Get more replies from employers
Send a job-specific resume in minutes.
COLSA Corporation in Huntsville, AL is seeking an experienced Software Assurance (SwA) Engineer to help secure complex software across the SDLC. You will identify vulnerabilities, perform SAST/DAST/IAST testing, and support materiel release readiness.
The role requires 8+ years in software security, a bachelor's in a related field, and the ability to obtain a Secret clearance with potential TS clearance. Collaboration across teams and familiarity with CWEs/CVEs and security tools are highly
COLSA Corporation is seeking an experienced Software Assurance (SwA) Engineer to join our team in Huntsville, Alabama. This role will support the security and integrity of complex software applications throughout the software development lifecycle (SDLC), with a focus on identifying vulnerabilities, conducting application security testing, and supporting software assessment, authorization, and readiness for materiel release.
The ideal candidate brings strong technical expertise in software assurance and application security, with the ability to analyze complex software systems, identify and assess security weaknesses, and develop effective solutions to mitigate risk.
Conducts Application Security Testing: Plans and executes investigations and tests of considerable complexity, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Interactive Application Security Testing (IAST), fuzzing, and penetration testing.*
Vulnerability Analysis & Remediation: Analyzes source code and compiled binaries to identify security flaws, mapping findings to Common Weakness Enumerations (CWEs) and Common Vulnerabilities and Exposures (CVEs).*
Advanced Problem Solving: Develops and applies advanced methods, theories, and research techniques in the investigation and solution of complex and advanced software security problems.*
Project Coordination: Coordinates efforts of software engineers, development teams, and technical support staff in the performance of assigned SwA projects, ensuring security is integrated throughout the SDLC.*
Materiel Release Support: Plans, conducts, and technically directs major phases of significant SwA projects to ensure software meets the rigorous safety and security standards required for materiel release.*
Technical Review: Reviews the completion and implementation of technical products, ensuring that vulnerability remediations are effective and compliant with current security practices.*
Tool & Vendor Evaluation: May evaluate vendor capabilities and commercial/open-source SwA tools (e.g., Fortify, Coverity, Semgrep, Cppcheck, etc.) to provide required security testing products or services.
Industry Research: Reviews literature, patents, and current practices relevant to the solution of assigned application security projects and threat landscapes.*
Technical Leadership: May provide technical consultation to other organizations regarding secure coding practices and may provide work leadership to lower-level employees.
At COLSA, people are our most valuable resource and centered at our core value. We invite you to unite your talents with opportunity and be a part of our “Family of Professionals!” Learn about our employee-centric culture and benefits here: https://www.colsa.com/culture_benefits
Applicant selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. COLSA Corporation is an Equal Opportunity Employer, Minorities/Females/Veterans/Disabled. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, or national origin.