Staff / Sr Staff Application Security Engineer
Quick Summary
Static code analysis (SAST) Software composition analysis (SCA) Fuzzing Manual code and design reviews Identify, analyze,
SciTec, a wholly owned subsidiary of Firefly Aerospace, is a dynamic non-traditional defense contractor that delivers advanced technologies in support of U.S. National Security and Defense. For the past forty-five plus years, we have supported Department of Defense customers by developing innovative remote sensing algorithms, tools, and techniques to deliver world-class data exploitation capabilities supporting missile defense; intelligence, surveillance, & reconnaissance; space domain awareness; and aircraft survivability missions.
Responsibilities
~1 min read- →Bachelor’s degree plus 2+ years of professional experience in cybersecurity or software development, or equivalent experience
- →2+ years of experience focused on application/software security
- → Experience analyzing source code for security flaws
- → Familiarity with secure software development practices
- → Strong analytical, problem-solving, and communication skills
- → Detail-oriented with strong written and verbal communication abilities
- → Ability to qualify for and maintain a DoD or DoE Secret security clearance
- → Ability to meet DoD 8140.01 Cyberspace Workforce Management requirements within six months of hire
- →Good verbal and written communication skills
- →Attention to detail
Nice to Have
~1 min read- Active DoD Secret clearance or higher
- Experience identifying, exploiting, and remediating application vulnerabilities
- Credit for published CVEs is a strong plus
- Proficiency in one or more programming languages such as C++, Python, JavaScript, Rust
- Experience configuring and operating static analysis tools (e.g., Coverity, Klocwork, SonarQube)
- Experience configuring and operating software composition analysis tools (e.g., Snyk, Sonatype, Anchore, JFrog Xray)
- Experience with fuzzing frameworks (AFL, AFL++, honggfuzz, or similar)
- Experience with debugging, runtime instrumentation, or reverse engineering, including tools such as:
- strace
- eBPF
- Ghidra or IDA Pro
- Familiarity with threat modeling methodologies and frameworks such as MITRE ATT&CK
- Experience working in DevSecOps or Agile development environments
What We Offer
~1 min readSciTec offers a highly competitive salary and benefits package, including:
Location & Eligibility
Listing Details
- Posted
- June 1, 2026
- First seen
- September 28, 2026
- Last seen
- September 28, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 22%
- Scored at
- September 28, 2026
Signal breakdown
Similar Security Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.