Application Security Engineer — Secure Mission Systems

Rackner· Laurel, Maryland, USA· greenhouse· objavljeno 23. 07. 2026
Obvezno:GitKubernetesCI/CDAISecurityRemote

Application Security Engineer — Secure Mission Systems

Location: Mainly remote, with onsite work in Laurel, Maryland, typically one day approximately every six weeks for team-wide sprint planning Clearance: Active final DoD Secret clearance required

This position supports a pending contract opportunity and is contingent upon contract award, with an anticipated start in November 2026.

Build Security into Mission-Critical Software

At Rackner, you will help strengthen secure software supporting high-impact Department of Defense planning and decision-support missions.

This is a hands-on application-security role where you can influence how security is built into software from development through release. You will work closely with software engineers, AI/ML engineers, platform teams, DevSecOps professionals, and customer technical leads to identify meaningful risks, support vulnerability remediation, and strengthen secure-development practices.

Your work will go beyond running scanners or delivering reports. You will help teams understand security findings, separate actionable risks from false positives, verify fixes, improve software supply-chain security, and deliver resilient software with greater confidence.

You will:

Integrate application-security testing throughout the software-development lifecycle.

Conduct and support static application-security testing using Fortify.

Conduct and support dynamic application-security testing using OWASP ZAP.

Support software-composition analysis and software supply-chain security using JFrog Xray.

Review and triage security findings, identify actionable vulnerabilities, and distinguish meaningful risks from false positives.

Work directly with software engineers to understand root causes, support remediation, and verify completed fixes.

Integrate automated security scanning into secure CI/CD and GitLab-based development workflows.

Strengthen dependency-management and software supply-chain controls throughout development and delivery.

Support application security within environments using GitLab, Artifactory, OpenShift, and Kubernetes.

Contribute to technical reviews, code reviews, software testing, and security-remediation activities.

Produce clear vulnerability findings, remediation reports, code-review observations, and technical documentation.

Support verification that software meets applicable functional, coding, and security requirements before release.

Collaborate with software, AI/ML, platform, DevSecOps, and customer technical teams.

What You’ll Bring

Bachelor’s degree in Cybersecurity.

At least six years of experience involving cyber resilience, SAST, DAST, and software-vulnerability remediation.

Hands-on experience with Fortify, JFrog Xray, and OWASP ZAP.

Identifying, evaluating, triaging, and supporting remediation of application-security vulnerabilities.

Working directly with software-development teams to resolve security findings.

Experience with software supply-chain security, dependency risk, or software-composition analysis.

Understanding of secure software-development lifecycle practices.

Integrating automated security scanning into software-development or CI/CD workflows.

Ability to clearly document technical findings and communicate them to developers and technical stakeholders.

Experience That Can Strengthen Your Fit

Experience with several of the following can improve alignment:

GitLab-based development and CI/CD workflows.

Artifactory or similar artifact-management platforms.

OpenShift, Kubernetes, and containerized application environments.

Additional SAST, DAST, dependency-scanning, or software-composition-analysis tools.

Secure-code review and remediation verification.

Application-security testing in disconnected, restricted, or customer-managed environments.

Supporting classified, defense, aerospace, government, or other regulated software environments.

Collaboration across application security, software engineering, platform, DevSecOps, and AI/ML teams.

You do not need equal depth in every area, but your background should include direct experience with the named application-security tools and workflows.

Why Rackner

At Rackner, you will have the opportunity to protect technology supporting critical defense and public-sector missions.

You will work on more than isolated scan execution or vulnerability reports. This role combines hands-on application-security testing, vulnerability analysis, remediation verification, software supply-chain security, and close collaboration across software, AI/ML, platform, and mission-focused teams.

Rackner has delivered more than $30 million in recent federal awards and supports mission-critical work across defense, civilian, and public-sector environments. We are looking for an application-security engineer who can build on that momentum by strengthening secure delivery, helping teams resolve vulnerabilities, and improving confidence in the software reaching mission users.

Benefits & Professional Growth

Competitive compensation

Company-supported certifications aligned with current and future program work

401(k) with 100% company match up to 6%

Medical, dental, vision, life, and disability coverage

Paid time off and company holidays

Remote-work support and home-office equipment plan

Fitness and wellness reimbursement

Weekly pay schedule

Professional-development and future growth opportunities

Apply

If you are an application-security professional who wants broader influence across secure development, automated security testing, vulnerability remediation, and software supply-chain security, we would like to hear from you.