Application Security Engineer
Core
Perform security reviews, threat modeling, and vulnerability analysis for mission-critical defense, intelligence, and commercial software products.
Role type
Senior IC application security engineer
Builds
Secure-by-default software products for defense and intelligence clients
Domain
Cybersecurity / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
software engineering, modern high-level programming languages (Java, Golang, Javascript, Python), code vulnerability evaluation, complex architecture design (SOA, micro-services), static code analysis (CodeQL), black-box web application testing
Preferred skills
offensive security collaboration, security automation development, software supply chain security, hardware-backed key signing
Technologies
CodeQL, in-toto, GPG
Responsibilities
Perform full-scope security reviews (whitebox, greybox, blackbox), threat model and assess risks for product architects, identify and resolve novel security vulnerabilities, develop security automation to eliminate weaknesses, lead strategic security initiatives
Seniority
Senior, hands-on IC
