Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Leidos

Senior Product Application Security Engineer

Leidos

Senior Product Security Engineer securing shared software platforms for Leidos, a government and commercial digital mission technology company. Building DevSecOps controls, hardened configurations, vulnerability remediation, and reusable security automation for Ports & Borders and Aviation missions.

Posted 8/5/2026full-timeRemote • 🇺🇸 United StatesSenior💰 $87,100 - $157,450 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in product security engineering, including threat modeling, vulnerability assessments, and secure design assessments. Proficient in integrating security controls within CI/CD pipelines and developing automation using programming languages such as Python and Bash.

Highest-signal resume keywords
Threat ModelingVulnerability AssessmentCI/CD Security IntegrationSecurity Architecture ReviewAutomation Development

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Threat ModelingVulnerability AssessmentSecurity Architecture ReviewAutomation DevelopmentSecure Design AssessmentLinux SecurityKubernetes SecuritySAST IntegrationPython ProgrammingBash Scripting
Soft Skills
Strong Communication SkillsCollaborationIndependent Work
Tools & Technologies
CI/CD PipelinesDISA STIGsCIS BenchmarksNIST SP 800-53NIST SP 800-171CMMCRMFSecret ScanningContainer ScanningInfrastructure-as-Code Analysis
Certifications & Qualifications
Active DoD 8140 CertificationAbility to Obtain Security Clearance
Industry Keywords
Product SecurityCybersecurity EngineeringDevSecOpsApplication SecurityTechnical Risk AnalysisCompliance RequirementsSecurity FrameworksAudit LoggingData Protection ControlsService-to-Service Communication

Tech Stack

Tools & technologies
Cyber SecurityKubernetesLinuxPython

About the role

Key responsibilities & impact
  • Serve as a hands-on product security engineer for Enterprise products and collaborate with cybersecurity, product, software, DevOps, infrastructure, systems, and program stakeholders
  • Translate policies, customer requirements, threat information, and compliance obligations into product security requirements and engineering guidance
  • Perform threat modeling, attack-surface analysis, security architecture and design reviews, and targeted code or configuration reviews
  • Design, integrate, and improve automated security controls in CI/CD pipelines
  • Define, automate, and validate secure configurations for Linux, Kubernetes, containers, databases, identity services, networking, and platform services
  • Develop and validate hardened baselines using DISA STIGs, SRGs, CIS Benchmarks, customer requirements, and industry best practices
  • Assess vulnerabilities, analyze technical risk, prioritize findings, provide remediation guidance, coordinate with owning teams, and verify corrective actions
  • Support authentication, authorization, RBAC, encryption, secrets and certificate management, audit logging, service-to-service communication, and data protection controls
  • Develop reusable security tools, scripts, pipeline templates, configuration baselines, reporting capabilities, and secure implementation patterns
  • Create and maintain security engineering documentation and technical evidence for NIST, CMMC, RMF, DHS, TSA, DISA, customer-specific, and international requirements
  • Perform security testing and technical validation of releases and architectural or platform changes, including targeted penetration testing when appropriate
  • Communicate findings, remediation options, residual risks, and technical tradeoffs to technical and nontechnical stakeholders and promote secure development practices

Requirements

What you’ll need
  • Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, Software Engineering, Information Systems, or related technical discipline with 8+ years of relevant experience; or master's degree with 6+ years of relevant experience
  • Additional relevant experience may be considered in lieu of a degree where permitted
  • Hands-on experience in product, application, software, DevSecOps, platform, or related cybersecurity engineering
  • Experience integrating security throughout the software development lifecycle
  • Experience with threat modeling, application or API security reviews, security architecture reviews, or secure design assessments
  • Experience integrating SAST, SCA, secret scanning, container scanning, or infrastructure-as-code analysis into CI/CD pipelines
  • Experience securing Linux systems, containerized applications, or Kubernetes environments
  • Experience performing vulnerability assessments, analyzing findings, developing remediation guidance, and communicating technical risk
  • Experience developing automation using Python, Bash, PowerShell, or another applicable programming language
  • Working knowledge of OWASP application security risks and security frameworks or baselines such as NIST SP 800-53, NIST SP 800-171, CMMC, RMF, DISA STIGs, or CIS Benchmarks
  • Ability to work independently across multiple technical disciplines and collaborate with engineering, cybersecurity, program, and customer stakeholders
  • Strong written and verbal communication skills, including documenting technical decisions and explaining security risks and tradeoffs
  • Ability to obtain and maintain the public trust or security clearance required by assigned programs
  • Active certification meeting applicable DoD 8140 or customer requirements, or ability to obtain the required certification within 6 months of employment

Benefits

Comp & perks
  • Competitive compensation
  • Health and Wellness programs
  • Income Protection
  • Paid Leave
  • Retirement