SciTec, a wholly owned subsidiary of Firefly Aerospace, is a dynamic non-traditional defense contractor that delivers advanced technologies in support of U.S. National Security and Defense. For the past forty-five plus years, we have supported Department of Defense customers by developing innovative remote sensing algorithms, tools, and techniques to deliver world-class data exploitation capabilities supporting missile defense; intelligence, surveillance, & reconnaissance; space domain awareness; and aircraft survivability missions.
Important Notice : SciTec exclusively works on U.S. government contracts that require U.S. citizenship for all employees. Applicants that do not meet this requirement will not be considered.
SciTec has an immediate opportunity for a talented engineer to support our programs delivering Next-Generation Missile Warning software. This is a unique opportunity to join a small business delivering core capabilities for National defense. You will work within a fast-paced team delivering end-to-end software processing of Overhead Persistent InfraRed (OPIR) sensor data for Missile Warning, Missile Defense, Battlespace Awareness, and Technical Intelligence.
We are seeking an Application Security Engineer to help secure mission-critical software systems by identifying, analyzing, and mitigating application-level vulnerabilities. This role focuses on hands-on security analysis, tooling integration, and working directly with software engineers to embed security into the development lifecycle.
The ideal candidate combines strong technical security skills with the ability to collaborate effectively with developers in a DevSecOps environment.
Responsibilities
- Perform application security analysis using both automated and manual techniques, including :
- Static code analysis (SAST)
- Software composition analysis (SCA)
- Fuzzing
- Manual code and design reviews
- Identify, analyze, and help remediate application vulnerabilities
- Support software engineers in integrating security considerations into system and application designs
- Integrate and maintain application security tooling within CI / CD and DevSecOps pipelines
- Design, implement, and improve continuous integration security analysis tooling
- Tune and maintain security tools to reduce false positives and improve signal quality
- Assist development teams in understanding findings and implementing effective fixes
- Support threat modeling and secure design reviews
- Stay current with emerging vulnerabilities, attack techniques, and mitigation strategies
- Document findings, recommendations, and best practices
- Perform other duties as assigned
Requirements
Bachelor’s degree plus 2+ years of professional experience in cybersecurity or software development, or equivalent experience2+ years of experience focused on application / software securityExperience analyzing source code for security flawsFamiliarity with secure software development practicesStrong analytical, problem-solving, and communication skillsDetail-oriented with strong written and verbal communication abilitiesAbility to qualify for and maintain a DoD or DoE Secret security clearanceAbility to meet DoD 8140.01 Cyberspace Workforce Management requirements within six months of hireGood verbal and written communication skillsAttention to detailCandidates who have any of the following skills will be preferred :
Active DoD Secret clearance or higherExperience identifying, exploiting, and remediating application vulnerabilitiesCredit for published CVEs is a strong plusProficiency in one or more programming languages such as C++, Python, JavaScript, RustExperience configuring and operating static analysis tools (e.g., Coverity, Klocwork, SonarQube)Experience configuring and operating software composition analysis tools (e.g., Snyk, Sonatype, Anchore, JFrog Xray)Experience with fuzzing frameworks (AFL, AFL++, honggfuzz, or similar)Experience with debugging, runtime instrumentation, or reverse engineering, including tools such as :straceeBPFGhidra or IDA ProFamiliarity with threat modeling methodologies and frameworks such as MITRE ATT&CKExperience working in DevSecOps or Agile development environmentsResumes, Cover Letters, and Applications which are generated by AI will not be considered for employment.Colorado Residents : In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.
Benefits
SciTec offers a highly competitive salary and benefits package, including :
4% Safe Harbor 401(k) match100% company paid HSA Medical insurance, with a choice of 2 buy-up options80% company paid Dental insurance100% company paid Vision insurance100% company paid Life insurance100% company paid Long-term Disability insurance100% company paid Hospital Indemnity insuranceVoluntary Accident and Critical Illness insuranceShort-term Disability insuranceAnnual Profit-Sharing PlanDiscretionary Performance BonusPaid Parental LeaveGenerous Paid Time Off, including Holiday, Vacation, and Sick PayFlexible Work HoursThe pay range for this position is $96,000 - $146,000 / year. SciTec considers several factors when extending an offer of employment, including but not limited to the role and associated responsibilities, a candidate's work experience, education / training, and key skills. This is not a guarantee of compensation.
SciTec is proud to be an Equal Opportunity employer. VET / Disabled.