1 month ago
Remote, United StatesSenior
Responsibilities
- Integrate application-security testing throughout the software-development lifecycle.
- Conduct and support SAST using Fortify and DAST using OWASP ZAP.
- Support software-composition analysis and software supply-chain security using JFrog Xray.
- Review, triage, and document security findings; identify actionable vulnerabilities and false positives.
- Work with software engineers to understand root causes, support remediation, and verify completed fixes.
- Integrate automated security scanning into GitLab-based development workflows.
- Strengthen dependency-management and software supply-chain controls.
- Support application security in GitLab, Artifactory, OpenShift, and Kubernetes environments.
- Contribute to technical reviews, code reviews, software testing, and security-remediation activities.
- Produce vulnerability findings, remediation reports, code-review observations, and technical documentation.
- Verify that software meets applicable functional, coding, and security requirements before release.
- Collaborate with software, AI/ML, platform, DevSecOps, and customer technical teams.
Requirements
- Bachelor’s degree in Cybersecurity.
- At least six years of experience involving cyber resilience, SAST, DAST, and software-vulnerability remediation.
- Hands-on experience with Fortify, JFrog Xray, and OWASP ZAP.
- Experience identifying, evaluating, triaging, and remediating application-security vulnerabilities.
- Experience working directly with software-development teams to resolve security findings.
- Experience with software supply-chain security, dependency risk, or software-composition analysis.
- Understanding of secure software-development lifecycle practices.
- Experience integrating automated security scanning into software-development or CI/CD workflows.
- Ability to document technical findings clearly and communicate them to developers and technical stakeholders.
- Active final DoD Secret clearance.
- Preferred experience includes GitLab CI/CD workflows, Artifactory, OpenShift, Kubernetes, containerized environments, additional security-scanning tools, secure-code review, remediation verification, disconnected or restricted environments, and classified, defense, aerospace, government, or regulated software environments.
Benefits
- Competitive compensation, with no specific base salary stated.
- Company-supported certifications aligned with current and future program work.
- 401(k) with 100% company match up to 6%.
- Medical, dental, vision, life, and disability coverage.
- Paid time off and company holidays.
- Remote-work support and a home-office equipment plan.
- Fitness and wellness reimbursement.
- Weekly pay schedule.
- Professional-development and future growth opportunities.
- Mainly remote work with onsite team-wide sprint planning in Laurel, Maryland, typically approximately one day every six weeks.
- Position is contingent upon contract award, with an anticipated November 2026 start.
Tech Stack
KubernetesOpenShift
