AppSec Engineer

CACI InternationalO'Fallon, IL
$75,200 - $158,100Remote

About The Position

Join a mission‑driven DoD program where your expertise in application security directly strengthens national defense. In this role, you will shape and elevate AppSec across a complex, modern application ecosystem—leading testing operations, influencing secure development practices, and mentoring the next generation of security engineers. You will work side‑by‑side with the Cybersecurity Architect to define secure SDLC strategy and ensure security is deeply woven into every phase of development, from initial design through final deployment.

Requirements

  • Active Secret clearance
  • 6–9 years of experience in application security, penetration testing, or secure software development
  • Advanced proficiency with Fortify and SonarQube
  • Demonstrated experience leading penetration testing engagements and performing secure code reviews
  • Strong knowledge of web application, API, and mobile application vulnerabilities
  • Proven ability to mentor and develop junior AppSec engineers
  • DoD 8140.03M DCWF Intermediate Tier certification — one of: CEH(P), RCCE Level 1, Cloud+, CPTE, FITSP-A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, or Security+
  • Bachelor’s degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering

Nice To Haves

  • Multiple DoD 8140.03M DCWF Advanced Tier 541 certifications
  • OSCP or equivalent offensive security certification
  • Experience integrating security into DevSecOps pipelines
  • Prior experience developing AppSec programs or secure coding standards within a DoD environment
  • DoD 8140.03M DCWF Advanced Tier certification — one of: CFR, CISA, CISM, CySA+, GPEN, or GSNA
  • Master’s or Ph.D. in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering

Responsibilities

  • Lead SAST operations using Fortify, including full ownership of findings triage and remediation tracking
  • Oversee SonarQube continuous code security analysis and quality gate governance
  • Manage and execute DAST testing and runtime vulnerability assessments
  • Plan, lead, and deliver penetration testing engagements across varied application stacks
  • Lead secure code reviews and coach developers on remediation techniques
  • Own application vulnerability remediation tracking, verification, and closure
  • Develop and maintain standards for AppSec assessments and penetration test reporting
  • Drive secure development lifecycle (SDLC) compliance across assigned application portfolios
  • Mentor junior and mid‑level AppSec engineers, fostering technical growth and excellence
  • Serve as the AppSec liaison to the Cybersecurity Architect to advance program‑wide SDLC security strategy

Benefits

  • flexible time off
  • robust learning resources
  • comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service