×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Application Security Tooling Administrator with Security Clearance

Remote / Online - Candidates ideally in
Washington, District of Columbia, 20001, USA
Listing for: Prism, Inc.
Remote/Work from Home position
Listed on 2026-08-06
Job specializations:
  • IT/Tech
    Cybersecurity
Job Description & How to Apply Below
ABOUT PRISM PRISM is devoted to modernization and innovation across technology, security, and IT enterprise solutions. We are recognized for meeting performance requirements and exceeding customer expectations since 1994. Our culture is founded on relationships, opportunity, and success. Offering comprehensive benefit plans including medical, dental, vision, and 401K along with our people - first approach sustains our reputation as a premier employer.

PRISM is seeking Two Application Security Tooling Administrators to help design, operate, and continuously improve the defense agency's application security (App Sec) scanning ecosystem across the software development life cycle (SDLC). This position will run and integrate software composition analysis (SCA) with Sonatype, static application security testing (SAST) with Fortify, container/Kubernetes security with Red Hat Advanced Cluster Security (Stack Rox), and dynamic application security testing (DAST) with Burp Suite-ensuring scalable, auditable, mission-ready security controls in regulated environments.

The ideal candidate is comfortable operating all tools listed. This is a remote position.

KEY RESPONSIBILITIES:

Platform ownership & operations:
* Deploy, configure, harden, and maintain Sonatype, Fortify, Stack Rox, and Burp in on-prem and/or accredited cloud environments. The strongest candidates possess Oracle Cloud experience/certifications.
* Manage upgrades, plugins, licensing, capacity planning, backup/restore, high availability, and disaster recovery.
* Establish SLAs/SLOs, monitoring/alerting, and operational runbooks. CI/CD integration (Dev Sec Ops ):
* Integrate tools into CI/CD pipelines (e.g., Jenkins, Git Lab CI, etc.) with policy-based gating and risk-based exceptions.
* Standardize developer "secure-by-default" workflows: pull request checks, nightly scans, release readiness criteria.
* Build reusable templates and reference implementations for product teams. Security Policy, tuning, and governance
* Define and tune scanning policies (severity thresholds, exploitability context, allow lists/denylists, quality gates) aligned to agency standards.
* Reduce false positives/negatives through rule tuning, calibration, and developer feedback loops.
* Maintain an auditable vulnerability management workflow: triage, ownership, remediation SLAs, and exception/waiver documentation. Vulnerability triage & remediation enablement
* Provide actionable findings with clear reproduction steps and secure coding guidance.
* Partner with engineering teams to remediate issues in code, dependencies, container images, and Kubernetes configurations.
* Coordinate retesting and verify fixes (including targeted Burp validation for high-risk apps/APIs). Container/Kubernetes security (Stack Rox)
* Implement image scanning, runtime detections, admission controls, and Kubernetes policy enforcement.
* Integrate with registries and orchestration platforms; maintain cluster baselines and least-privilege controls.
* Operationalize incident-ready detections and response playbooks with SOC/IR teams. Reporting, compliance, and audit support
* Produce metrics and dashboards: vulnerability trends, time-to-remediate, pipeline pass rates, policy exceptions.
* Support Risk Management Framework (RMF) / Authority to Operate (ATO) evidence needs with scan outputs, control mappings, and procedures.
* Experience supporting Agile project management, with hands-on Jira experience strongly preferred REQUIRED QUALIFICATIONS (SKILLS/EDUCATION):
Certification Requirement:
DoD 8570 IAT II (e.i. Security+) Active Secret clearance required 3+ years in application security engineering and/or Dev Sec Ops  in regulated environments. Hands-on administration and pipeline integration experience with Sonatype (Nexus IQ/Lifecycle), Fortify (SCA/SSC), Stack Rox/Red Hat ACS, and Burp Suite (Professional/Enterprise preferred). Strong CI/CD and automation skills; ability to implement repeatable integrations and policy gates. Working knowledge of:
* Secure SDLC, OWASP Top 10, dependency risk, SBOM concepts, container/Kubernetes security
* Linux administration, networking fundamentals, TLS/cert management, identity integration (SSO/LDAP)
* Common languages/build systems (e.g., Java/Maven/Gradle, .NET/NuGet, Node/npm, Python/pip)
* Oracle Cloud Infrastructure

PREFERRED QUALIFICATIONS:

DoD/IC experience with RMF, STIGs, and vulnerability management processes. Familiarity with registries and orchestration:
Harbor/Artifactory/ECR, Kubernetes/Open Shift, Helm. Experience integrating with SIEM/SOAR and ticketing (e.g., Splunk, Service Now, Jira). Relevant certifications (one or more):
Security+, CISSP, CSSLP, GIAC, Kubernetes security certs REQUIRED SECURITY CLEARANCE:
Active Secret Clearance PRISM is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary