> Markdown version of [/jobs/ext/1365653-senior-application-security-engineering-lead](https://www.wearedevelopers.com/jobs/ext/1365653-senior-application-security-engineering-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineering Lead - **Company:** SciTec, Inc. - **Location:** Boulder, CO, United States - **Experience:** Expert - **Salary:** $155,000.0 - $185,000.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Agile Methodology, Artificial Intelligence, C++ (Programming Language), Static Program Analysis, System Configuration, Continuous Integration, Software Debugging, Fuzz Testing, Python (Programming Language), Reverse Engineering, Software Engineering, Software Systems, SonarQube, Systems Integration, Rust (Programming Language), Sonatype, Software Security, Mitre Att&ck, IDA Pro, Devsecops, Static Application Security Testing, Programming Languages - **Published:** July 21, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9042397/senior-application-security-engineering-lead ## About the Role The ideal candidate combines strong technical security skills with the ability to collaborate effectively with developers in a DevSecOps environment., * Bachelor's degree plus 8+ years of professional experience in cybersecurity or software development, or equivalent experience * 2+ years of experience focused on application/software security * Experience analyzing source code for security flaws * Familiarity with secure software development practices * Strong analytical and problem-solving skills * Detail-oriented with strong written and verbal communication abilities * Ability to qualify for and maintain a DoD Secret security clearance * Ability to meet DoD 8140.01 Cyberspace Workforce Management requirements within six months of hire * Ability to effectively collaborate with government customer team members and other engineers Candidates who have any of the following skills will be preferred: * Active DoD Secret clearance or higher * Experience identifying, exploiting, and remediating application vulnerabilities * Credit for published CVEs is a strong plus Proficiency in one or more programming languages such as C++, Python, JavaScript, Rust Experience configuring and operating static analysis tools (e.g., Coverity, Klocwork, SonarQube) Experience configuring and operating software composition analysis tools (e.g., Snyk, Sonatype, Anchore, JFrog Xray) Experience with fuzzing frameworks (AFL, AFL++, honggfuzz, or similar) Experience with debugging, runtime instrumentation, or reverse engineering, including tools such as strace, eBPF, Ghidra or IDA Pro Familiarity with threat modeling methodologies and frameworks such as MITRE ATT&CK Experience working in DevSecOps or Agile development environments *Resumes, Cover Letters, and Applications which are generated by AI will not be considered for employment. ## Description SciTec has an immediate opportunity for a talented engineer to support our programs delivering Next-Generation Missile Warning software. This is a unique opportunity to join a business delivering core capabilities for National defense. You will work within a fast-paced team delivering end-to-end software processing of Overhead Persistent InfraRed (OPIR) sensor data for Missile Warning, Missile Defense, Battlespace Awareness, and Technical Intelligence., * Perform application security analysis using both automated and manual techniques, including: * Static code analysis (SAST) * Software composition analysis (SCA) * Fuzzing * Manual code and design reviews Lead an application security team in support of multiple programs Identify, analyze, and help remediate application vulnerabilities Support software engineers in integrating security considerations into system and application designs Integrate and maintain application security tooling within CI/CD and DevSecOps pipelines Design, implement, and improve continuous integration security analysis tooling Tune and maintain security tools to reduce false positives and improve signal quality Assist development teams in understanding findings and implementing effective fixes Support threat modeling and secure design reviews Stay current with emerging vulnerabilities, attack techniques, and mitigation strategies Document findings, recommendations, and best practices Perform other duties as assigned ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Open sourcing a library: how hard can that be?](https://www.wearedevelopers.com/videos/1058-open-sourcing-a-library-how-hard-can-that-be) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools)