Staff Application Security Engineer (R5949)
Core
Build and advance a scalable, developer-centered application security program, establishing company-wide secure SDLC policies and partnering with engineering teams to improve secure development and software supply-chain maturity.
Role type
Staff individual-contributor application security engineer
Builds
Secure software development lifecycle (SDLC) policies, standards, tooling, and supply-chain security practices
Domain
Defense technology, secure software engineering, DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security program design, secure SDLC implementation, SAST/DAST/SCA tooling, threat modeling, software supply-chain security, open-source governance, CI/CD pipeline security, vulnerability management, secure coding practices
Preferred skills
SLSA practices, signed software attestations, VEX/CSAF/SBOM formats, cloud-native security, Kubernetes security
Technologies
SAST, DAST, SCA, SBOM, VEX, SPDX, CycloneDX, Kubernetes, CI/CD pipelines
Responsibilities
Establish and improve company-wide secure SDLC policies and standards; Translate security policy into achievable requirements for development teams; Assess and lead improvement roadmaps for CI/CD pipelines and release processes; Develop secure-development guidance, reference architectures, and security guardrails; Partner with development teams to triage and remediate application-security findings; Evaluate and operationalize application-security tooling (SAST, DAST, SCA, secrets detection, IaC scanning); Lead threat modeling and secure design reviews; Establish risk-based vulnerability management and open-source software governance processes; Mature software supply-chain security practices (SBOMs, VEX, artifact signing, provenance); Secure CI/CD pipelines and deployment workflows; Create executive-ready metrics on secure-SDLC adoption and program maturity
Seniority
Staff, hands-on IC with significant influence across engineering and leadership