Rackner
Rackner

Application Security Engineer — Secure Mission Systems

engineeringfull-timeRemote
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more

About the role

<p><strong>Application Security Engineer — Secure Mission Systems</strong></p>

<p><strong>Location:</strong> Mainly remote, with onsite work in Laurel, Maryland, typically one day approximately every six weeks for team-wide sprint planning<br><strong>Clearance:</strong> Active final DoD Secret clearance required</p>

<p>This position supports a pending contract opportunity and is contingent upon contract award, with an anticipated start in November 2026.</p>

<p><strong>Build Security into Mission-Critical Software</strong></p>

<p>At Rackner, you will help strengthen secure software supporting high-impact Department of Defense planning and decision-support missions.</p>

<p>This is a hands-on application-security role where you can influence how security is built into software from development through release. You will work closely with software engineers, AI/ML engineers, platform teams, DevSecOps professionals, and customer technical leads to identify meaningful risks, support vulnerability remediation, and strengthen secure-development practices.</p>

<p>Your work will go beyond running scanners or delivering reports. You will help teams understand security findings, separate actionable risks from false positives, verify fixes, improve software supply-chain security, and deliver resilient software with greater confidence.</p>

<p><strong>You will:</strong></p>

<ul>

<li>Integrate application-security testing throughout the software-development lifecycle.</li>

<li>Conduct and support static application-security testing using Fortify.</li>

<li>Conduct and support dynamic application-security testing using OWASP ZAP.</li>

<li>Support software-composition analysis and software supply-chain security using JFrog Xray.</li>

<li>Review and triage security findings, identify actionable vulnerabilities, and distinguish meaningful risks from false positives.</li>

<li>Work directly with software engineers to understand root causes, support remediation, and verify completed fixes.</li>

<li>Integrate automated security scanning into secure CI/CD and GitLab-based development workflows.</li>

<li>Strengthen dependency-management and software supply-chain controls throughout development and delivery.</li>

<li>Support application security within environments using GitLab, Artifactory, OpenShift, and Kubernetes.</li>

<li>Contribute to technical reviews, code reviews, software testing, and security-remediation activities.</li>

<li>Produce clear vulnerability findings, remediation reports, code-review observations, and technical documentation.</li>

<li>Support verification that software meets applicable functional, coding, and security requirements before release.</li>

<li>Collaborate with software, AI/ML, platform, DevSecOps, and customer technical teams.</li>

</ul>

<p><strong>What You’ll Bring</strong></p>

<ul>

<li>Bachelor’s degree in Cybersecurity.</li>

<li>At least six years of experience involving cyber resilience, SAST, DAST, and software-vulnerability remediation.</li>

<li>Hands-on experience with Fortify, JFrog Xray, and OWASP ZAP.</li>

<li>Identifying, evaluating, triaging, and supporting remediation of application-security vulnerabilities.</li>

<li>Working directly with software-development teams to resolve security findings.</li>

<li>Experience with software supply-chain security, dependency risk, or software-composition analysis.</li>

<li>Understanding of secure software-development lifecycle practices.</li>

<li>Integrating automated security scanning into software-development or CI/CD workflows.</li>

<li>Ability to clearly document technical findings and communicate them to developers and technical stakeholders.</li>

</ul>

<p><strong>Experience That Can Strengthen Your Fit</strong></p>

<p>Experience with several of the following can improve alignment:</p>

<ul>

<li>GitLab-based development and CI/CD workflows.</li>

<li>Artifactory or similar artifact-management platforms.</li>

<li>OpenShift, Kubernetes, and containerized application environments.</li>

<li>Additional SAST, DAST, dependency-scanning, or software-composition-analysis tools.</li>

<li>Secure-code review and remediation verification.</li>

<li>Application-security testing in disconnected, restricted, or customer-managed environments.</li>

<li>Supporting classified, defense, aerospace, government, or other regulated software environments.</li>

<li>Collaboration across application security, software engineering, platform, DevSecOps, and AI/ML teams.</li>

</ul>

<p>You do not need equal depth in every area, but your background should include direct experience with the named application-security tools and workflows.</p>

<p><strong>Why Rackner</strong></p>

<p>At Rackner, you will have the opportunity to protect technology supporting critical defense and public-sector missions.</p>

<p>You will work on more than isolated scan execution or vulnerability reports. This role combines hands-on application-security testing, vulnerability analysis, remediation verification, software supply-chain security, and close collaboration across software, AI/ML, platform, and mission-focused teams.</p>

<p>Rackner has delivered more than $30 million in recent federal awards and supports mission-critical work across defense, civilian, and public-sector environments. We are looking for an application-security engineer who can build on that momentum by strengthening secure delivery, helping teams resolve vulnerabilities, and improving confidence in the software reaching mission users.</p>

<p><strong>Benefits & Professional Growth</strong></p>

<ul>

<li>Competitive compensation</li>

<li>Company-supported certifications aligned with current and future program work</li>

<li>401(k) with 100% company match up to 6%</li>

<li>Medical, dental, vision, life, and disability coverage</li>

<li>Paid time off and company holidays</li>

<li>Remote-work support and home-office equipment plan</li>

<li>Fitness and wellness reimbursement</li>

<li>Weekly pay schedule</li>

<li>Professional-development and future growth opportunities</li>

</ul>

<p><strong>Apply</strong></p>

<p>If you are an application-security professional who wants broader influence across secure development, automated security testing, vulnerability remediation, and software supply-chain security, we would like to hear from you.</p>

✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply
Apply now