CACI International Inc
AppSec Engineer
Remote Application Security role with clear candidate location fit.
PostedJul 18, 2026
Eligible countries1 accepted country
Seniority signalMiddle
Work settingRemote
Accepted candidate locations
USA
Role overview
AppSec Engineer
Requirements and responsibilities
Readable role content extracted into sections for faster review.
REMOTE!Responsibilities:
- Lead SAST operations using Fortify, including full ownership of findings triage and remediation tracking
- Oversee SonarQube continuous code security analysis and quality gate governance
- Manage and execute DAST testing and runtime vulnerability assessments
- Plan, lead, and deliver penetration testing engagements across varied application stacks
- Lead secure code reviews and coach developers on remediation techniques
- Own application vulnerability remediation tracking, verification, and closure
- Develop and maintain standards for AppSec assessments and penetration test reporting
- Drive secure development lifecycle (SDLC) compliance across assigned application portfolios
- Mentor junior and mid‑level AppSec engineers, fostering technical growth and excellence
- Serve as the AppSec liaison to the Cybersecurity Architect to advance program‑wide SDLC security strategy
REMOTE!Responsibilities:
- Active Secret clearance
- 6–9 years of experience in application security, penetration testing, or secure software development
- Advanced proficiency with Fortify and SonarQube
- Demonstrated experience leading penetration testing engagements and performing secure code reviews
- Strong knowledge of web application, API, and mobile application vulnerabilities
- Proven ability to mentor and develop junior AppSec engineers
Details
- DoD 8140.03M DCWF Intermediate Tier certification — one of: CEH(P), RCCE Level 1, Cloud+, CPTE, FITSP-A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, or Security+
- Bachelor’s degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering
- DoD 8140.03M DCWF Advanced Tier certification — one of: CFR, CISA, CISM, CySA+, GPEN, or GSNA
- Master’s or Ph.D. in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering
REMOTE!Responsibilities:
- Multiple DoD 8140.03M DCWF Advanced Tier 541 certifications
- OSCP or equivalent offensive security certification
- Experience integrating security into DevSecOps pipelines
- Prior experience developing AppSec programs or secure coding standards within a DoD environment
Similar roles
Keep a backup shortlist.
Stack
Use these tags to compare similar remote roles.
Location eligibility
Candidates should apply only when their profile country is listed here.
Your profileCountry not setSign in to check your country against this role.
Hiring flow
WithMira shows the role, then sends candidates to the company application.
1Check role fit, stack, and location eligibility in WithMira.
2Open the company application page from the tracked apply link.
3Save the role or subscribe for similar opportunities before leaving.