Senior Application Security Engineer

Milestone Technologies, Inc.

Torrance (CA)

On-site

USD 140,000 - 180,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Milestone Technologies, Inc. is seeking a Senior Application Security Engineer to embed security into the software development lifecycle for custom applications handling CUI and ITAR-regulated data.

The role focuses on secure design, threat modeling, and secure coding across Python/Java, deployed on AWS, Azure, Palantir Foundry, and Kubernetes. You will collaborate with engineering teams to enforce data protection, implement secure API designs, and support DOE/NRC regulatory programs while

Qualifications

  • 5+ years in application security or security engineering with ownership of an AppSec program.
  • Hands-on security across AWS and Azure including IAM, secrets management, logging/monitoring.
  • Experience securing Kubernetes environments (RBAC, network policies, image scanning).
  • Proficient in reading Python and Java code for secure fixes (OWASP Top 10).
  • Experience securing REST/GraphQL APIs, OAuth2/OIDC, and API gateway controls.
  • Direct experience with CUI/ITAR data handling requirements.
  • Strong ability to work embedded with engineering teams as a trusted advisor.

Responsibilities

  • Partner with software engineers to identify and remediate security risks in custom applications processing CUI, ITAR, and UCNI.
  • Perform threat modeling, secure architecture reviews, and design reviews for new features and services.
  • Conduct secure code reviews for Python and Java codebases.
  • Review and harden API design/API gateway configurations (OAuth2/OIDC, mTLS).
  • Contribute security architecture artifacts (data flow diagrams, trust-zone diagrams).
  • Own and mature the application security program aligned to CMMC 2.0 Level 2, including SSP/POA&M.
  • Support DOE/NRC program alignment and audits for controlled systems.
  • Secure CI/CD pipelines in GitHub to satisfy regulatory requirements.
  • Define guardrails for Kubernetes workloads and AI data handling guidelines.
  • Work with Palantir Foundry pipelines to enforce data classification and access controls.
  • Develop secure coding training and threat modeling workshops for engineers.
  • Evaluate new tools and cloud services for security posture.

Skills

Application security
Cloud security (AWS/Azure)
Kubernetes security
CI/CD security (GitHub Actions)
Threat modeling (STRIDE)
Secure SDLC
Python/Java secure coding
API security (REST/GraphQL)
Regulatory compliance (CMMC/DOE/NRC)
Engineering collaboration

Tools

GitHub Actions
Palantir Foundry
Kubernetes tooling
OWASP ZAP
SAST/DAST tooling

Job description

** W2 only (not available for C2C/1099 consulting **

** Possible full-time conversion in the future **

** Onsite position in Torrance **

Description

The Senior Application Security Engineer will focus on embedding security directly into the software development lifecycle for custom applications handling Controlled Unclassified Information (CUI) and ITAR-regulated data, in an environment governed by CMMC 2.0, Department of Energy (DOE) cybersecurity requirements, and Nuclear Regulatory Commission (NRC) cyber security standards. This role partners closely with software engineering teams building custom applications and APIs primarily in Python and Java, deployed on AWS, Azure, Palantir Foundry, Kubernetes, and GitHub, and helps establish secure, compliant patterns for integrating AI tools (Claude, OpenAI) into engineering workflows without compromising data protection, safeguards, or regulatory obligations.

Key Responsibilities
  • Partner with software engineers throughout design, development, and deployment to identify and remediate security risks in custom applications processing CUI, ITAR, and Unclassified Controlled Nuclear Information (UCNI).
  • Perform threat modeling, secure architecture reviews, and design reviews for new features and services, with particular attention to data flows across AWS, Azure, and Palantir Foundry.
  • Conduct manual and tool-assisted secure code review of Python and Java codebases, identifying issues such as injection flaws, insecure deserialization, broken authentication/authorization, and insecure cryptographic usage.
  • Review and harden API design and implementation (REST/GraphQL) — authentication and authorization schemes (OAuth 2.0/OIDC, mTLS), input validation, rate limiting, schema validation, and API gateway configuration — across internally built and third-party-integrated APIs, including AI service APIs (Claude, OpenAI).
  • Contribute light-touch security architecture artifacts — data flow diagrams, trust-zone/boundary diagrams, and control-to-requirement mappings — to help engineering teams design new systems in alignment with existing security architecture and reference patterns; elevate to enterprise/security architecture as needed for larger initiatives.
  • Own and mature the application security program aligned to CMMC 2.0 Level 2 (NIST SP 800-171, and 800-172 where required), including SSP and POA&M maintenance for application-layer scope.
  • Support DOE cybersecurity program requirements (e.g., DOE O 205.1, DOE O 471.6, RMF per NIST SP 800-37) for systems and applications supporting DOE contracts or facilities.
  • Support NRC cyber security program alignment (10 CFR 73.54, Regulatory Guide 5.71) for applications supporting critical digital assets, including defense-in-depth boundary controls and access-control requirements.
  • Secure CI/CD pipelines in GitHub (branch protection, secrets management, signed commits/artifacts, dependency and supply-chain risk controls) to satisfy CMMC/DOE/NRC audit and traceability requirements.
  • Define and enforce security guardrails for Kubernetes workloads (pod security standards, network policies, image scanning, admission controls, secrets/config management) consistent with system security plan boundaries.
  • Establish security and data-handling guidelines for the use of AI coding/productivity assistants (Claude, OpenAI/Azure OpenAI) — covering data residency, prompt/data leakage prevention, model access controls, and audit logging consistent with CUI/ITAR/UCNI and safeguards information (SGI) boundaries.
  • Work with data engineering/platform teams to ensure Palantir Foundry pipelines, ontologies, and access controls correctly enforce data classification, need-to-know, least privilege, and export-control/safeguards boundaries.
  • Build and deliver secure coding training and threat-modeling workshops for engineering teams, incorporating CMMC/DOE/NRC-specific handling requirements.
  • Evaluate new tools and cloud services for security posture and regulatory suitability prior to adoption, including AI/LLM-based tooling.
Required Qualifications
  • 5+ years in application security, product security, or security engineering, with demonstrated ownership of an AppSec program or major component of one.
  • Hands-on experience securing applications and infrastructure across AWS and Azure (IAM, network segmentation, key/secrets management, logging/monitoring, and cloud-native security tooling).
  • Experience with Kubernetes security (RBAC, network policies, admission controllers, image/container scanning, runtime protection).
  • Experience securing GitHub-based CI/CD pipelines (Actions, branch protections, secret scanning, SBOM/dependency management, supply-chain security practices).
  • Practical understanding of secure SDLC practices: threat modeling (e.g., STRIDE), secure code review, SAST/DAST/SCA tooling, and remediation workflows.
  • Proficiency reading and reviewing Python and Java code, with the ability to identify and help remediate security defects (e.g., OWASP Top 10 issues) directly in source, not just via scanner output.
  • Experience securing REST and/or GraphQL APIs, including authentication/authorization schemes (OAuth 2.0/OIDC), input validation, and API gateway/WAF controls.
  • Direct experience working under CUI and/or ITAR data-handling requirements.
  • Strong communication skills and the proven ability to work embedded with engineering teams as a trusted advisor rather than a gatekeeper.
Preferred Qualifications
  • Prior hands-on software development experience in Python and/or Java (e.g., prior developer or DevSecOps role) beyond code review.
  • Experience with Palantir Foundry security model — ontology-level access controls, pipeline security, data lineage, and classification enforcement.
  • Prior experience supporting a DoE facility, national laboratory, or DoE contractor cybersecurity program.
  • Direct working knowledge of CMMC 2.0 and its underlying NIST SP 800-171 control families, including practical experience preparing for or supporting a CMMC assessment.
  • Experience operating within DoE or NRC regulatory environments, or comparable federal/critical-infrastructure cybersecurity frameworks (e.g., NIST SP 800-53, RMF, 10 CFR 73.54).
  • Prior experience supporting an NRC-licensed facility or NRC-regulated vendor cyber security plan (10 CFR 73.54).
  • Familiarity with DFARS 252.204-7012, DoD Assessment Methodology, or Unclassified Controlled Nuclear Information (UCNI) / Safeguards Information (SGI) handling requirements.
  • Relevant certifications: CISSP, CMMC Certified Professional (CCP) / CMMC Certified Assessor (CCA), OSCP, GWAPT, GPEN, or equivalent.
  • Experience with Infrastructure-as-Code security (Terraform, CloudFormation, Bicep) and policy-as-code (OPA/Gatekeeper, Sentinel).
  • Experience with API security testing/tooling (e.g., OWASP ZAP, Postman/Newman security test suites, API-focused SAST/DAST) and API security standards such as the OWASP API Security Top 10.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Software Engineer On-site
Security Software Engineer On-site

Eccalon, LLC • Detroit (MI)

On-site
USD 110,000 - 145,000
Security Software Engineer
Security Software Engineer

Eccalon, LLC • Hanover (MD)

On-site
USD 120,000 - 190,000
Senior Application Security Engineer
Senior Application Security Engineer

Valar Atomics • Torrance (CA)

On-site
USD 165,000 - 190,000
Competitive base salary
Equity ownership
Comprehensive medical benefits
+3
Cybersecurity Engineer - Cloud, Ops (human)
Cybersecurity Engineer - Cloud, Ops (human)

NEURA Robotics • Germany (OH)

On-site
USD 120,000 - 160,000
Application Security Engineer ( Only USC Or GC)
Application Security Engineer ( Only USC Or GC)

LinQ Global Group • Philadelphia

Hybrid
USD 110,000 - 160,000
Cybersecurity Engineer (DevSecOps)
Cybersecurity Engineer (DevSecOps)

Arcfield • Home Creek (VA)

On-site
USD 120,000 - 170,000
Health Insurance
Life Insurance
Paid Time Off
+6
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000
Application Security Architect & Engineer
Application Security Architect & Engineer

Mbi Llc • Richmond (VA)

On-site
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States

On-site
USD 120,000 - 150,000