Full-Time

Senior Product Application Security Engineer

Posted on 8/5/2026

Leidos

Leidos

10,001+ employees

Defense, intelligence, and civil IT solutions

Compensation Overview

$87.1k - $157.4k/yr

Company Historically Provides H1B Sponsorship

Remote in USA

Remote

Bachelor's, Master's

Category
IT Operations
Cybersecurity
Required Skills
PowerShell
Bash
Kubernetes
Python
Threat modeling
Computer Networking
Docker
Cybersecurity
Vulnerability Analysis
Role-based Access Control
Cryptography
Penetration Testing
DevOps
Linux/Unix

Get referred to Leidos

See people who can refer or advise you

Requirements
  • A bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, Software Engineering, Information Systems, or a related technical discipline with 8+ years of relevant experience, or a master's degree with 6+ years of relevant experience; additional relevant experience may substitute for a degree where permitted.
  • Hands-on experience in product security, application security, software security, DevSecOps security, platform security, or a closely related cybersecurity engineering discipline.
  • Experience integrating security into software development lifecycle activities, including requirements, architecture, implementation, testing, build, deployment, and sustainment.
  • Experience performing threat modeling, application or API security reviews, security architecture reviews, or secure design assessments.
  • Experience implementing or integrating security tooling into CI/CD pipelines, such as static application security testing, software composition analysis, secret scanning, container scanning, or infrastructure-as-code analysis.
  • Experience securing Linux-based systems, containerized applications, or Kubernetes-based deployment environments.
  • Experience performing vulnerability assessments, analyzing findings, developing remediation guidance, and communicating technical risk.
  • Experience developing scripts or automation using Python, Bash, PowerShell, or another applicable programming language.
  • Working knowledge of OWASP application security risks and one or more security frameworks or baselines, such as NIST SP 800-53, NIST SP 800-171, CMMC, RMF, DISA STIGs, or CIS Benchmarks.
  • Ability to work independently across multiple technical disciplines while collaborating with engineering, cybersecurity, program, and customer stakeholders.
  • Strong written and verbal communication skills, including the ability to document technical decisions and explain security risks, recommendations, and tradeoffs.
  • Ability to obtain and maintain the public trust or security clearance required by assigned programs.
  • An active certification meeting applicable DoD 8140 or customer requirements, or the ability to obtain the required certification within six months of employment.
Responsibilities
  • Serve as a hands-on product security engineer for Enterprise products and collaborate with cybersecurity leadership, product owners, software engineers, DevOps engineers, infrastructure engineers, systems engineers, and program stakeholders.
  • Translate organizational policies, customer requirements, threat information, and compliance obligations into actionable product security requirements, implementation guidance, and engineering backlog items.
  • Perform threat modeling, attack-surface analysis, security architecture and design reviews, and targeted code or configuration reviews for applications, APIs, data flows, identity services, and distributed system components.
  • Design, integrate, and improve automated security controls within CI/CD pipelines, including static application security testing, software composition analysis, secret detection, container scanning, infrastructure-as-code scanning, software bill of materials generation, and security reporting.
  • Partner with platform and infrastructure teams to define, automate, and validate secure configurations for Linux operating systems, Kubernetes, containers, databases, identity services, networking components, and other common platform services.
  • Develop and validate hardened baselines using DISA STIGs and SRGs, CIS Benchmarks, customer requirements, and industry best practices, and automate implementation and verification where practical.
  • Assess product and platform vulnerabilities, analyze technical risk, prioritize findings, provide actionable remediation guidance, coordinate with owning teams, and verify corrective actions.
  • Support secure implementation of authentication, authorization, role-based access control, encryption, secrets management, certificate management, audit logging, service-to-service communication, and data protection controls.
  • Develop reusable security tools, scripts, pipeline templates, configuration baselines, reporting capabilities, and secure implementation patterns for adoption across Enterprise products and other engineering teams.
  • Create and maintain security engineering documentation and technical evidence supporting applicable NIST, CMMC, RMF, DHS, TSA, DISA, customer-specific, and international requirements.
  • Perform security testing and technical validation of significant releases, architectural changes, and platform changes, including targeted penetration testing when appropriate.
  • Communicate findings, remediation options, residual risks, and technical tradeoffs to technical and nontechnical stakeholders, and promote secure development practices through guidance and reusable self-service capabilities.

Leidos is a large technology and engineering company that serves defense, intelligence, healthcare, and civil government customers. It provides scientific, engineering, and IT solutions to help ensure safety, health, and efficiency, from upgrading air traffic control to strengthening cybersecurity for critical missions. The company delivers integrated systems and services—software, research, cyber defense, and digital modernization—through programs that span government and commercial clients. Leidos stands out through its long history as SAIC’s split-off and rapid growth via major acquisitions, creating a broad, mission-focused portfolio across defense, space, intelligence, and civilian sectors. Its overarching goal is to help customers solve hard problems with advanced technology, enabling safer operations and better public services.

Company Size

10,001+

Company Stage

IPO

Headquarters

Reston, Virginia

Founded

1969

Get referred to Leidos

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Sea Hunter and Seahawk logged 200,000 nautical miles through September 2026, validating autonomy.
  • Leidos won a $56 million Naval Health Research Center contract on August 2026.
  • Punta Cana Airport adopted Leidos ClearScan with SeeTrue AI on August 24, 2026.

What critics are saying

  • GDIT’s July 10, 2026 GAO protest targets Leidos’ roughly $11 billion DISA expansion.
  • Leidos issued 305 layoff notices in June 2026, signaling margin pressure and reorganization.
  • A DHS contract cancellation after Nightwing’s protest shows Federal customers can unwind Leidos awards quickly.

What makes Leidos unique

  • Leidos combines LAVA autonomy, RAVe geospatial AI, and ClearScan hardware across missions.
  • Kudu Dynamics acquisition, completed May 28, 2025, strengthened offensive cyber and spectrum warfare.
  • Fiscal 2025 backlog reached $49.0 billion, including $9.7 billion funded backlog, supporting scale.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Medical, dental, & vision insurance

Health Savings account

Income protection

PTO

Paid parental leave

Jury duty pay

Bereavement leave

401(k) Retirement Plan

Employee Stock Purchase Plan

Family Benefits

Growth & Insights and Company News

Headcount

6 month growth

8%

1 year growth

8%

2 year growth

8%
PR Newswire
Sep 8th, 2026
Leidos autonomous vessels complete 200,000 nautical miles across naval operations

Leidos autonomous vessels Sea Hunter and Seahawk participated in significant naval operations, demonstrating advanced maritime autonomy capabilities. Sea Hunter operated at RIMPAC 2026 as the exercise's only Medium Unmanned Surface Vessel, autonomously travelling over 2,000 nautical miles from Hawaii to California. Seahawk became the first MUSV to deploy operationally with a carrier strike group, joining the USS Theodore Roosevelt. Both vessels use Leidos Autonomous Vessel Architecture (LAVA), featuring autonomous navigation, collision avoidance, and GPS-denied operation. Across its autonomous maritime portfolio, Leidos has accumulated over 200,000 nautical miles and 14,000 hours of safe autonomous operation. The company previously demonstrated offensive capabilities in 2021 when its MUSV Ranger test-fired an SM-6 Standard Missile. Leidos reported annual revenues of approximately $17.2 billion for the fiscal year ended 2 January 2026.

ITnews
Sep 1st, 2026
ADHA sticks with Accenture for My Health Record support.

ADHA sticks with Accenture for My Health Record support. Sep 1 2026 4:28PM Creates new operating model. The Australian Digital Health Agency will stick with Accenture for infrastructure services underpinning My Health Record, signing a new $162m deal. The agency went to market for "application support and maintenance services" in July last year, testing a package of work that Accenture had held as the "national infrastructure operator" since 2012. Accenture has since made tens of millions more from a transition arrangement - required while ADHA tested the market - but has now landed the work again. The new contract is worth approximately $161.6 million and runs for three years from August 28 2026 to August 27 2029. There is one extension option, with a hard contract end-date of August 31 2032 for Accenture. The open tender closed in October last year, and covers both the My Health Record system and the ADHA's API gateway infrastructure. Chief technical officer John Borchi said the engagement with Accenture would be different this time, courtesy of a new operating model where the agency led end-to-end service delivery. "The agency sets priorities for national digital health infrastructure, including My Health Record, coordinates delivery across multiple suppliers and, of course, retains accountability for governance, assurance and decision-making," Borchi said. ADHA chief executive Amanda Cattermole said the new contract would support My Health Record at a time of significant and growing use. Cattermole said there are more than 25 million active records, and around 207 million clinician uses in the past 12 months plus around 30 million consumer views each month. "This contract will support those services while providing a foundation for future transformation as the Agency works with governments, healthcare providers and technology partners on the progressive transition to a modernised FHIR [fast healthcare interoperability resources]-based ecosystem," Cattermole said. Telstra Health won a $33.2 million contract to implement a FHIR-based based data architecture for My Health Record. Telstra Health is working with Leidos Australia and Canada's Smile Digital Health, with the data architecture designed to run in parallel with existing clinical document formats. ADHA declined to say how many organisations tendered for the work, or whether any bidder other than Accenture reached the final stage of evaluation, saying the information is commercial-in-confidence and subject to procurement confidentiality obligations.

WashingtonExec
Sep 1st, 2026
Applied taps Elizabeth Robertson as EVP of business development.

Applied taps Elizabeth Robertson as EVP of business development. Applied Aerospace & Defense has appointed Elizabeth Robertson as executive vice president of business development. Robertson will lead enterprise growth, new program capture and strategic customer relationships across Space & Launch Systems, Defense Aviation & Airborne Systems, and C5ISR & Precision Strike Systems. "Elizabeth is a proven growth executive with a rare combination of technical depth, end market knowledge, and customer relationships across the entire space and defense technology ecosystem," said Chris Rogers, president and chief strategy officer for Applied. "She has built and delivered new programs from every side of the table, as a NASA engineer, a program leader for next-generation defense technology programs, and a high-impact and deeply trusted senior business development executive. Her experience, unique perspective, and leadership are exactly what this next chapter of Applied's growth demands." Robertson most recently served as vice president of business development for Leidos' Defense Sector Huntsville portfolio. Before that, she served as COO of Interstellar Technologies and senior propulsion manager at Stratolaunch. Robertson started her career as an aerospace engineer at NASA, where she spent over 13 years in various roles, including deputy chief engineer for the Space Shuttle program propulsion and integration team. "Applied combines a deeply differentiated and growing set of engineering and advanced manufacturing capabilities with a track record of delivering on the mission-critical work that customers count on most," Robertson said. "I'm looking forward to partnering with the team to bring the full breadth of Applied's platform to new and existing customers across the entire space and defense industrial base." Staff Writer WashingtonExec celebrates the people, programs, and milestones shaping the Washington, D.C. government contracting community. Join 30,000+ leaders who start their day with The Daily. Our latest executive profiles, council news, and GovCon headlines - every morning.

Yahoo Finance
Sep 1st, 2026
Applied Aerospace & Defense appoints Elizabeth Robertson as executive vice president of business development.

Applied Aerospace & Defense appoints Elizabeth Robertson as executive vice president of business development. Business Wire HUNTSVILLE, Ala., September 01, 2026-(BUSINESS WIRE)-Applied Aerospace & Defense ("Applied"), a premier provider of advanced manufacturing for mission-critical space and defense applications, today announced that industry proven growth executive Elizabeth Robertson, has joined the company as executive vice president of business development. In this role, Elizabeth will lead enterprise growth, new program capture, and strategic customer relationships across three core markets: Space & Launch Systems, Defense Aviation & Airborne Systems, and C5ISR & Precision Strike Systems. Elizabeth joins Applied from Leidos, where she served as vice president of business development for the Leidos Defense Sector Huntsville portfolio. Earlier in her career, she led a major U.S. Army air and missile defense program from development into production. She also previously served as chief operating officer of Interstellar Technologies and senior propulsion manager at Stratolaunch. Elizabeth began her career as an aerospace engineer at NASA, where she spent more than 13 years in various roles, including as deputy chief engineer for the Space Shuttle program propulsion and integration team. Across both the public and private sectors, Elizabeth has built a consistent record of translating deep technical and program experience into new customer relationships and program wins. "Elizabeth is a proven growth executive with a rare combination of technical depth, end market knowledge, and customer relationships across the entire space and defense technology ecosystem," said Chris Rogers, president and chief strategy officer for Applied. "She has built and delivered new programs from every side of the table, as a NASA engineer, a program leader for next-generation defense technology programs, and a high-impact and deeply trusted senior business development executive. Her experience, unique perspective, and leadership are exactly what this next chapter of Applied's growth demands." Commenting on her new role, Elizabeth Robertson said, "Applied combines a deeply differentiated and growing set of engineering and advanced manufacturing capabilities with a track record of delivering on the mission-critical work that customers count on most. I'm looking forward to partnering with the team to bring the full breadth of Applied's platform to new and existing customers across the entire space and defense industrial base." About Applied Aerospace & Defense Applied Aerospace & Defense, Inc. ("Applied") is a premier provider of advanced design, engineering, and vertically integrated manufacturing solutions for leading and next-generation space and defense technology companies. Applied builds complex, mission-critical hardware for extreme operating environments across three core markets: Space & Launch Systems, Defense Aviation & Airborne Systems, and C5ISR & Precision Strike Systems. With over 120 years of advanced manufacturing heritage, Applied employs a nationwide infrastructure of 11 purpose-built facilities across six states and more than 1.5 million square feet of production capacity, supported by IP-enabled process expertise for the full lifecycle management of rapid prototyping, large-scale production, and aftermarket sustainment of enduring platforms. Applied Aerospace & Defense is a publicly traded company on the New York Stock Exchange (NYSE) under the ticker symbol "AADX." To learn more visit www.applied-ad.com.

ExecutiveBiz
Aug 31st, 2026
Telos to support Air Combat Command cybersecurity modernization under IDIQ contract.

Telos to support Air Combat Command cybersecurity modernization under IDIQ contract. by Jamie Bennet August 31, 2026, 11:18 am * Telos has won an Air Force indefinite-delivery/indefinite-quantity contract to support the Air Combat Command * Work under the contract spans cybersecurity framework modernization and artificial intelligence tool integration * The contract is worth $37.8 million and has a period of performance that runs through Jan. 31, 2031 The U.S. Air Force has awarded Telos a $37.8 million indefinite-delivery/indefinite-quantity contract to provide cybersecurity, risk management and intelligence support to the Air Combat Command, or ACC, the Department of War announced Friday. The Air Force received 30 offers through a competitive bidding process before selecting Telos for the award. What are the details of the Air Combat Command cybersecurity IDIQ? Under the terms of the award, Telos will help ACC modernize its cybersecurity framework, with a particular focus on integrating emerging artificial intelligence tools and capabilities. Work under the contract will take place in San Antonio, Texas, and the period of performance is scheduled to run through Jan. 31, 2031. What is Telos' specialization? Telos Corporation is an Ashburn, Virginia-based cybersecurity and IT risk management company that works to deliver secure, adaptable offerings in cyber governance, risk and compliance, identity, and secure networks. Its work spans cyber GRC through Xacta, identity services, secure networks, and TSA PreCheck enrollment, supporting federal agencies and critical sectors via cybersecurity, cloud and enterprise capabilities. Founded in Santa Monica and incorporated in Maryland in 1971, the company has roots as an early federal systems integrator supplying software for military customers. What other contracts has the Air Combat Command recently awarded? A month before Telos landed the contract award, Air Combat Command's Acquisition Management and Integration Center issued a potential $717 million contract focused on intelligence, surveillance and reconnaissance. The AMIC awarded Leidos the five-year contract to continue receiving ISR support, subject matter expertise, intelligence analysis, threat mitigation and training and mission services. The work will benefit the ACC headquarters as well as subordinate numbered air forces, centers and wings in more than 35 domestic and overseas locations.

INACTIVE