> Markdown version of [/jobs/ext/1368734-application-security-tooling-administrator](https://www.wearedevelopers.com/jobs/ext/1368734-application-security-tooling-administrator). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Tooling Administrator - **Company:** Prism, Inc. - **Location:** Washington, DC, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), .NET Framework, Application Programming Interfaces (APIs), Agile Methodology, JIRA, Burp Suite, Continuous Integration, Disaster Recovery, Gradle, Python (Programming Language), Lightweight Directory Access Protocols (LDAP), Linux System Administration, Apache Maven, Networking Basics, Cisco Nexus Switches, Node.Js, NuGet, OpenShift, Open Web Application Security, Performance Tuning, Prism (Software), Systems Development Life Cycle, Red Hat Enterprise Linux, Fortify (Software), Secure Coding, Security Information and Event Management, Software Engineering, Systems Integration, Software Vulnerability Management, Transport Layer Security, Cloud Platform System, System Availability, Sonatype, Software Security, SC Clearance, Gitlab-ci, Kubernetes, Bug Reporting, Enterprise Integration, Build Tools, Npm(Software), Oracle Cloud Infrastructure, Splunk, Devsecops, Jenkins, Servicenow, Static Application Security Testing, Artifactory, Dynamic Application Security Testing - **Published:** July 21, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9042868/application-security-tooling-administrator ## About the Role Certification Requirement: DoD 8570 IAT II (e.i. Security+) Active Secret clearance required 3+ years in application security engineering and/or DevSecOps in regulated environments. Hands-on administration and pipeline integration experience with Sonatype (Nexus IQ/Lifecycle), Fortify (SCA/SSC), StackRox/Red Hat ACS, and Burp Suite (Professional/Enterprise preferred). Strong CI/CD and automation skills; ability to implement repeatable integrations and policy gates. Working knowledge of: * Secure SDLC, OWASP Top 10, dependency risk, SBOM concepts, container/Kubernetes security * Linux administration, networking fundamentals, TLS/cert management, identity integration (SSO/LDAP) * Common languages/build systems (e.g., Java/Maven/Gradle, .NET/NuGet, Node/npm, Python/pip) * Oracle Cloud Infrastructure, DoD/IC experience with RMF, STIGs, and vulnerability management processes. Familiarity with registries and orchestration: Harbor/Artifactory/ECR, Kubernetes/OpenShift, Helm. Experience integrating with SIEM/SOAR and ticketing (e.g., Splunk, ServiceNow, Jira). Relevant certifications (one or more): Security+, CISSP, CSSLP, GIAC, Kubernetes security certs ## Description PRISM is seeking Two Application Security Tooling Administrators to help design, operate, and continuously improve the defense agency's application security (AppSec) scanning ecosystem across the software development life cycle (SDLC). This position will run and integrate software composition analysis (SCA) with Sonatype, static application security testing (SAST) with Fortify, container/Kubernetes security with Red Hat Advanced Cluster Security (StackRox), and dynamic application security testing (DAST) with Burp Suite-ensuring scalable, auditable, mission-ready security controls in regulated environments. The ideal candidate is comfortable operating all tools listed. This is a remote position., Platform ownership & operations: * Deploy, configure, harden, and maintain Sonatype, Fortify, StackRox, and Burp in on-prem and/or accredited cloud environments. The strongest candidates possess Oracle Cloud experience/certifications. * Manage upgrades, plugins, licensing, capacity planning, backup/restore, high availability, and disaster recovery. * Establish SLAs/SLOs, monitoring/alerting, and operational runbooks. CI/CD integration (DevSecOps): * Integrate tools into CI/CD pipelines (e.g., Jenkins, GitLab CI, etc.) with policy-based gating and risk-based exceptions. * Standardize developer "secure-by-default" workflows: pull request checks, nightly scans, release readiness criteria. * Build reusable templates and reference implementations for product teams. Security Policy, tuning, and governance * Define and tune scanning policies (severity thresholds, exploitability context, allowlists/denylists, quality gates) aligned to agency standards. * Reduce false positives/negatives through rule tuning, calibration, and developer feedback loops. * Maintain an auditable vulnerability management workflow: triage, ownership, remediation SLAs, and exception/waiver documentation. Vulnerability triage & remediation enablement * Provide actionable findings with clear reproduction steps and secure coding guidance. * Partner with engineering teams to remediate issues in code, dependencies, container images, and Kubernetes configurations. * Coordinate retesting and verify fixes (including targeted Burp validation for high-risk apps/APIs). Container/Kubernetes security (StackRox) * Implement image scanning, runtime detections, admission controls, and Kubernetes policy enforcement. * Integrate with registries and orchestration platforms; maintain cluster baselines and least-privilege controls. * Operationalize incident-ready detections and response playbooks with SOC/IR teams. Reporting, compliance, and audit support * Produce metrics and dashboards: vulnerability trends, time-to-remediate, pipeline pass rates, policy exceptions. * Support Risk Management Framework (RMF) / Authority to Operate (ATO) evidence needs with scan outputs, control mappings, and procedures. * Experience supporting Agile project management, with hands-on Jira experience strongly preferred ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [How your .NET software supply chain is open to attack : and how to fix it](https://www.wearedevelopers.com/videos/938-how-your-net-software-supply-chain-is-open-to-attack-and-how-to-fix-it) - [Modular Secrets to Lightning-Fast Android Builds](https://www.wearedevelopers.com/videos/1428-modular-secrets-to-lightning-fast-android-builds) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)