Rackner is a company focused on strengthening secure software for Department of Defense missions. The Application Security Engineer will be responsible for integrating security into software development, conducting application security testing, and collaborating with various teams to enhance secure delivery practices.
Responsibilities:
- Conduct and support static and dynamic application-security testing
- Use and support automated security scanning with Fortify, X-Ray, OWASP ZAP, and related tools
- Review findings, identify actionable vulnerabilities, and help distinguish meaningful risks from false positives
- Work with software engineers to understand root causes, support remediation, and verify that fixes address identified vulnerabilities
- Help integrate security testing into secure CI/CD and Git-based development workflows
- Strengthen software supply-chain security throughout the development and delivery process
- Apply secure software-development and cyber-resilience practices in an environment using GitLab, Artifactory, OpenShift, and Kubernetes
- Contribute to technical reviews, code-review findings, security-remediation reports, and software testing
- Help ensure software meets applicable functional, coding, and security requirements before release
Requirements:
- At least six years of experience involving cyber resilience, SAST, DAST, and software-vulnerability remediation
- Bachelor's degree in Cybersecurity
- Hands-on experience identifying, evaluating, and helping resolve application-security vulnerabilities
- Experience working directly with software-development teams to improve secure delivery
- Understanding of secure software-development lifecycle practices and software supply-chain security
- Ability to explain technical security findings clearly to developers and technical stakeholders
- Active final DoD Secret clearance required
- Fortify, X-Ray, OWASP ZAP, or comparable SAST, DAST, dependency, or artifact-scanning tools
- Integrating automated security checks into CI/CD workflows
- GitLab, Artifactory, or similar development and artifact-management environments
- OpenShift, Kubernetes, or other containerized application environments
- Secure-code review and remediation verification
- Supporting classified, defense, or other highly regulated software environments
- Collaborating across application-security, software-engineering, platform, and AI/ML teams