Senior Application Security Engineering Lead

SciTec Incorporated

Boulder (CO)

On-site

USD 155,000 - 185,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401(k) match
Company-paid Health Insurance
Discretionary Performance Bonus
Paid Parental Leave
Flexible Work Hours
Life Insurance
Long-term Disability
Vision Insurance
Dental Insurance
HSA Medical Insurance

Job summary

SciTec Incorporated is seeking an Application Security Engineer Lead to secure mission-critical software for DoD programs. You will guide hands-on security analysis, embed security in development, and collaborate with software engineers to strengthen CI/CD pipelines.

The role requires 8+ years in cybersecurity or software development, DoD security clearance, and strong code-analysis skills. Join a fast-paced team delivering OPIR data processing for national defense, with comprehensive benefits.

Qualifications

  • Bachelor’s degree plus 8+ years of professional experience in cybersecurity or software development, or equivalent experience.
  • 2+ years of experience focused on application/software security.
  • Experience analyzing source code for security flaws.
  • Familiarity with secure software development practices.
  • Strong analytical and problem-solving skills.
  • Detail-oriented with strong written and verbal communication abilities.
  • Ability to qualify for and maintain a DoD Secret security clearance.
  • Ability to meet DoD 8140.01 Cyberspace Workforce Management requirements within six months of hire.
  • Ability to effectively collaborate with government customer team members and other engineers.
  • Active DoD Secret clearance or higher.
  • Experience identifying, exploiting, and remediating application vulnerabilities.
  • Credit for published CVEs is a strong plus.
  • Proficiency in C++, Python, JavaScript, Rust.
  • Experience configuring and operating static analysis tools (Coverity, Klocwork, SonarQube).
  • Experience configuring and operating software composition analysis tools (Snyk, Sonatype, Anchore, JFrog Xray).
  • Experience with fuzzing frameworks (AFL, AFL++, honggfuzz, or similar).
  • Experience with debugging, runtime instrumentation, or reverse engineering (strace, eBPF, Ghidra, IDA Pro).
  • Familiarity with threat modeling methodologies and frameworks such as MITRE ATT&CK.
  • Experience working in DevSecOps or Agile development environments.

Responsibilities

  • Perform application security analysis using both automated and manual techniques, including SAST, SCA, fuzzing, and manual reviews.
  • Lead an application security team in support of multiple programs.
  • Identify, analyze, and help remediate application vulnerabilities.
  • Support software engineers in integrating security into designs and CI/CD/DevSecOps pipelines.
  • Design, implement, and improve continuous integration security analysis tooling.
  • Tune and maintain security tools to reduce false positives and improve signal quality.
  • Assist development teams in understanding findings and implementing fixes.
  • Support threat modeling and secure design reviews.
  • Stay current with emerging vulnerabilities and mitigation strategies.
  • Document findings, recommendations, and best practices.
  • Perform other duties as assigned.

Skills

Application security
Code analysis
Secure SDLC
Analytical skills
Communication
Security clearance
DoD 8140 requirements
Collaboration
DoD Secret clearance
C++
Python
JavaScript
Rust

Education

Bachelor’s degree

Tools

Coverity
Klocwork
SonarQube
Snyk
Sonatype
Anchore
JFrog Xray
AFL
AFL++
honggfuzz
strace
eBPF
Ghidra
IDA Pro
MITRE ATT&CK

Job description

SciTec, a wholly owned subsidiary of Firefly Aerospace, is a dynamic non-traditional defense contractor that delivers advanced technologies in support of U.S. National Security and Defense. For more than forty-five years, we have supported Department of Defense customers by developing innovative remote sensing algorithms, tools, and techniques to deliver world-class data exploitation capabilities supporting missile defense; intelligence, surveillance, & reconnaissance; space domain awareness; and aircraft survivability missions.

Important Notice: SciTec exclusively works on U.S. government contracts that require U.S. citizenship for all employees. Applicants that do not meet this requirement will not be considered.

SciTec has an immediate opportunity for a talented engineer to support our programs delivering Next-Generation Missile Warning software. This is a unique opportunity to join a business delivering core capabilities for National defense. You will work within a fast-paced team delivering end-to-end software processing of Overhead Persistent InfraRed (OPIR) sensor data for Missile Warning, Missile Defense, Battlespace Awareness, and Technical Intelligence.

We are seeking an Application Security Engineer Lead to help secure mission-critical software systems by identifying, analyzing, and mitigating application-level vulnerabilities. This role focuses on hands-on security analysis, tooling integration, and working directly with software engineers to embed security into the development lifecycle.

The ideal candidate combines strong technical security skills with the ability to collaborate effectively with developers in a DevSecOps environment.

Responsibilities
  • Perform application security analysis using both automated and manual techniques, including:
    • Static code analysis (SAST)
    • Software composition analysis (SCA)
    • Fuzzing
    • Manual code and design reviews
  • Lead an application security team in support of multiple programs
  • Identify, analyze, and help remediate application vulnerabilities
  • Support software engineers in integrating security considerations into system and application designs
  • Integrate and maintain application security tooling within CI/CD and DevSecOps pipelines
  • Design, implement, and improve continuous integration security analysis tooling
  • Tune and maintain security tools to reduce false positives and improve signal quality
  • Assist development teams in understanding findings and implementing effective fixes
  • Support threat modeling and secure design reviews
  • Stay current with emerging vulnerabilities, attack techniques, and mitigation strategies
  • Document findings, recommendations, and best practices
  • Perform other duties as assigned
  • Bachelor’s degree plus 8+ years of professional experience in cybersecurity or software development, or equivalent experience
  • 2+ years of experience focused on application/software security
  • Experience analyzing source code for security flaws
  • Familiarity with secure software development practices
  • Strong analytical and problem-solving skills
  • Detail-oriented with strong written and verbal communication abilities
  • Ability to qualify for and maintain a DoD Secret security clearance
  • Ability to meet DoD 8140.01 Cyberspace Workforce Management requirements within six months of hire
  • Ability to effectively collaborate with government customer team members and other engineers

Candidates who have any of the following skills will be preferred:

  • Active DoD Secret clearance or higher
  • Experience identifying, exploiting, and remediating application vulnerabilities
    • Credit for published CVEs is a strong plus
  • Proficiency in one or more programming languages such as C++, Python, JavaScript, Rust
  • Experience configuring and operating static analysis tools (e.g., Coverity, Klocwork, SonarQube)
  • Experience configuring and operating software composition analysis tools (e.g., Snyk, Sonatype, Anchore, JFrog Xray)
  • Experience with fuzzing frameworks (AFL, AFL++, honggfuzz, or similar)
  • Experience with debugging, runtime instrumentation, or reverse engineering, including tools such as strace, eBPF, Ghidra or IDA Pro
  • Familiarity with threat modeling methodologies and frameworks such as MITRE ATT&CK
  • Experience working in DevSecOps or Agile development environments

*Resumes, Cover Letters, and Applications which are generated by AI will not be considered for employment.

Colorado Residents: In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.

SciTec offers a highly competitive salary and benefits package, including:

  • 4% Safe Harbor 401(k) match
  • 100% company paid HSA Medical insurance, with a choice of 2 buy-up options
  • 80% company paid Dental insurance
  • 100% company paid Vision insurance
  • 100% company paid Life insurance
  • 100% company paid Long-term Disability insurance
  • 100% company paid Hospital Indemnity insurance
  • Voluntary Accident and Critical Illness insurance
  • Short-term Disability insurance
  • Annual Profit-Sharing Plan
  • Discretionary Performance Bonus
  • Paid Parental Leave
  • Generous Paid Time Off, including Holiday, Vacation, and Sick Pay
  • Flexible Work Hours

The pay range for this position is $155,000 - $185,000 / year. SciTec considers several factors when extending an offer of employment, including but not limited to the role and associated responsibilities, a candidate's work experience, education/training, and key skills. This is not a guarantee of compensation.

SciTec is proud to be an Equal Opportunity employer. VET/Disabled.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineering Lead
Senior Application Security Engineering Lead

SciTec • Boulder (CO)

On-site
USD 155,000 - 185,000
401(k) match
Health insurance
Dental and Vision insurance
+2
Staff/Sr. Staff Application Security Engineer
Staff/Sr. Staff Application Security Engineer

SciTec Incorporated • Boulder (CO)

On-site
USD 96,000 - 146,000
401(k) match
100% company paid health insurance
Generous Paid Time Off
Staff/Sr. Staff Application Security Engineer
Staff/Sr. Staff Application Security Engineer

SciTec • Boulder (CO)

On-site
USD 96,000 - 146,000
100% company paid HSA Medical insurance
80% company paid Dental insurance
Flexible Work Hours
Staff/Sr. Staff Application Security Engineer
Staff/Sr. Staff Application Security Engineer

SciTec • Princeton (NJ)

On-site
USD 96,000 - 146,000
401(k) match
100% company-paid HSA Medical insurance
Annual Profit-Sharing Plan
Staff/Sr. Staff Application Security Engineer
Staff/Sr. Staff Application Security Engineer

SciTec • Princeton (KY)

On-site
USD 98,000 - 146,000
401(k) match
Health insurance
Vision insurance
+6
Staff / Sr Staff C++ Software Engineer
Staff / Sr Staff C++ Software Engineer

SciTec • Boulder (CO)

On-site
USD 96,000 - 140,000
4% Safe Harbor 401(k) match
100% company paid HSA Medical insurance
80% company paid Dental insurance
+5
Staff / Sr Staff C++ Software Engineer
Staff / Sr Staff C++ Software Engineer

SciTec Incorporated • Boulder (CO)

On-site
USD 96,000 - 140,000
4% Safe Harbor 401(k) match
100% company paid HSA Medical insurance
80% company paid Dental insurance
+1
Senior C++ Software Engineer
Senior C++ Software Engineer

SciTec Incorporated • Boulder (CO)

On-site
USD 156,000 - 193,000
4% Safe Harbor 401(k) match
Company-paid HSA Medical insurance
Dental insurance (80%)
+9
Sr Staff/Senior Software Engineer (Clearance Required)
Sr Staff/Senior Software Engineer (Clearance Required)

SciTec • Aurora (CO)

On-site
USD 130,000 - 170,000
4% Safe Harbor 401(k) match
100% company paid HSA Medical insurance
Discretionary Performance Bonus
+1
Staff / Sr Staff DevSecOps Engineer
Staff / Sr Staff DevSecOps Engineer

SciTec • Dayton (KY)

On-site
USD 91,000 - 141,000
4% Safe Harbor 401(k) match
Company-paid Health Insurance/HSA
Profit-Sharing Plan
+3