yoinka

Sr Product Application Security Engineer

Leidos

Remote6314 Remote/Teleworker USSeniorH-1B sponsor company
Sign in to applyVerified 2h ago
Location
6314 Remote/Teleworker US
Work model
Remote
Level
Senior
H-1B history
26 approvals (FY2023)
Posted
15h ago

Skills

CI/CDCybersecurityKubernetesLinux

About this role

Leidos Security Enterprise Solutions (SES) is seeking a Senior Product Security Engineer to support a portfolio of shared software platforms and product capabilities used across Ports & Borders and Aviation missions. This senior, hands-on individual contributor will be embedded with the Enterprise Products engineering organization and will partner with cybersecurity leadership, software, DevOps, infrastructure, systems, and product teams. The role translates cybersecurity standards, customer requirements, and product risk into practical controls across architecture, software development, CI/CD pipelines, and the shared deployment platform. The engineer will develop reusable security tooling, automation, hardened configurations, and technical documentation; assess and communicate risk; and help engineering teams implement secure-by-default solutions. Technical findings and recommendations from this role will support formal risk and release decisions made by designated authorities.

Primary Responsibilities

Serve as a hands-on product security engineer for Enterprise products and collaborate with cybersecurity leadership, product owners, software engineers, DevOps engineers, infrastructure engineers, systems engineers, and program stakeholders. Translate organizational policies, customer requirements, threat information, and compliance obligations into actionable product security requirements, implementation guidance, and engineering backlog items. Perform threat modeling, attack-surface analysis, security architecture and design reviews, and targeted code or configuration reviews for applications, APIs, data flows, identity services, and distributed system components. Design, integrate, and improve automated security controls within CI/CD pipelines, including static application security testing, software composition analysis, secret detection, container scanning, infrastructure-as-code scanning, software bill of materials generation, and security reporting. Partner with platform and infrastructure teams to define, automate, and validate secure configurations for Linux operating systems, Kubernetes, containers, databases, identity services, networking components, and other common platform services. Develop and validate hardened baselines using DISA STIGs and SRGs, CIS Benchmarks, customer requirements, and industry best practices; automate implementation and verification where practical. Assess product and platform vulnerabilities, analyze technical risk, prioritize findings, provide actionable remediation guidance, coordinate with owning teams, and verify corrective actions. Support secure implementation of authentication, authorization, role-based access control, encryption, secrets management, certificate management, audit logging, service-to-service communication, and data protection controls. Develop reusable security tools, scripts, pipeline templates, configuration baselines, reporting capabilities, and secure implementation patterns that can be adopted across Enterprise products and other engineering teams. Create and maintain security engineering documentation and technical evidence supporting applicable NIST, CMMC, RMF, DHS, TSA, DISA, customer-specific, and international requirements. Perform security testing and technical validation of significant releases, architectural changes, and platform changes, including targeted penetration testing when appropriate. Communicate findings, remediation options, residual risks, and technical tradeoffs to technical and nontechnical stakeholders, and promote secure development practices through guidance and reusable self-service capabilities.

Required Qualifications

Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, Software Engineering, Information Systems, or a related technical discipline with 8+ years of relevant experience; or a master's degree with 6+ years of relevant experience. Additional relevant experience may be considered in lieu of a

Sr Product Application Security Engineer at Leidos, 6314 Remote/Teleworker US | Yoinka