Logo for Rackner

Application Security Engineer — Secure Mission Systems

Role overview

Qualifications

  • Bachelor’s degree in Cybersecurity
  • At least six years of experience involving cyber resilience, SAST, DAST, and software-vulnerability remediation
  • Hands-on experience with Fortify, JFrog Xray, and OWASP ZAP
  • Identifying, evaluating, triaging, and supporting remediation of application-security vulnerabilities

Responsibilities

  • Integrate application-security testing throughout the software-development lifecycle
  • Conduct and support static application-security testing using Fortify
  • Conduct and support dynamic application-security testing using OWASP ZAP
  • Support software-composition analysis and software supply-chain security using JFrog Xray

Key facts

  • Remote from: Kansas (USA)
  • Full time
  • Application Security Engineer
  • English

Hard skills

Other skills

  • Collaboration
  • Communication

About the company

Rackner logo

Rackner

IT Services & IT Consulting

Rackner builds cutting-edge solutions that apply DevSecOps and the power of AI in the datacenter, public and private clouds, and edge, leveraging the future of compute capability and technologies like Kubernetes (k8s) and WebAssembly (WASM). We're a member of the Cloud Native Computing Foundation and a Kubernetes Certified Service Provider - as well as a partner to the major public cloud companies. Our customers include hypergrowth startups and federal agencies, both Civilian and Defense. Core Competencies - DevSecOps - Edge Computing - AI/ML - Cloud-Native and Hybrid-Cloud development - Web and Mobile Applications Development (Microservices)

Company details

Company typeScaleup
IndustryIT Services & IT Consulting
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Application Security Engineer — Secure Mission Systems

Location: Mainly remote, with onsite work in Laurel, Maryland, typically one day approximately every six weeks for team-wide sprint planning
Clearance: Active final DoD Secret clearance required

This position supports a pending contract opportunity and is contingent upon contract award, with an anticipated start in November 2026.

Build Security into Mission-Critical Software

At Rackner, you will help strengthen secure software supporting high-impact Department of Defense planning and decision-support missions.

This is a hands-on application-security role where you can influence how security is built into software from development through release. You will work closely with software engineers, AI/ML engineers, platform teams, DevSecOps professionals, and customer technical leads to identify meaningful risks, support vulnerability remediation, and strengthen secure-development practices.

Your work will go beyond running scanners or delivering reports. You will help teams understand security findings, separate actionable risks from false positives, verify fixes, improve software supply-chain security, and deliver resilient software with greater confidence.

You will:

  • Integrate application-security testing throughout the software-development lifecycle.
  • Conduct and support static application-security testing using Fortify.
  • Conduct and support dynamic application-security testing using OWASP ZAP.
  • Support software-composition analysis and software supply-chain security using JFrog Xray.
  • Review and triage security findings, identify actionable vulnerabilities, and distinguish meaningful risks from false positives.
  • Work directly with software engineers to understand root causes, support remediation, and verify completed fixes.
  • Integrate automated security scanning into secure CI/CD and GitLab-based development workflows.
  • Strengthen dependency-management and software supply-chain controls throughout development and delivery.
  • Support application security within environments using GitLab, Artifactory, OpenShift, and Kubernetes.
  • Contribute to technical reviews, code reviews, software testing, and security-remediation activities.
  • Produce clear vulnerability findings, remediation reports, code-review observations, and technical documentation.
  • Support verification that software meets applicable functional, coding, and security requirements before release.
  • Collaborate with software, AI/ML, platform, DevSecOps, and customer technical teams.

What You’ll Bring

  • Bachelor’s degree in Cybersecurity.
  • At least six years of experience involving cyber resilience, SAST, DAST, and software-vulnerability remediation.
  • Hands-on experience with Fortify, JFrog Xray, and OWASP ZAP.
  • Identifying, evaluating, triaging, and supporting remediation of application-security vulnerabilities.
  • Working directly with software-development teams to resolve security findings.
  • Experience with software supply-chain security, dependency risk, or software-composition analysis.
  • Understanding of secure software-development lifecycle practices.
  • Integrating automated security scanning into software-development or CI/CD workflows.
  • Ability to clearly document technical findings and communicate them to developers and technical stakeholders.

Experience That Can Strengthen Your Fit

Experience with several of the following can improve alignment:

  • GitLab-based development and CI/CD workflows.
  • Artifactory or similar artifact-management platforms.
  • OpenShift, Kubernetes, and containerized application environments.
  • Additional SAST, DAST, dependency-scanning, or software-composition-analysis tools.
  • Secure-code review and remediation verification.
  • Application-security testing in disconnected, restricted, or customer-managed environments.
  • Supporting classified, defense, aerospace, government, or other regulated software environments.
  • Collaboration across application security, software engineering, platform, DevSecOps, and AI/ML teams.

You do not need equal depth in every area, but your background should include direct experience with the named application-security tools and workflows.

Why Rackner

At Rackner, you will have the opportunity to protect technology supporting critical defense and public-sector missions.

You will work on more than isolated scan execution or vulnerability reports. This role combines hands-on application-security testing, vulnerability analysis, remediation verification, software supply-chain security, and close collaboration across software, AI/ML, platform, and mission-focused teams.

Rackner has delivered more than $30 million in recent federal awards and supports mission-critical work across defense, civilian, and public-sector environments. We are looking for an application-security engineer who can build on that momentum by strengthening secure delivery, helping teams resolve vulnerabilities, and improving confidence in the software reaching mission users.

Benefits & Professional Growth

  • Competitive compensation
  • Company-supported certifications aligned with current and future program work
  • 401(k) with 100% company match up to 6%
  • Medical, dental, vision, life, and disability coverage
  • Paid time off and company holidays
  • Remote-work support and home-office equipment plan
  • Fitness and wellness reimbursement
  • Weekly pay schedule
  • Professional-development and future growth opportunities

Apply

If you are an application-security professional who wants broader influence across secure development, automated security testing, vulnerability remediation, and software supply-chain security, we would like to hear from you.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Application Security Engineer Related jobs

Other jobs at Rackner

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.