Software Assurance (SwA) Engineer

Colsa-5

Huntsville (AL)

On-site

USD 110,000 - 170,000

Full time

13 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical
Dental
Vision
Life Insurance
Short-Term Disability
Long-Term Disability
AD&D
Income Protection
401(k)
Flexible Spending Accounts
EAP
Education Reimbursement
Employee Discount
PTO and Holidays

Job summary

COLSA Corporation is seeking an experienced Software Assurance (SwA) Engineer to join our team in Huntsville, Alabama. This role focuses on identifying vulnerabilities, conducting application security testing, and supporting readiness for materiel release throughout the SDLC.

The ideal candidate will have strong expertise in SAST/DAST/IAST, vulnerability analysis, and collaboration with software engineers to embed secure coding practices.

Qualifications

  • Bachelor's degree in CS/SE/Cybersecurity or related field.
  • Minimum 8 years of related experience.
  • Experience integrating security practices across the SDLC.
  • Ability to obtain and maintain security clearance.

Responsibilities

  • Plans and executes investigations and tests (SAST/DAST/IAST) and penetration testing.
  • Analyzes source code and binaries to identify security flaws and maps to CWEs/CVEs.
  • Develops advanced methods for solving complex software security problems.
  • Coordinates software engineers and support staff to secure the SDLC.
  • Plans, conducts, and directs major phases for materiel release.

Skills

Application security
SDLC security
Vulnerability analysis
Technical leadership
Security testing (SAST/DAST/IAST)

Education

Bachelor's degree in CS/SE/Cybersecurity or related field
8+ years related experience

Tools

SAST tools
DAST tools
IAST tools
Fortify
Coverity
Semgrep
Cppcheck

Job description

COLSA Corporation is seeking an experienced Software Assurance (SwA) Engineer to join our team in Huntsville, Alabama. This role will support the security and integrity of complex software applications throughout the software development lifecycle (SDLC), with a focus on identifying vulnerabilities, conducting application security testing, and supporting software assessment, authorization, and readiness for materiel release.

The ideal candidate brings strong technical expertise in software assurance and application security, with the ability to analyze complex software systems, identify and assess security weaknesses, and develop effective solutions to mitigate risk.

Principal Duties and Responsibilities (*Essential functions)
  • Conducts Application Security Testing: Plans and executes investigations and tests of considerable complexity, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Interactive Application Security Testing (IAST), fuzzing, and penetration testing.
  • Vulnerability Analysis & Remediation: Analyzes source code and compiled binaries to identify security flaws, mapping findings to Common Weakness Enumerations (CWEs) and Common Vulnerabilities and Exposures (CVEs).
  • Advanced Problem Solving: Develops and applies advanced methods, theories, and research techniques in the investigation and solution of complex and advanced software security problems.
  • Project Coordination: Coordinates efforts of software engineers, development teams, and technical support staff in the performance of assigned SwA projects, ensuring security is integrated throughout the SDLC.
  • Materiel Release Support: Plans, conducts, and technically directs major phases of significant SwA projects to ensure software meets the rigorous safety and security standards required for materiel release.
  • Technical Review: Reviews the completion and implementation of technical products, ensuring that vulnerability remediations are effective and compliant with current security practices.
  • Tool & Vendor Evaluation: May evaluate vendor capabilities and commercial/open-source SwA tools (e.g., Fortify, Coverity, Semgrep, Cppcheck, etc.) to provide required security testing products or services.
  • Industry Research: Reviews literature, patents, and current practices relevant to the solution of assigned application security projects and threat landscapes.
  • Technical Leadership: May provide technical consultation to other organizations regarding secure coding practices and may provide work leadership to lower-level employees.

At COLSA, people are our most valuable resource and centered at our core value. We invite you to unite your talents with opportunity and be a part of our "Family of Professionals!" Learn about our employee-centric culture and benefits here: https://www.colsa.com/culture_benefits

Required Experience
  • Bachelors' degree in Computer Science, Software Engineering, Cybersecurity, Information Systems, Engineering, or a related field (or equivalent experience).
  • Minimum of 8 years of related experience
  • Experience integrating security practices throughout the Software Development Lifecycle (SDLC).
  • Experience supporting software assessments, authorization, or materiel release activities
  • Hands-on experience performing application security testing, such as SAST, DAST, IAST, fuzzing, and/or penetration testing.
  • Ability to obtain and maintain a Secret Security Clearance prior to start; and willing and able to obtain a Top Secret clearance, if required by the customer
Preferred Qualifications
  • Proficiency in technical documentation, reporting, and vulnerability tracking using standard desktop applications, spreadsheets, and database/issue-tracking programs.
  • Working knowledge of modern operating systems (e.g., Linux, Windows) and programming languages common in defense and complex systems (e.g., C/C++, Java, Python, Ada, and Rust) to effectively analyze and secure diverse codebases.

Applicant selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information.COLSA Corporation is an Equal Opportunity Employer, Minorities/Females/Veterans/Disabled. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, or national origin.

Salary Type

Annually

The salary range, if referenced, represents a good faith estimate. COLSA considers various factors when determining base salary offers, but not limited to, location, the role, function and associated responsibilities, a candidate's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements.

COLSA offers a comprehensive and customizeable benefits program which includes

  • Medical
  • Dental
  • Vision
  • Life Insurance
  • Short-Term Disability
  • Long-Term Disability
  • Accidental Death & Dismemberment
  • Supplemental Income Protection Programs
  • 401(k) with company match
  • Flexible Spending Accounts
  • Employee Assistance Program
  • Education & Certification Reimbursement
  • Employee Discount Program
  • Paid Time Off and Holidays

This position will be posted for a minimum of 3 business days. If a candidate has not been selected at that time, it will continue to be posted until a suitable candidate is selected or the position is closed.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Assurance (SwA) Engineer
Software Assurance (SwA) Engineer

COLSA • Huntsville (AL)

On-site
USD 110,000 - 160,000
Software Assurance SwA Engineer
Software Assurance SwA Engineer

COLSA Corporation • Huntsville (AL)

On-site
USD 120,000 - 170,000
Software Engineer, Journeyman
Software Engineer, Journeyman

Colsa-5 • San Antonio (TX)

On-site
USD 85,000 - 125,000
Software Engineer, Journeyman
Software Engineer, Journeyman

COLSA • San Antonio (TX)

On-site
USD 90,000 - 150,000
Local Defender - Cybersecurity (SOC Analyst & Threat Analyst)
Local Defender - Cybersecurity (SOC Analyst & Threat Analyst)

Colsa-5 • Concord (CA)

On-site
USD 139,000 - 150,000
Medical coverage
401(k) with company match
Paid time off
Local Defender - Cybersecurity (SOC Analyst & Threat Analyst)
Local Defender - Cybersecurity (SOC Analyst & Threat Analyst)

Colsa • Northern (KY)

Hybrid
USD 139,000 - 150,000
Medical benefits
401(k) with company match
Paid time off
Local Defender - Cybersecurity (SOC Analyst & Threat Analyst)
Local Defender - Cybersecurity (SOC Analyst & Threat Analyst)

COLSA • Concord (CA)

On-site
USD 139,000 - 150,000
Medical
Dental
Vision
+6
Cyber Security Vulnerability Researcher (Advanced)
Cyber Security Vulnerability Researcher (Advanced)

COLSA • Patuxent Highland (MD)

On-site
USD 115,000 - 220,000
Medical, Dental, Vision
Life Insurance
Short-Term Disability
+2
Senior Software Assurance Engineer – SDLC Security Leader
Senior Software Assurance Engineer – SDLC Security Leader

Colsa-5 • Huntsville (AL)

On-site
USD 110,000 - 170,000
Medical
Dental
Vision
+11
Cybersecurity Operations Analyst (CSSP)
Cybersecurity Operations Analyst (CSSP)

Colsa-5 • Huntsville (AL)

On-site
USD 90,000 - 120,000
Medical
Dental
Vision
+3