Sr Product Application Security Engineer

Koitecc Solutions

Reston (VA)

Hybrid

USD 87,000 - 157,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Leidos is seeking a Senior Product Security Engineer to support a portfolio of shared software platforms across Ports & Borders and Aviation missions. You will translate customer requirements into practical controls, develop reusable security tooling, and work with software, DevOps, and platform teams to implement secure-by-default solutions.

You will lead threat modeling, secure design reviews, CI/CD security improvements, and vulnerability remediation across Linux, Kubernetes, containers, and

Qualifications

  • Bachelor's degree in Cybersecurity, CS, CE, or related field with 8+ years of experience or a Master's with 6+ years.
  • Hands-on product/secure software engineering experience and DevSecOps practices.
  • Experience integrating security into SDLC including requirements, architecture, and testing.
  • Experience threat modeling, security reviews, and secure design assessments.
  • Experience with CI/CD security tooling (SAST, SCA, secret scanning, container security) and Linux/Kubernetes security.

Responsibilities

  • Serve as a hands-on product security engineer for Enterprise products and collaborate with cross-functional teams.
  • Translate policies and requirements into actionable security requirements and backlog items.
  • Perform threat modeling, attack-surface analysis, and security reviews of applications, APIs, and data flows.
  • Design, integrate, and improve automated security controls within CI/CD pipelines and tooling.
  • Develop and validate hardened configurations for Linux, Kubernetes, containers, and platform services; automate where possible.
  • Create and maintain security engineering documentation and evidence for applicable standards.
  • Conduct security testing and validation of releases and architecture changes; provide remediation guidance.

Skills

Product security
Threat modeling
DevSecOps
Python scripting
Communication

Education

Bachelor's degree in a related technical discipline
Master's degree

Tools

SAST
SCA
Secret scanning
Container scanning
IaC analysis

Job description

Leidos Security Enterprise Solutions (SES) is seeking a Senior Product Security Engineer to support a portfolio of shared software platforms and product capabilities used across Ports & Borders and Aviation missions. This senior, hands-on individual contributor will be embedded with the Enterprise Products engineering organization and will partner with cybersecurity leadership, software, DevOps, infrastructure, systems, and product teams.

The role translates cybersecurity standards, customer requirements, and product risk into practical controls across architecture, software development, CI/CD pipelines, and the shared deployment platform. The engineer will develop reusable security tooling, automation, hardened configurations, and technical documentation; assess and communicate risk; and help engineering teams implement secure-by-default solutions. Technical findings and recommendations from this role will support formal risk and release decisions made by designated authorities.

Primary Responsibilities:
  • Serve as a hands-on product security engineer for Enterprise products and collaborate with cybersecurity leadership, product owners, software engineers, DevOps engineers, infrastructure engineers, systems engineers, and program stakeholders.
  • Translate organizational policies, customer requirements, threat information, and compliance obligations into actionable product security requirements, implementation guidance, and engineering backlog items.
  • Perform threat modeling, attack-surface analysis, security architecture and design reviews, and targeted code or configuration reviews for applications, APIs, data flows, identity services, and distributed system components.
  • Design, integrate, and improve automated security controls within CI/CD pipelines, including static application security testing, software composition analysis, secret detection, container scanning, infrastructure-as-code scanning, software bill of materials generation, and security reporting.
  • Partner with platform and infrastructure teams to define, automate, and validate secure configurations for Linux operating systems, Kubernetes, containers, databases, identity services, networking components, and other common platform services.
  • Develop and validate hardened baselines using DISA STIGs and SRGs, CIS Benchmarks, customer requirements, and industry best practices; automate implementation and verification where practical.
  • Assess product and platform vulnerabilities, analyze technical risk, prioritize findings, provide actionable remediation guidance, coordinate with owning teams, and verify corrective actions.
  • Support secure implementation of authentication, authorization, role-based access control, encryption, secrets management, certificate management, audit logging, service-to-service communication, and data protection controls.
  • Develop reusable security tools, scripts, pipeline templates, configuration baselines, reporting capabilities, and secure implementation patterns that can be adopted across Enterprise products and other engineering teams.
  • Create and maintain security engineering documentation and technical evidence supporting applicable NIST, CMMC, RMF, DHS, TSA, DISA, customer-specific, and international requirements.
  • Perform security testing and technical validation of significant releases, architectural changes, and platform changes, including targeted penetration testing when appropriate.
  • Communicate findings, remediation options, residual risks, and technical tradeoffs to technical and nontechnical stakeholders, and promote secure development practices through guidance and reusable self-service capabilities.
Required Qualifications:
  • Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, Software Engineering, Information Systems, or a related technical discipline with 8+ years of relevant experience; or a master's degree with 6+ years of relevant experience. Additional relevant experience may be considered in lieu of a degree where permitted by the selected job profile.
  • Hands-on experience in product security, application security, software security, DevSecOps security, platform security, or a closely related cybersecurity engineering discipline.
  • Experience integrating security into software development lifecycle activities, including requirements, architecture, implementation, testing, build, deployment, and sustainment.
  • Experience performing threat modeling, application or API security reviews, security architecture reviews, or secure design assessments.
  • Experience implementing or integrating security tooling into CI/CD pipelines, such as SAST, SCA, secret scanning, container scanning, or infrastructure-as-code analysis.
  • Experience securing Linux-based systems, containerized applications, or Kubernetes-based deployment environments.
  • Experience performing vulnerability assessments, analyzing findings, developing remediation guidance, and communicating technical risk.
  • Experience developing scripts or automation using Python, Bash, PowerShell, or another applicable programming language.
  • Working knowledge of OWASP application security risks and one or more security frameworks or baselines, such as NIST SP 800-53, NIST SP 800-171, CMMC, RMF, DISA STIGs, or CIS Benchmarks.
  • Ability to work independently across multiple technical disciplines while collaborating effectively with engineering, cybersecurity, program, and customer stakeholders.
  • Strong written and verbal communication skills, including the ability to document technical decisions and explain security risks, recommendations, and tradeoffs.
  • Ability to obtain and maintain the public trust or security clearance required by assigned programs.
  • Active certification meeting applicable DoD 8140 or customer requirements, or ability to obtain the required certification within 6 months of employment.
Original Posting:

August 5, 2026

Pay Range:

Pay Range $87,100.00 - $157,450.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.

Pay and Benefits
  • Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement.
  • More details are available at www.leidos.com/careers/pay-benefits.
Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Product Application Security Engineer
Sr Product Application Security Engineer

Leidos • Virginia (IL)

Hybrid
USD 87,000 - 157,000
Sr Product Application Security Engineer
Sr Product Application Security Engineer

Leidos Inc • United States

On-site
USD 87,000 - 157,000
Sr Product Application Security Engineer
Sr Product Application Security Engineer

Leidos • United States

On-site
USD 87,000 - 157,000
Cybersecurity Engineer SME
Cybersecurity Engineer SME

Leidos • United States

On-site
USD 154,000 - 278,000
Paid Time Off
401K with 6% company match
Flexible schedules
Cybersecurity Engineer SME
Cybersecurity Engineer SME

Leidos Inc • Bethesda (MD)

On-site
USD 154,000 - 279,000
Paid Time Off
401K with 6% match
Flexible Schedules
+1
Cybersecurity Engineer SME
Cybersecurity Engineer SME

Koitecc Solutions • Bethesda (MD)

On-site
USD 154,000 - 279,000
Paid Time Off
401K with company match
Flexible Schedules
+2
Cybersecurity Product Engineer
Cybersecurity Product Engineer

Leidos • United States

On-site
USD 87,100 - 157,450
Paid Time Off
11 paid Holidays
401K with 6% company match
+5
Senior SecDevOps Engineer
Senior SecDevOps Engineer

Leidos • Tampa (FL)

On-site
USD 131,000 - 237,000
Sr. Software Engineer
Sr. Software Engineer

Leidos Inc • Bethesda (MD)

On-site
USD 107,000 - 196,000
Paid Time Off
11 paid Holidays
401K with 6% company match
+5
Cybersecurity Product Engineer
Cybersecurity Product Engineer

Koitecc Solutions • Lawton (OK)

On-site
USD 70,000 - 126,000
Paid time off
11 holidays
401K 6% match
+5