Karl Storz SE & Co. KG

Application Security Engineer III

Karl Storz SE & Co. KG
Apply
25 days ago
Stafford, TX, USASenior

Responsibilities

  • Lead and maintain DoD Authorization to Operate certifications and serve as the primary cybersecurity contact for DoD-related projects.
  • Manage RMF compliance activities, including STIG and SCAP scanning, POA&M management, risk mitigation planning, audits, renewals, and customer-facing reviews.
  • Author and maintain cybersecurity documentation, risk analyses, and compliance reports.
  • Verify cybersecurity requirements through testing, documentation, and validation activities.
  • Support secure software development, threat modeling, vulnerability management, product security reviews, and risk mitigation recommendations.
  • Design and maintain DevSecOps pipelines with automated security testing, vulnerability scanning, and compliance monitoring.
  • Establish and maintain cybersecurity lab environments and test infrastructure.
  • Collaborate with Software Engineering, Systems Engineering, Quality, Regulatory, IT, Operations, R&D, and Product Management teams.
  • Communicate cybersecurity risks and recommendations to technical and non-technical stakeholders and participate in customer meetings, technical reviews, and occasional on-site visits.

Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related technical field.
  • At least 5 years of cybersecurity experience, or 4 years with a master's degree.
  • Experience supporting application, product, or embedded cybersecurity in regulated industries such as medical devices, defense, or aerospace.
  • Hands-on experience with DoD RMF, STIGs, SCAP tools, and POA&M management.
  • Knowledge of NIST 800-53 and NIST 800-171 frameworks.
  • Experience with secure software development, vulnerability management, risk assessment, and DevSecOps practices.
  • Experience with Windows and Linux hardening, network security, and system compliance validation.
  • Preferred experience obtaining or maintaining DoD ATO certifications and knowledge of FDA cybersecurity guidance and medical device security standards.
  • Preferred certifications include CISSP, Security+, CEH, or GSEC.
  • Preferred experience includes cloud security, container security, automated testing frameworks, Linux, Windows Server, virtualized environments, and network security architectures.
  • Strong communication, analytical, organizational, and problem-solving skills.

Benefits

  • Up to 10% travel is required.
  • The role requires sitting for extended periods and occasionally lifting equipment up to 20 pounds.
  • Work is performed in a fast-paced, collaborative environment supporting regulated medical technology products.

Tech Stack

LinuxWindows

Categories

Karl Storz SE & Co. KG

About Karl Storz SE & Co. KG

5,001-10,000 employees
Contact me