Application Security Engineer III

KARL STORZ North America

Stafford (TX)

On-site

USD 100,000 - 130,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

KARL STORZ North America is looking for an Application Security Engineer III to lead cybersecurity compliance and secure product development initiatives. This role involves maintaining DoD ATO certifications and ensuring compliance throughout the development lifecycle.

Applicants should have a Bachelor's degree in Computer Science or related field, with over 5 years of cybersecurity experience. This position offers the chance to work in a fast-paced, collaborative environment within the medical technology sector.

Qualifications

  • 5+ years of cybersecurity experience, 4+ with a Master's degree.
  • Experience in regulated industries such as medical devices or defense.
  • Hands-on with DoD RMF and secure software development.

Responsibilities

  • Lead and maintain DoD Authorization to Operate (ATO) certifications.
  • Manage RMF compliance activities and support certification audits.
  • Design DevSecOps pipelines with automated security testing.

Skills

Cybersecurity experience
Communication skills
Analytical skills
Problem-solving skills

Education

Bachelor's degree in Computer Science, Cybersecurity, or related field

Tools

DoD RMF
STIGs
SCAP tools
POA&M management

Job description

Why KARL STORZ?

At KARL STORZ, we are driven by innovation and a commitment to improving patient outcomes through cutting‑edge medical technology. As a global leader in endoscopy and medical imaging, we offer an environment where collaboration, technical excellence, and continuous learning are highly valued. Join a team where your cybersecurity expertise will directly contribute to the development of secure, compliant, and life‑changing healthcare technologies.

Position Summary

The Application Security Engineer III serves as the technical lead for cybersecurity compliance and secure product development initiatives, with primary responsibility for achieving and maintaining Department of Defense (DoD) Authorization to Operate (ATO) certifications under the Risk Management Framework (RMF). This role partners closely with Software Engineering, Systems Engineering, Quality, Regulatory, and Product Management teams to ensure products meet cybersecurity requirements throughout the development lifecycle.

Key Responsibilities
DoD RMF & ATO Leadership
  • Lead and maintain DoD Authorization to Operate (ATO) certifications.
  • Serve as the primary cybersecurity contact for DoD‑related projects.
  • Manage RMF compliance activities, including STIG and SCAP scanning, POA&M management, and risk mitigation planning.
  • Author and maintain cybersecurity documentation, risk analyses, and compliance reports.
  • Support certification audits, renewals, and customer‑facing cybersecurity reviews.
Product Security & Verification
  • Verify cybersecurity requirements through testing, documentation, and validation activities.
  • Partner with engineering teams to implement secure development practices.
  • Support threat modeling, vulnerability management, and security testing throughout the SDLC.
  • Participate in product security reviews and provide risk mitigation recommendations.
DevSecOps & Security Operations
  • Design and maintain DevSecOps pipelines with automated security testing and vulnerability scanning.
  • Support secure CI/CD practices and compliance monitoring.
  • Establish and maintain cybersecurity lab environments and test infrastructure.
Cross‑Functional Collaboration
  • Collaborate with R&D, Quality, Regulatory, IT, Operations, and Product Management teams.
  • Communicate cybersecurity risks, requirements, and recommendations to technical and non‑technical stakeholders.
  • Participate in customer meetings, technical reviews, and occasional on‑site visits.
Qualifications
Required
  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related technical field.
  • 5+ years of cybersecurity experience (4+ years with a Master's degree).
  • Experience supporting application, product, or embedded cybersecurity in regulated industries such as medical devices, defense, or aerospace.
  • Hands‑on experience with DoD RMF, STIGs, SCAP tools, and POA&M management.
  • Knowledge of NIST frameworks, including NIST 800‑53 and NIST 800‑171.
  • Experience with secure software development, vulnerability management, risk assessment, and DevSecOps practices.
  • Experience with Windows and Linux hardening, network security, and system compliance validation.
  • Strong communication, analytical, organizational, and problem‑solving skills.
Preferred
  • Experience obtaining or maintaining DoD ATO certifications.
  • Knowledge of FDA cybersecurity guidance and medical device security standards.
  • Certifications such as CISSP, Security+, CEH, or GSEC.
  • Experience with cloud security, container security, and automated testing frameworks.
  • Experience working in Linux, Windows Server, virtualized environments, and network security architectures.
  • Master's degree in a related technical discipline.
Additional Information
  • Travel: Up to 10%
  • Physical Requirements: Ability to sit for extended periods and lift equipment up to 20 pounds occasionally.
  • Work Environment: Fast‑paced, collaborative environment supporting highly regulated medical technology products.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer III
Application Security Engineer III

KARL STORZ SE & Co. KG • Stafford (TX)

On-site
USD 90,000 - 120,000
Medical / Dental / Vision benefits
401(k) retirement savings plan with a match
Tuition pre-reimbursement up to $5,250 annually
+1
Senior DoD RMF & Product Security Engineer
Senior DoD RMF & Product Security Engineer

KARL STORZ North America • Stafford (TX)

On-site
USD 100,000 - 130,000
Product Security Engineer - Medical Device
Product Security Engineer - Medical Device

BioTalent • San Diego (CA)

Hybrid
USD 90,000 - 120,000
Cybersecurity Analyst, RMF & ATO
Cybersecurity Analyst, RMF & ATO

JBS International • North Bethesda (MD)

Hybrid
USD 90,000 - 130,000
Cybersecurity Analyst, RMF & ATO
Cybersecurity Analyst, RMF & ATO

JBS International • Virginia Beach (VA)

Hybrid
USD 90,000 - 140,000
Cybersecurity Analyst, RMF & ATO
Cybersecurity Analyst, RMF & ATO

JBS International, Inc. • United States

On-site
USD 110,000 - 150,000
Cybersecurity Analyst, RMF & ATO
Cybersecurity Analyst, RMF & ATO

JBS International • Hayward Park (CA)

Hybrid
USD 120,000 - 150,000
Sr. DevSecOps Engineer
Sr. DevSecOps Engineer

UIC Arctic Response Services, LLC • San Diego (CA)

On-site
USD 120,000 - 160,000
Cybersecurity Analyst, RMF & ATO
Cybersecurity Analyst, RMF & ATO

JBS International • Los Angeles (CA)

Hybrid
USD 90,000 - 150,000
Cyber Security Engineer
Cyber Security Engineer

Systems Planning & Analysis • Huntsville (AL)

On-site
USD 80,000 - 110,000
Competitive compensation
Industry-leading 401k contribution