{"schemaVersion":"jobsearcher.job.v1","id":"2c0ef45afff9940f93f4b06d","url":"https://jobsearcher.com/jobs/2c0ef45afff9940f93f4b06d","canonicalUrl":"https://jobsearcher.com/jobs/2c0ef45afff9940f93f4b06d","title":"Lead Application Security Engineer","description":"SciTec, a wholly owned subsidiary of Firefly Aerospace, is a dynamic non-traditional defense contractor that delivers advanced technologies in support of U.S. National Security and Defense. For more than forty-five years, we have supported Department of Defense customers by developing innovative remote sensing algorithms, tools, and techniques to deliver world-class data exploitation capabilities supporting missile defense; intelligence, surveillance, & reconnaissance; space domain awareness; and aircraft survivability missions.\n\nImportant Notice: SciTec exclusively works on U.S. government contracts that require U.S. citizenship for all employees. Applicants that do not meet this requirement will not be considered.\n\nSciTec has an immediate opportunity for a talented engineer to support our programs delivering Next-Generation Missile Warning software. This is a unique opportunity to join a business delivering core capabilities for National defense. You will work within a fast-paced team delivering end-to-end software processing of Overhead Persistent InfraRed (OPIR) sensor data for Missile Warning, Missile Defense, Battlespace Awareness, and Technical Intelligence.\n\nWe are seeking an Application Security Engineer Lead to help secure mission-critical software systems by identifying, analyzing, and mitigating application-level vulnerabilities. This role focuses on hands-on security analysis, tooling integration, and working directly with software engineers to embed security into the development lifecycle.\n\nThe ideal candidate combines strong technical security skills with the ability to collaborate effectively with developers in a DevSecOps environment.\n\nResponsibilities\nPerform application security analysis using both automated and manual techniques, including:\nStatic code analysis (SAST)\nSoftware composition analysis (SCA)\nFuzzing\nManual code and design reviews\nLead an application security team in support of multiple programs\nIdentify, analyze, and help remediate application vulnerabilities\nSupport software engineers in integrating security considerations into system and application designs\nIntegrate and maintain application security tooling within CI/CD and DevSecOps pipelines\nDesign, implement, and improve continuous integration security analysis tooling\nTune and maintain security tools to reduce false positives and improve signal quality\nAssist development teams in understanding findings and implementing effective fixes\nSupport threat modeling and secure design reviews\nStay current with emerging vulnerabilities, attack techniques, and mitigation strategies\nDocument findings, recommendations, and best practices\nPerform other duties as assigned\n\nRequirements\n\nBachelor’s degree plus 8+ years of professional experience in cybersecurity or software development, or equivalent experience\n2+ years of experience focused on application/software security\nExperience analyzing source code for security flaws\nFamiliarity with secure software development practices\nStrong analytical and problem-solving skills\nDetail-oriented with strong written and verbal communication abilities\nAbility to qualify for and maintain a DoD Secret security clearance\nAbility to meet DoD 8140.01 Cyberspace Workforce Management requirements within six months of hire\nAbility to effectively collaborate with government customer team members and other engineers\n\nCandidates who have any of the following skills will be preferred:\n\nActive DoD Secret clearance or higher\nExperience identifying, exploiting, and remediating application vulnerabilities\nCredit for published CVEs is a strong plus\nProficiency in one or more programming languages such as C++, Python, JavaScript, Rust\nExperience configuring and operating static analysis tools (e.g., Coverity, Klocwork, SonarQube)\nExperience configuring and operating software composition analysis tools (e.g., Snyk, Sonatype, Anchore, JFrog Xray)\nExperience with fuzzing frameworks (AFL, AFL++, honggfuzz, or similar)\nExperience with debugging, runtime instrumentation, or reverse engineering, including tools such as strace, eBPF, Ghidra or IDA Pro\nFamiliarity with threat modeling methodologies and frameworks such as MITRE ATT&CK\nExperience working in DevSecOps or Agile development environments\n\n*Resumes, Cover Letters, and Applications which are generated by AI will not be considered for employment.\n\nColorado Residents: In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.\n\nBenefits\n\nSciTec offers a highly competitive salary and benefits package, including:\n\n4% Safe Harbor 401(k) match\n100% company paid HSA Medical insurance, with a choice of 2 buy-up options\n80% company paid Dental insurance\n100% company paid Vision insurance\n100% company paid Life insurance\n100% company paid Long-term Disability insurance\n100% company paid Hospital Indemnity insurance\nVoluntary Accident and Critical Illness insurance\nShort-term Disability insurance\nAnnual Profit-Sharing Plan\nDiscretionary Performance Bonus\nPaid Parental Leave\nGenerous Paid Time Off, including Holiday, Vacation, and Sick Pay\nFlexible Work Hours\n\nThe pay range for this position is $155,000 - $185,000 / year. SciTec considers several factors when extending an offer of employment, including but not limited to the role and associated responsibilities, a candidate's work experience, education/training, and key skills. This is not a guarantee of compensation.\n\nSciTec is proud to be an Equal Opportunity employer. VET/Disabled.","company":"Scitec","rawCompany":"scitec","city":"Boulder","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-09-18T08:27:13.399Z","occupations":[{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Lead Application Security Engineer","description":"SciTec, a wholly owned subsidiary of Firefly Aerospace, is a dynamic non-traditional defense contractor that delivers advanced technologies in support of U.S. National Security and Defense. For more than forty-five years, we have supported Department of Defense customers by developing innovative remote sensing algorithms, tools, and techniques to deliver world-class data exploitation capabilities supporting missile defense; intelligence, surveillance, & reconnaissance; space domain awareness; and aircraft survivability missions.\n\nImportant Notice: SciTec exclusively works on U.S. government contracts that require U.S. citizenship for all employees. Applicants that do not meet this requirement will not be considered.\n\nSciTec has an immediate opportunity for a talented engineer to support our programs delivering Next-Generation Missile Warning software. This is a unique opportunity to join a business delivering core capabilities for National defense. You will work within a fast-paced team delivering end-to-end software processing of Overhead Persistent InfraRed (OPIR) sensor data for Missile Warning, Missile Defense, Battlespace Awareness, and Technical Intelligence.\n\nWe are seeking an Application Security Engineer Lead to help secure mission-critical software systems by identifying, analyzing, and mitigating application-level vulnerabilities. This role focuses on hands-on security analysis, tooling integration, and working directly with software engineers to embed security into the development lifecycle.\n\nThe ideal candidate combines strong technical security skills with the ability to collaborate effectively with developers in a DevSecOps environment.\n\nResponsibilities\nPerform application security analysis using both automated and manual techniques, including:\nStatic code analysis (SAST)\nSoftware composition analysis (SCA)\nFuzzing\nManual code and design reviews\nLead an application security team in support of multiple programs\nIdentify, analyze, and help remediate application vulnerabilities\nSupport software engineers in integrating security considerations into system and application designs\nIntegrate and maintain application security tooling within CI/CD and DevSecOps pipelines\nDesign, implement, and improve continuous integration security analysis tooling\nTune and maintain security tools to reduce false positives and improve signal quality\nAssist development teams in understanding findings and implementing effective fixes\nSupport threat modeling and secure design reviews\nStay current with emerging vulnerabilities, attack techniques, and mitigation strategies\nDocument findings, recommendations, and best practices\nPerform other duties as assigned\n\nRequirements\n\nBachelor’s degree plus 8+ years of professional experience in cybersecurity or software development, or equivalent experience\n2+ years of experience focused on application/software security\nExperience analyzing source code for security flaws\nFamiliarity with secure software development practices\nStrong analytical and problem-solving skills\nDetail-oriented with strong written and verbal communication abilities\nAbility to qualify for and maintain a DoD Secret security clearance\nAbility to meet DoD 8140.01 Cyberspace Workforce Management requirements within six months of hire\nAbility to effectively collaborate with government customer team members and other engineers\n\nCandidates who have any of the following skills will be preferred:\n\nActive DoD Secret clearance or higher\nExperience identifying, exploiting, and remediating application vulnerabilities\nCredit for published CVEs is a strong plus\nProficiency in one or more programming languages such as C++, Python, JavaScript, Rust\nExperience configuring and operating static analysis tools (e.g., Coverity, Klocwork, SonarQube)\nExperience configuring and operating software composition analysis tools (e.g., Snyk, Sonatype, Anchore, JFrog Xray)\nExperience with fuzzing frameworks (AFL, AFL++, honggfuzz, or similar)\nExperience with debugging, runtime instrumentation, or reverse engineering, including tools such as strace, eBPF, Ghidra or IDA Pro\nFamiliarity with threat modeling methodologies and frameworks such as MITRE ATT&CK\nExperience working in DevSecOps or Agile development environments\n\n*Resumes, Cover Letters, and Applications which are generated by AI will not be considered for employment.\n\nColorado Residents: In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.\n\nBenefits\n\nSciTec offers a highly competitive salary and benefits package, including:\n\n4% Safe Harbor 401(k) match\n100% company paid HSA Medical insurance, with a choice of 2 buy-up options\n80% company paid Dental insurance\n100% company paid Vision insurance\n100% company paid Life insurance\n100% company paid Long-term Disability insurance\n100% company paid Hospital Indemnity insurance\nVoluntary Accident and Critical Illness insurance\nShort-term Disability insurance\nAnnual Profit-Sharing Plan\nDiscretionary Performance Bonus\nPaid Parental Leave\nGenerous Paid Time Off, including Holiday, Vacation, and Sick Pay\nFlexible Work Hours\n\nThe pay range for this position is $155,000 - $185,000 / year. SciTec considers several factors when extending an offer of employment, including but not limited to the role and associated responsibilities, a candidate's work experience, education/training, and key skills. This is not a guarantee of compensation.\n\nSciTec is proud to be an Equal Opportunity employer. VET/Disabled.","datePosted":"2026-09-18T08:27:13.399Z","dateModified":"2026-09-18T08:27:13.399Z","hiringOrganization":{"@type":"Organization","name":"Scitec","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Boulder","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"2c0ef45afff9940f93f4b06d"},"url":"https://jobsearcher.com/jobs/2c0ef45afff9940f93f4b06d"}}