Software Assurance (SwA) Engineer

COLSA CORPORATION
Huntsville, AL, United States
7 days ago
Apply on jobs.silkroad.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours

Tech stack

Java (Programming Language) Microsoft Windows Software Applications Software System Penetration Testing C++ (Programming Language) Databases Linux Fuzz Testing Python (Programming Language) Open Source Technology Systems Development Life Cycle Fortify (Software)
+7 more
Software Engineering Software Security SC Clearance Static Application Security Testing Vulnerability Analysis Programming Languages Dynamic Application Security Testing

Job description

  • Conducts Application Security Testing: Plans and executes investigations and tests of considerable complexity, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Interactive Application Security Testing (IAST), fuzzing, and penetration testing.*
  • Vulnerability Analysis & Remediation: Analyzes source code and compiled binaries to identify security flaws, mapping findings to Common Weakness Enumerations (CWEs) and Common Vulnerabilities and Exposures (CVEs).*
  • Advanced Problem Solving: Develops and applies advanced methods, theories, and research techniques in the investigation and solution of complex and advanced software security problems.*
  • Project Coordination: Coordinates efforts of software engineers, development teams, and technical support staff in the performance of assigned SwA projects, ensuring security is integrated throughout the SDLC.*
  • Materiel Release Support: Plans, conducts, and technically directs major phases of significant SwA projects to ensure software meets the rigorous safety and security standards required for materiel release.*
  • Technical Review: Reviews the completion and implementation of technical products, ensuring that vulnerability remediations are effective and compliant with current security practices.*
  • Tool & Vendor Evaluation: May evaluate vendor capabilities and commercial/open-source SwA tools (e.g., Fortify, Coverity, Semgrep, Cppcheck, etc.) to provide required security testing products or services.
  • Industry Research: Reviews literature, patents, and current practices relevant to the solution of assigned application security projects and threat landscapes.*
  • Technical Leadership: May provide technical consultation to other organizations regarding secure coding practices and may provide work leadership to lower-level employees.

Requirements

The ideal candidate brings strong technical expertise in software assurance and application security, with the ability to analyze complex software systems, identify and assess security weaknesses, and develop effective solutions to mitigate risk., * Bachelors’ degree in Computer Science, Software Engineering, Cybersecurity, Information Systems, Engineering, or a related field (or equivalent experience).

  • Minimum of 8 years of related experience
  • Experience integrating security practices throughout the Software Development Lifecycle (SDLC).
  • Experience supporting software assessments, authorization, or materiel release activities
  • Hands-on experience performing application security testing, such as SAST, DAST, IAST, fuzzing, and/or penetration testing.
  • Ability to obtain and maintain a Secret Security Clearance prior to start; and willing and able to obtain a Top Secret clearance, if required by the customer
  • US Citizenship required, * Active Secret clearance
  • Proficiency in technical documentation, reporting, and vulnerability tracking using standard desktop applications, spreadsheets, and database/issue-tracking programs.
  • Working knowledge of modern operating systems (e.g., Linux, Windows) and programming languages common in defense and complex systems (e.g., C/C++, Java, Python, Ada, and Rust) to effectively analyze and secure diverse codebases.

Benefits & conditions

Annually

The salary range, if referenced, represents a good faith estimate. COLSA considers various factors when determining base salary offers, but not limited to, location, the role, function and associated responsibilities, a candidate’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements.

COLSA offers a comprehensive and customizeable benefits program which includes Medical, Dental, Vision, Life Insurance, Short-Term Disability, Long-Term Disability, Accidental Death & Dismemberment, Supplemental Income Protection Programs, 401(k) with company match, Flexible Spending Accounts, Employee Assistance Program, Education & Certification Reimbursement, Employee Discount Program, Paid Time Off and Holidays.

This position will be posted for a minimum of 3 business days. If a candidate has not been selected at that time, it will continue to be posted until a suitable candidate is selected or the position is closed.

About the company

At COLSA, people are our most valuable resource and centered at our core value. We invite you to unite your talents with opportunity and be a part of our “Family of Professionals!” Learn about our employee-centric culture and benefits here: https://www.colsa.com/culture_benefits

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.silkroad.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

3:40 min

Integrating mutation testing and fuzzing into software workflows

Michael Contento · World Congress 2023

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all