Sr Product Application Security Engineer

Leidos Security Enterprise Solutions (SES) is seeking a Senior Product Security Engineer to support a portfolio of shared software platforms and product capabilities used across Ports & Borders and Aviation missions. This senior, hands-on individual contributor will be embedded with the Enterprise Products engineering organization and will partner with cybersecurity leadership, software, DevOps, infrastructure, systems, and product teams. The role translates cybersecurity standards, customer requirements, and product risk into practical controls across architecture, software development, CI/CD pipelines, and the shared deployment platform. The engineer will develop reusable security tooling, automation, hardened configurations, and technical documentation; assess and communicate risk; and help engineering teams implement secure-by-default solutions. Technical findings and recommendations from this role will support formal risk and release decisions made by designated authorities. Primary Responsibilities: Serve as a hands-on product security engineer for Enterprise products and collaborate with cybersecurity leadership, product owners, software engineers, DevOps engineers, infrastructure engineers, systems engineers, and program stakeholders. Translate organizational policies, customer requirements, threat information, and compliance obligations into actionable product security requirements, implementation guidance, and engineering backlog items. Perform threat modeling, attack-surface analysis, security architecture and design reviews, and targeted code or configuration reviews for applications, APIs, data flows, identity services, and distributed system components. Design, integrate, and improve automated security controls within CI/CD pipelines, including static application security testing, software composition analysis, secret detection, container scanning, infrastructure-as-code scanning, software bill of materials generation, and security reporting. Partner with platform and infrastructure teams to define, automate, and validate secure configurations for Linux operating systems, Kubernetes, containers, databases, identity services, networking components, and other common platform services. Develop and validate hardened baselines using DISA STIGs and SRGs, CIS Benchmarks, customer requirements, and industry best practices; automate implementation and verification where practical. Assess product and platform vulnerabilities, analyze technical risk, prioritize findings, provide actionable remediation guidance, coordinate with owning teams, and verify corrective actions. Support secure implementation of authentication, authorization, role-based access control, encryption, secrets management, certificate management, audit logging, service-to-service communication, and data protection controls. Develop reusable security tools, scripts, pipeline templates, configuration baselines, reporting capabilities, and secure implementation patterns that can be adopted across Enterprise products and other engineering teams. Create and maintain security engineering documentation and technical evidence supporting applicable NIST, CMMC, RMF, DHS, TSA, DISA, customer-specific, and international requirements. Perform security testing and technical validation of significant releases, architectural changes, and platform changes, including targeted penetration testing when appropriate. Communicate findings, remediation options, residual risks, and technical tradeoffs to technical and nontechnical stakeholders, and promote secure development practices through guidance and reusable self-service capabilities. Required Qualifications: Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, Software Engineering, Information Systems, or a related technical discipline with 8+ years of relevant experience; or a master's degree with 6+ years of relevant experience. Additional relevant experience may be considered in lieu of a degree where permitted by the selected job profile. Hands-on experience in product security, application security, software security, DevSecOps security, platform security, or a closely related cybersecurity engineering discipline. Experience integrating security into software development lifecycle activities, including requirements, architecture, implementation, testing, build, deployment, and sustainment. Experience performing threat modeling, application or API security reviews, security architecture reviews, or secure design assessments. Experience implementing or integrating security tooling into CI/CD pipelines, such as SAST, SCA, secret scanning, container scanning, or infrastructure-as-code analysis. Experience securing Linux-based systems, containerized applications, or Kubernetes-based deployment environments. Experience performing vulnerability assessments, analyzing findings, developing remediation guidance, and communicating technical risk. Experience developing scripts or automation using Python, Bash, PowerShell, or another applicable programming language. Working knowledge of OWASP application security risks and one or more security frameworks or baselines, such as NIST SP 800-53, NIST SP 800-171, CMMC, RMF, DISA STIGs, or CIS Benchmarks. Ability to work independently across multiple technical disciplines while collaborating effectively with engineering, cybersecurity, program, and customer stakeholders. Strong written and verbal communication skills, including the ability to document technical decisions and explain security risks, recommendations, and tradeoffs. Ability to obtain and maintain the public trust or security clearance required by assigned programs. Active certification meeting applicable DoD 8140 or customer requirements, or ability to obtain the required certification within 6 months of employment. If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares. Original Posting: August 5, 2026 For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above. Pay Range: Pay Range $87,100.00 - $157,450.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law. Apply To this Job

Back to blog

Other Jobs To Apply

No other job posts for this day.

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...