
Application Security Engineer III
Karl Storz SE & Co. KG25 days ago
Stafford, TX, USASenior
Responsibilities
- Lead and maintain DoD Authorization to Operate certifications and serve as the primary cybersecurity contact for DoD-related projects.
- Manage RMF compliance activities, including STIG and SCAP scanning, POA&M management, risk mitigation planning, audits, renewals, and customer-facing reviews.
- Author and maintain cybersecurity documentation, risk analyses, and compliance reports.
- Verify cybersecurity requirements through testing, documentation, and validation activities.
- Support secure software development, threat modeling, vulnerability management, product security reviews, and risk mitigation recommendations.
- Design and maintain DevSecOps pipelines with automated security testing, vulnerability scanning, and compliance monitoring.
- Establish and maintain cybersecurity lab environments and test infrastructure.
- Collaborate with Software Engineering, Systems Engineering, Quality, Regulatory, IT, Operations, R&D, and Product Management teams.
- Communicate cybersecurity risks and recommendations to technical and non-technical stakeholders and participate in customer meetings, technical reviews, and occasional on-site visits.
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related technical field.
- At least 5 years of cybersecurity experience, or 4 years with a master's degree.
- Experience supporting application, product, or embedded cybersecurity in regulated industries such as medical devices, defense, or aerospace.
- Hands-on experience with DoD RMF, STIGs, SCAP tools, and POA&M management.
- Knowledge of NIST 800-53 and NIST 800-171 frameworks.
- Experience with secure software development, vulnerability management, risk assessment, and DevSecOps practices.
- Experience with Windows and Linux hardening, network security, and system compliance validation.
- Preferred experience obtaining or maintaining DoD ATO certifications and knowledge of FDA cybersecurity guidance and medical device security standards.
- Preferred certifications include CISSP, Security+, CEH, or GSEC.
- Preferred experience includes cloud security, container security, automated testing frameworks, Linux, Windows Server, virtualized environments, and network security architectures.
- Strong communication, analytical, organizational, and problem-solving skills.
Benefits
- Up to 10% travel is required.
- The role requires sitting for extended periods and occasionally lifting equipment up to 20 pounds.
- Work is performed in a fast-paced, collaborative environment supporting regulated medical technology products.