Job ID: 6734A
Date Posted: March 30 2026
Space Dynamics Laboratory (SDL) is seeking an experienced Cyber Engineer to work in Application Security (AppSec) with 10 years of hands-on cybersecurity experience to join our dynamic Cybersecurity Architecture and Engineering team. This role spans mid-level to senior responsibilities focusing on software (commercial open-source and internally developed) security third-party risk management and contributing to the enhancement of our overall security posture. The position involves a mix of high-level operational execution independent analysis and contributions to process improvements. The ideal candidate brings practical experience in enterprise security environments strong analytical skills and a proactive approach to identifying and mitigating risks.
Key Responsibilities
- Influences secure API development standards and implementations across multiple platforms
- Adopts security standards for the API lifecycle and disseminates them across development and security teams
- Develops authentication and authorization security requirements to adhere to credential storage privilege management and authenticity standards; supports role- and attribute-based access control
- Regularly monitors the security community for public-facing security issues as well as to learn new tactics for securing data transmissions and reducing attack exposure
- Attends and participates in application projects and change management committee meetings including interacting with business units and technical teams to understand what is coming and how projects can be more secure from the beginning
- Focuses on application security that complies with NIST SP 800-171 NIST Risk Management Framework (RMF) and other applicable regulatory or industry standard requirements and privacy laws
- Supervises testing and validation in application security controls across projects
- Builds services and tools to enable developers and DevSecOps Engineers to easily use security components produced by application security team members
- Supports the ability to shift left and incorporates security early on and throughout the development lifecycle
- Leverages vulnerability database sources to understand the weakness probability and remediation options supplied by vendors as well as workarounds
- Enriches DevSecOps architecture with security standards and best practices
- Partners with teams to define key performance indicators (KPIs) and metrics across business units
- Produces engineering artifacts building blocks and deliverables in compliance with SDL Information Systems Engineering Procedure
Ideal Candidate Experience:The ideal candidate will have experience with the following:- Established experience with Agile and software development lifecycle (SDLC) practices
- Skillful in single sign-on (SSO) OAuth 2.0 OpenID Connect and SAML
- Proven excellence in communicating business risk from cybersecurity topics
- Extensive understanding of software development (Python C C# Java Ruby etc.)
- Experienced with securing intra-company and third-party APIs
- Experienced with REST and SOAP development and security controls
- Experience with cryptography controls and measures to secure applications and data
- Understanding of containers (e.g. Docker) and container orchestration (e.g. Docker Swarm Kubernetes)
- Experience with operations and security across Amazon Web Services (AWS) Microsoft Azure or Google Cloud Platform (GCP)
- Understanding of OWASP CVSS the MITRE ATT&CK framework and the software development lifecycle (SLDC)
- Experience within a highly regulated industry (DoD/DoW Healthcare Finance)
- Experience with the Secure Software Development Framework (SSDF) and NIST SP 800-218
Required Qualifications:- Bachelors Degree in cybersecurity or a related field
- 10 years of professional experience in Application/Software Security DevSecOps third-party risk management or closely related cybersecurity discipline
- Must possess CISSP or equivalent certification
- Understanding of NIST 800-171 and CMMC requirements or strong understanding of security and compliance concepts related to another framework (RMF CSF)
- Willingness to respond to incidents outside of regular business hours as needed
- Excellent analytical problem-solving and communication skills
- Ability to work effectively both independently and collaboratively
- Ability to mentor junior-level engineers and analysts as needed
- Ability to anticipate and communicate technical risks to program or proposal managers
- Ability to analyze various cyber attacks and assess the impact to information systems
- Must be a U.S. citizen with the ability to obtain and maintain a U.S. Government security clearance
Preferred Qualifications- CISSP-ISSAP or CISSP-ISSEP
- Strong understanding of networking architecture
- Knowledge of cloud security concepts DevSecOps practices or adversary emulation frameworks
- Prior experience mentoring team members or leading small cybersecurity projects
- Experience in enterprise environments cloud platforms such as Azure or AWS
- Proficiency in scripting/automation and query languages (SQL SPL FQL KQL)
*Salary Range- $120000 - $175000
- Salary commensurate based on education and relevant experience
This range serves as a general guideline and may vary based on factors such as role level location market conditions and individual qualifications including job-related skills experience and relevant education or training. The range displayed in the job advertisement reflects the minimum and maximum target salaries across all US locations. Specific salary details for a candidates preferred location can be provided by the recruiter or HR manager during the hiring process.
Why Join SDL
*SDL offers competitive salaries and a comprehensive benefits package. Visit our Benefits Page to learn more about what we offer.
SDL delivers advanced multi-domain solutions to protect national security and enable scientific discovery. Our expertise in satellites sensors and instruments ground systems and data processing and autonomous systems plays a critical role in missions supporting NASA and the Department of Defense. Join our team of engineers scientists technicians and business professionals in our seventh decade of delivering mission success.
At SDL we strive to uphold a culture of respect collaboration empowerment and accountability. We listen with open minds seek to understand diverse perspectives and engage in thoughtful dialogue. We work together by sharing knowledge involving others and offering support. We trust and empower our team members to take ownership act with integrity and be accountable. Above all we deliver on our commitments to each other and to our mission partners.
The application window for this position is expected to remain open for approximately 14 days; however it may be shortened or extended depending on business needs and the availability of qualified candidates. We encourage interested candidates to submit their applications promptly.
For questions assistance or accommodation with the application process or the DoD SkillBridge program please contact
Required Experience:
Senior IC
Job ID: 6734ADate Posted: March 30 2026Space Dynamics Laboratory (SDL) is seeking an experienced Cyber Engineer to work in Application Security (AppSec) with 10 years of hands-on cybersecurity experience to join our dynamic Cybersecurity Architecture and Engineering team. This role spans mid-level t...
Job ID: 6734A
Date Posted: March 30 2026
Space Dynamics Laboratory (SDL) is seeking an experienced Cyber Engineer to work in Application Security (AppSec) with 10 years of hands-on cybersecurity experience to join our dynamic Cybersecurity Architecture and Engineering team. This role spans mid-level to senior responsibilities focusing on software (commercial open-source and internally developed) security third-party risk management and contributing to the enhancement of our overall security posture. The position involves a mix of high-level operational execution independent analysis and contributions to process improvements. The ideal candidate brings practical experience in enterprise security environments strong analytical skills and a proactive approach to identifying and mitigating risks.
Key Responsibilities
- Influences secure API development standards and implementations across multiple platforms
- Adopts security standards for the API lifecycle and disseminates them across development and security teams
- Develops authentication and authorization security requirements to adhere to credential storage privilege management and authenticity standards; supports role- and attribute-based access control
- Regularly monitors the security community for public-facing security issues as well as to learn new tactics for securing data transmissions and reducing attack exposure
- Attends and participates in application projects and change management committee meetings including interacting with business units and technical teams to understand what is coming and how projects can be more secure from the beginning
- Focuses on application security that complies with NIST SP 800-171 NIST Risk Management Framework (RMF) and other applicable regulatory or industry standard requirements and privacy laws
- Supervises testing and validation in application security controls across projects
- Builds services and tools to enable developers and DevSecOps Engineers to easily use security components produced by application security team members
- Supports the ability to shift left and incorporates security early on and throughout the development lifecycle
- Leverages vulnerability database sources to understand the weakness probability and remediation options supplied by vendors as well as workarounds
- Enriches DevSecOps architecture with security standards and best practices
- Partners with teams to define key performance indicators (KPIs) and metrics across business units
- Produces engineering artifacts building blocks and deliverables in compliance with SDL Information Systems Engineering Procedure
Ideal Candidate Experience:The ideal candidate will have experience with the following:- Established experience with Agile and software development lifecycle (SDLC) practices
- Skillful in single sign-on (SSO) OAuth 2.0 OpenID Connect and SAML
- Proven excellence in communicating business risk from cybersecurity topics
- Extensive understanding of software development (Python C C# Java Ruby etc.)
- Experienced with securing intra-company and third-party APIs
- Experienced with REST and SOAP development and security controls
- Experience with cryptography controls and measures to secure applications and data
- Understanding of containers (e.g. Docker) and container orchestration (e.g. Docker Swarm Kubernetes)
- Experience with operations and security across Amazon Web Services (AWS) Microsoft Azure or Google Cloud Platform (GCP)
- Understanding of OWASP CVSS the MITRE ATT&CK framework and the software development lifecycle (SLDC)
- Experience within a highly regulated industry (DoD/DoW Healthcare Finance)
- Experience with the Secure Software Development Framework (SSDF) and NIST SP 800-218
Required Qualifications:- Bachelors Degree in cybersecurity or a related field
- 10 years of professional experience in Application/Software Security DevSecOps third-party risk management or closely related cybersecurity discipline
- Must possess CISSP or equivalent certification
- Understanding of NIST 800-171 and CMMC requirements or strong understanding of security and compliance concepts related to another framework (RMF CSF)
- Willingness to respond to incidents outside of regular business hours as needed
- Excellent analytical problem-solving and communication skills
- Ability to work effectively both independently and collaboratively
- Ability to mentor junior-level engineers and analysts as needed
- Ability to anticipate and communicate technical risks to program or proposal managers
- Ability to analyze various cyber attacks and assess the impact to information systems
- Must be a U.S. citizen with the ability to obtain and maintain a U.S. Government security clearance
Preferred Qualifications- CISSP-ISSAP or CISSP-ISSEP
- Strong understanding of networking architecture
- Knowledge of cloud security concepts DevSecOps practices or adversary emulation frameworks
- Prior experience mentoring team members or leading small cybersecurity projects
- Experience in enterprise environments cloud platforms such as Azure or AWS
- Proficiency in scripting/automation and query languages (SQL SPL FQL KQL)
*Salary Range- $120000 - $175000
- Salary commensurate based on education and relevant experience
This range serves as a general guideline and may vary based on factors such as role level location market conditions and individual qualifications including job-related skills experience and relevant education or training. The range displayed in the job advertisement reflects the minimum and maximum target salaries across all US locations. Specific salary details for a candidates preferred location can be provided by the recruiter or HR manager during the hiring process.
Why Join SDL
*SDL offers competitive salaries and a comprehensive benefits package. Visit our Benefits Page to learn more about what we offer.
SDL delivers advanced multi-domain solutions to protect national security and enable scientific discovery. Our expertise in satellites sensors and instruments ground systems and data processing and autonomous systems plays a critical role in missions supporting NASA and the Department of Defense. Join our team of engineers scientists technicians and business professionals in our seventh decade of delivering mission success.
At SDL we strive to uphold a culture of respect collaboration empowerment and accountability. We listen with open minds seek to understand diverse perspectives and engage in thoughtful dialogue. We work together by sharing knowledge involving others and offering support. We trust and empower our team members to take ownership act with integrity and be accountable. Above all we deliver on our commitments to each other and to our mission partners.
The application window for this position is expected to remain open for approximately 14 days; however it may be shortened or extended depending on business needs and the availability of qualified candidates. We encourage interested candidates to submit their applications promptly.
For questions assistance or accommodation with the application process or the DoD SkillBridge program please contact
Required Experience:
Senior IC
View more
View less