远程工作雷达

应用安全工程师 — 安全任务系统

Application Security Engineer — Secure Mission Systems

开发工程全球可投
公司rackner
薪资未公开
工作地点Remote
地域资格全球可投
时区要求无特别要求
用工类型未标注
发布时间2026-07-23
数据来源Greenhouse
前往企业招聘页投递 →
全球可投:该职位未限制候选人所在地区。仍需注意薪资可能按地区折算,以及实际签约方式(正式雇佣 / 独立合同)。

应用安全工程师 — 安全任务系统

地点:主要远程办公,偶尔在马里兰州劳雷尔市现场工作,大约每六周一次团队冲刺计划会议
资质:需要有效的最终国防部机密级安全许可

该职位支持一项待定的合同机会,具体取决于合同的授予,预计将于2026年11月开始。

将安全融入关键任务软件

在Rackner,你将帮助加强支持高影响力国防部规划和决策支持任务的安全软件。

这是一个实践性很强的应用安全岗位,你可以影响从开发到发布整个过程中如何构建安全性。你将与软件工程师、AI/ML工程师、平台团队、DevSecOps专业人员和客户技术负责人紧密合作,识别有意义的风险,支持漏洞修复,并加强安全开发实践。

你的工作不仅仅是运行扫描器或交付报告。你将帮助团队理解安全发现,区分可操作的风险与误报,验证修复,提升软件供应链安全,并更有信心地交付可靠的软件。

你将:

  • 在整个软件开发生命周期中集成应用安全测试。
  • 使用Fortify进行并支持静态应用安全测试。
  • 使用OWASP ZAP进行并支持动态应用安全测试。
  • 使用JFrog Xray支持软件组成分析和软件供应链安全。
  • 审查和分类安全发现,识别可操作的漏洞,并区分有意义的风险与误报。
  • 直接与软件工程师合作,了解根本原因,支持修复,并验证已完成的修复。
  • 将自动化安全扫描集成到安全的CI/CD和基于GitLab的开发流程中。
  • 在开发和交付过程中加强依赖管理及软件供应链控制。
  • 支持使用GitLab、Artifactory、OpenShift和Kubernetes的环境中的应用安全。
  • 参与技术评审、代码评审、软件测试和安全修复活动。
  • 生成清晰的漏洞发现、修复报告、代码评审观察结果和技术文档。
  • 支持验证软件在发布前符合相关功能、编码和安全要求。
  • 与团队协作
查看英文原文

Application Security Engineer — Secure Mission Systems

Location: Mainly remote, with onsite work in Laurel, Maryland, typically one day approximately every six weeks for team-wide sprint planning
Clearance: Active final DoD Secret clearance required

This position supports a pending contract opportunity and is contingent upon contract award, with an anticipated start in November 2026.

Build Security into Mission-Critical Software

At Rackner, you will help strengthen secure software supporting high-impact Department of Defense planning and decision-support missions.

This is a hands-on application-security role where you can influence how security is built into software from development through release. You will work closely with software engineers, AI/ML engineers, platform teams, DevSecOps professionals, and customer technical leads to identify meaningful risks, support vulnerability remediation, and strengthen secure-development practices.

Your work will go beyond running scanners or delivering reports. You will help teams understand security findings, separate actionable risks from false positives, verify fixes, improve software supply-chain security, and deliver resilient software with greater confidence.

You will:

  • Integrate application-security testing throughout the software-development lifecycle.
  • Conduct and support static application-security testing using Fortify.
  • Conduct and support dynamic application-security testing using OWASP ZAP.
  • Support software-composition analysis and software supply-chain security using JFrog Xray.
  • Review and triage security findings, identify actionable vulnerabilities, and distinguish meaningful risks from false positives.
  • Work directly with software engineers to understand root causes, support remediation, and verify completed fixes.
  • Integrate automated security scanning into secure CI/CD and GitLab-based development workflows.
  • Strengthen dependency-management and software supply-chain controls throughout development and delivery.
  • Support application security within environments using GitLab, Artifactory, OpenShift, and Kubernetes.
  • Contribute to technical reviews, code reviews, software testing, and security-remediation activities.
  • Produce clear vulnerability findings, remediation reports, code-review observations, and technical documentation.
  • Support verification that software meets applicable functional, coding, and security requirements before release.
  • Collaborate with software, AI/ML, platform, DevSecOps, and customer technical teams.

What You’ll Bring

  • Bachelor’s degree in Cybersecurity.
  • At least six years of experience involving cyber resilience, SAST, DAST, and software-vulnerability remediation.
  • Hands-on experience with Fortify, JFrog Xray, and OWASP ZAP.
  • Identifying, evaluating, triaging, and supporting remediation of application-security vulnerabilities.
  • Working directly with software-development teams to resolve security findings.
  • Experience with software supply-chain security, dependency risk, or software-composition analysis.
  • Understanding of secure software-development lifecycle practices.
  • Integrating automated security scanning into software-development or CI/CD workflows.
  • Ability to clearly document technical findings and communicate them to developers and technical stakeholders.

Experience That Can Strengthen Your Fit

Experience with several of the following can improve alignment:

  • GitLab-based development and CI/CD workflows.
  • Artifactory or similar artifact-management platforms.
  • OpenShift, Kubernetes, and containerized application environments.
  • Additional SAST, DAST, dependency-scanning, or software-composition-analysis tools.
  • Secure-code review and remediation verification.
  • Application-security testing in disconnected, restricted, or customer-managed environments.
  • Supporting classified, defense, aerospace, government, or other regulated software environments.
  • Collaboration across application security, software engineering, platform, DevSecOps, and AI/ML teams.

You do not need equal depth in every area, but your background should include direct experience with the named application-security tools and workflows.

Why Rackner

At Rackner, you will have the opportunity to protect technology supporting critical defense and public-sector missions.

You will work on more than isolated scan execution or vulnerability reports. This role combines hands-on application-security testing, vulnerability analysis, remediation verification, software supply-chain security, and close collaboration across software, AI/ML, platform, and mission-focused teams.

Rackner has delivered more than $30 million in recent federal awards and supports mission-critical work across defense, civilian, and public-sector environments. We are looking for an application-security engineer who can build on that momentum by strengthening secure delivery, helping teams resolve vulnerabilities, and improving confidence in the software reaching mission users.

Benefits & Professional Growth

  • Competitive compensation
  • Company-supported certifications aligned with current and future program work
  • 401(k) with 100% company match up to 6%
  • Medical, dental, vision, life, and disability coverage
  • Paid time off and company holidays
  • Remote-work support and home-office equipment plan
  • Fitness and wellness reimbursement
  • Weekly pay schedule
  • Professional-development and future growth opportunities

Apply

If you are an application-security professional who wants broader influence across secure development, automated security testing, vulnerability remediation, and software supply-chain security, we would like to hear from you.

本页面信息整理自 Greenhouse,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位