{"schemaVersion":"jobsearcher.job.v1","id":"fb70c8b8cd1d04ca8e15500d","url":"https://jobsearcher.com/jobs/fb70c8b8cd1d04ca8e15500d","canonicalUrl":"https://jobsearcher.com/jobs/fb70c8b8cd1d04ca8e15500d","title":"Application Security Engineer — Secure Mission Systems","description":"Application Security Engineer — Secure Mission Systems\n\nLocation: Mainly remote, with onsite work in Laurel, Maryland, typically one day approximately every six weeks for team-wide sprint planning\nClearance: Active final DoD Secret clearance required\n\nThis position supports a pending contract opportunity and is contingent upon contract award, with an anticipated start in November 2026.\n\nBuild Security into Mission-Critical Software\n\nAt Rackner, you will help strengthen secure software supporting high-impact Department of Defense planning and decision-support missions.\n\nThis is a hands-on application-security role where you can influence how security is built into software from development through release. You will work closely with software engineers, AI/ML engineers, platform teams, DevSecOps professionals, and customer technical leads to identify meaningful risks, support vulnerability remediation, and strengthen secure-development practices.\n\nYour work will go beyond running scanners or delivering reports. You will help teams understand security findings, separate actionable risks from false positives, verify fixes, improve software supply-chain security, and deliver resilient software with greater confidence.\n\nYou will:\n\nIntegrate application-security testing throughout the software-development lifecycle.\nConduct and support static application-security testing using Fortify.\nConduct and support dynamic application-security testing using OWASP ZAP.\nSupport software-composition analysis and software supply-chain security using JFrog Xray.\nReview and triage security findings, identify actionable vulnerabilities, and distinguish meaningful risks from false positives.\nWork directly with software engineers to understand root causes, support remediation, and verify completed fixes.\nIntegrate automated security scanning into secure CI/CD and GitLab-based development workflows.\nStrengthen dependency-management and software supply-chain controls throughout development and delivery.\nSupport application security within environments using GitLab, Artifactory, OpenShift, and Kubernetes.\nContribute to technical reviews, code reviews, software testing, and security-remediation activities.\nProduce clear vulnerability findings, remediation reports, code-review observations, and technical documentation.\nSupport verification that software meets applicable functional, coding, and security requirements before release.\nCollaborate with software, AI/ML, platform, DevSecOps, and customer technical teams.\n\nWhat You'll Bring\n\nBachelor's degree in Cybersecurity.\nAt least six years of experience involving cyber resilience, SAST, DAST, and software-vulnerability remediation.\nHands-on experience with Fortify, JFrog Xray, and OWASP ZAP.\nIdentifying, evaluating, triaging, and supporting remediation of application-security vulnerabilities.\nWorking directly with software-development teams to resolve security findings.\nExperience with software supply-chain security, dependency risk, or software-composition analysis.\nUnderstanding of secure software-development lifecycle practices.\nIntegrating automated security scanning into software-development or CI/CD workflows.\nAbility to clearly document technical findings and communicate them to developers and technical stakeholders.\n\nExperience That Can Strengthen Your Fit\n\nExperience with several of the following can improve alignment:\n\nGitLab-based development and CI/CD workflows.\nArtifactory or similar artifact-management platforms.\nOpenShift, Kubernetes, and containerized application environments.\nAdditional SAST, DAST, dependency-scanning, or software-composition-analysis tools.\nSecure-code review and remediation verification.\nApplication-security testing in disconnected, restricted, or customer-managed environments.\nSupporting classified, defense, aerospace, government, or other regulated software environments.\nCollaboration across application security, software engineering, platform, DevSecOps, and AI/ML teams.\n\nYou do not need equal depth in every area, but your background should include direct experience with the named application-security tools and workflows.\n\nWhy Rackner\n\nAt Rackner, you will have the opportunity to protect technology supporting critical defense and public-sector missions.\n\nYou will work on more than isolated scan execution or vulnerability reports. This role combines hands-on application-security testing, vulnerability analysis, remediation verification, software supply-chain security, and close collaboration across software, AI/ML, platform, and mission-focused teams.\n\nRackner has delivered more than $30 million in recent federal awards and supports mission-critical work across defense, civilian, and public-sector environments. We are looking for an application-security engineer who can build on that momentum by strengthening secure delivery, helping teams resolve vulnerabilities, and improving confidence in the software reaching mission users.\n\nBenefits & Professional Growth\n\nCompetitive compensation\nCompany-supported certifications aligned with current and future program work\n401(k) with 100% company match up to 6%\nMedical, dental, vision, life, and disability coverage\nPaid time off and company holidays\nRemote-work support and home-office equipment plan\nFitness and wellness reimbursement\nWeekly pay schedule\nProfessional-development and future growth opportunities\n\nApply\n\nIf you are an application-security professional who wants broader influence across secure development, automated security testing, vulnerability remediation, and software supply-chain security, we would like to hear from you.","company":"Rackner","rawCompany":"rackner","city":"Laurel","state":"MD","isRemote":false,"isActive":false,"createdAt":"2026-08-19T18:07:47.630Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Application Security Engineer — Secure Mission Systems","description":"Application Security Engineer — Secure Mission Systems\n\nLocation: Mainly remote, with onsite work in Laurel, Maryland, typically one day approximately every six weeks for team-wide sprint planning\nClearance: Active final DoD Secret clearance required\n\nThis position supports a pending contract opportunity and is contingent upon contract award, with an anticipated start in November 2026.\n\nBuild Security into Mission-Critical Software\n\nAt Rackner, you will help strengthen secure software supporting high-impact Department of Defense planning and decision-support missions.\n\nThis is a hands-on application-security role where you can influence how security is built into software from development through release. You will work closely with software engineers, AI/ML engineers, platform teams, DevSecOps professionals, and customer technical leads to identify meaningful risks, support vulnerability remediation, and strengthen secure-development practices.\n\nYour work will go beyond running scanners or delivering reports. You will help teams understand security findings, separate actionable risks from false positives, verify fixes, improve software supply-chain security, and deliver resilient software with greater confidence.\n\nYou will:\n\nIntegrate application-security testing throughout the software-development lifecycle.\nConduct and support static application-security testing using Fortify.\nConduct and support dynamic application-security testing using OWASP ZAP.\nSupport software-composition analysis and software supply-chain security using JFrog Xray.\nReview and triage security findings, identify actionable vulnerabilities, and distinguish meaningful risks from false positives.\nWork directly with software engineers to understand root causes, support remediation, and verify completed fixes.\nIntegrate automated security scanning into secure CI/CD and GitLab-based development workflows.\nStrengthen dependency-management and software supply-chain controls throughout development and delivery.\nSupport application security within environments using GitLab, Artifactory, OpenShift, and Kubernetes.\nContribute to technical reviews, code reviews, software testing, and security-remediation activities.\nProduce clear vulnerability findings, remediation reports, code-review observations, and technical documentation.\nSupport verification that software meets applicable functional, coding, and security requirements before release.\nCollaborate with software, AI/ML, platform, DevSecOps, and customer technical teams.\n\nWhat You'll Bring\n\nBachelor's degree in Cybersecurity.\nAt least six years of experience involving cyber resilience, SAST, DAST, and software-vulnerability remediation.\nHands-on experience with Fortify, JFrog Xray, and OWASP ZAP.\nIdentifying, evaluating, triaging, and supporting remediation of application-security vulnerabilities.\nWorking directly with software-development teams to resolve security findings.\nExperience with software supply-chain security, dependency risk, or software-composition analysis.\nUnderstanding of secure software-development lifecycle practices.\nIntegrating automated security scanning into software-development or CI/CD workflows.\nAbility to clearly document technical findings and communicate them to developers and technical stakeholders.\n\nExperience That Can Strengthen Your Fit\n\nExperience with several of the following can improve alignment:\n\nGitLab-based development and CI/CD workflows.\nArtifactory or similar artifact-management platforms.\nOpenShift, Kubernetes, and containerized application environments.\nAdditional SAST, DAST, dependency-scanning, or software-composition-analysis tools.\nSecure-code review and remediation verification.\nApplication-security testing in disconnected, restricted, or customer-managed environments.\nSupporting classified, defense, aerospace, government, or other regulated software environments.\nCollaboration across application security, software engineering, platform, DevSecOps, and AI/ML teams.\n\nYou do not need equal depth in every area, but your background should include direct experience with the named application-security tools and workflows.\n\nWhy Rackner\n\nAt Rackner, you will have the opportunity to protect technology supporting critical defense and public-sector missions.\n\nYou will work on more than isolated scan execution or vulnerability reports. This role combines hands-on application-security testing, vulnerability analysis, remediation verification, software supply-chain security, and close collaboration across software, AI/ML, platform, and mission-focused teams.\n\nRackner has delivered more than $30 million in recent federal awards and supports mission-critical work across defense, civilian, and public-sector environments. We are looking for an application-security engineer who can build on that momentum by strengthening secure delivery, helping teams resolve vulnerabilities, and improving confidence in the software reaching mission users.\n\nBenefits & Professional Growth\n\nCompetitive compensation\nCompany-supported certifications aligned with current and future program work\n401(k) with 100% company match up to 6%\nMedical, dental, vision, life, and disability coverage\nPaid time off and company holidays\nRemote-work support and home-office equipment plan\nFitness and wellness reimbursement\nWeekly pay schedule\nProfessional-development and future growth opportunities\n\nApply\n\nIf you are an application-security professional who wants broader influence across secure development, automated security testing, vulnerability remediation, and software supply-chain security, we would like to hear from you.","datePosted":"2026-08-19T18:07:47.630Z","dateModified":"2026-08-19T18:07:47.630Z","hiringOrganization":{"@type":"Organization","name":"Rackner","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Laurel","addressRegion":"MD","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"fb70c8b8cd1d04ca8e15500d"},"url":"https://jobsearcher.com/jobs/fb70c8b8cd1d04ca8e15500d"}}