Remote
Application Security Engineer — Secure Mission Systems
About this role
Application Security Engineer — Secure Mission Systems Location: Mainly remote, with onsite work in Laurel, Maryland, typically one day approximately every six weeks for team-wide sprint planning Clearance: Active final DoD Secret clearance required This position supports a pending contract opportunity and is contingent upon contract award, with an anticipated start in November 2026. Build Security into Mission-Critical Software At Rackner, you will help strengthen secure software supporting high-impact Department of Defense planning and decision-support missions.
This is a hands-on application-security role where you can influence how security is built into software from development through release. You will work closely with software engineers, AI/ML engineers, platform teams, DevSecOps professionals, and customer technical leads to identify meaningful risks, support vulnerability remediation, and strengthen secure-development practices. Your work will go beyond running scanners or delivering reports.
You will help teams understand security findings, separate actionable risks from false positives, verify fixes, improve software supply-chain security, and deliver resilient software with greater confidence. You will: Integrate application-security testing throughout the software-development lifecycle. Conduct and support static application-security testing using Fortify. Conduct and support dynamic application-security testing using OWASP ZAP.
Support software-composition analysis and software supply-chain security using JFrog Xray. Review and triage security findings, identify actionable vulnerabilities, and distinguish meaningful risks from false positives. Work directly with software engineers to understand root causes, support remediation, and verify completed fixes. Integrate automated security scanning into secure CI/CD and GitLab-based development workflows.
Strengthen dependency-management and software supply-chain controls throughout development and delivery. Support application security within environments using GitLab, Artifactory, OpenShift, and Kubernetes. Contribute to technical reviews, code reviews, software testing, and security-remediation activities. Produce clear vulnerability findings, remediation reports, code-review observations, and technical documentation.