enthusiasm of individuals like you. MISSION: As the challenge evolves, we evolve faster. We deliver best-in-class mission-enabling technologies and end-to-end system solutions for our customers’ most difficult and important problems. VISION: Deliver persistent information dominance. Empower our workforce at every level to create, contribute, and grow. Innovate and adapt to address ever-evolving challenges. SciTec NEWS: https://www.linkedin.com/showcase/scitecnews/

Similar Jobs

CDW Logo CDW

Application Security Engineer

Information Technology
Remote or Hybrid
US
15100 Employees
172K-240K Annually

Zeta Global Logo Zeta Global

Application Security Engineer

AdTech • Artificial Intelligence • Marketing Tech • Software • Analytics
Easy Apply
Remote or Hybrid
United States
2429 Employees
140K-180K Annually

Beyond Finance Logo Beyond Finance

Application Security Engineer

Fintech • Financial Services
Easy Apply
Remote or Hybrid
United States
2200 Employees
140K-165K Annually

SciTec Logo SciTec

Application Security Engineer

Hardware • Database • Defense
In-Office
2 Locations
194 Employees
98K-146K Annually

Similar Companies Hiring

Fairly Even Thumbnail
Hardware • Robotics • Sales • Software • Hospitality
New York, NY
30 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account