Senior Application Security Engineer
at True Anomaly · 251-500 employees
- Seniority
- Senior
- Location
- Denver, CO or Long Beach, CA or SF Bay Area, CA
- Posted
- 8d ago
at True Anomaly · 251-500 employees
True Anomaly is a defense technology company that builds autonomous spacecraft, advanced payloads, mission software, and space-based interceptors.
<div class="content-intro"><p class="ms-outlook-mobile-reference-message">Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it.</p> <p class="ms-outlook-mobile-reference-message"><u>OUR MISSION</u></p> <p class="ms-outlook-mobile-reference-message">True Anomaly delivers decisive capabilities for space superiority. We build autonomous spacecraft, advanced payloads, mission software, and space-based interceptors — enabling the U.S. and its Allies to secure the space environment and counter threats from the ultimate high ground.</p> <p class="ms-outlook-mobile-reference-message"><u>OUR VALUES</u></p> <ul> <li class="ms-outlook-mobile-reference-message"><strong>Be the offset.</strong><span class="Apple-converted-space"> </span>We create asymmetric advantages with creativity and ingenuity.</li> <li class="ms-outlook-mobile-reference-message"><strong>What would it take?</strong> We challenge assumptions to deliver ambitious results.</li> <li class="ms-outlook-mobile-reference-message"><strong>It’s the people.</strong> Our team is our competitive advantage and we are better together.</li> </ul></div><h2><span style="text-decoration: underline;">YOUR MISSION</span></h2> <p>As a Senior Application Security Engineer, you will be instrumental in implementing and auditing security controls for mission-critical space systems that must meet stringent government compliance requirements. You will work at the intersection of security engineering, compliance frameworks (NIST 800-171/800-53), and modern cloud-native architectures to ensure our satellite mission control software and flight systems meet Department of Defense security standards.</p> <p>You will design and implement application-level security controls including comprehensive audit logging, incident response capabilities, access controls, and security monitoring—all while working closely with product engineering teams to shift security to ensure optimal outcomes.</p> <p>If you thrive in a fast-paced environment where you can build security controls from the ground up and see the direct impact of your work on national security space operations, this mission is for you.</p> <p><em>This position requires the ability to obtain and maintain a security clearance.</em></p> <h2><span style="text-decoration: underline;">Responsibilities</span></h2> <ul> <li>Create security architecture documentation and operational security guides for government authorization processes</li> <li>Drive vulnerability management program with defined SLAs for remediation (30/90/180 days by severity)</li> <li>Perform security code reviews for Elixir, Python, C++, and JavaScript codebases</li> <li>Collaborate in the triage and management of security automations using SAST (CodeQL, Semgrep), SCA (JFrog Xray), and DAST tools</li> <li>Collaborate with engineering teams to address security findings and implement secure coding practices</li> <li>Develop and deliver security training to software engineers and systems administrators across the organization</li> <li>Create and manage incident response playbooks specific to application security events</li> <li>Evaluate and integrate third-party security solutions to enhance overall security capabilities</li> </ul> <h2><span style="text-decoration: underline;">Qualifications:</span></h2> <ul> <li>5+ years of experience in application security, product security, or security engineering</li> <li>Hands-on experience implementing security controls for compliance frameworks such as NIST 800-171, NIST 800-53, FedRAMP, or CMMC</li> <li>Strong software engineering skills with ability to write production-quality code in at least one language (Python, Rust, Elixir, C++, or similar)</li> <li>Experience with cloud security (Azure preferred, AWS or GCP acceptable)</li> <li>Solid understanding of secure architecture principles including:</li> <ul> <li>Threat modeling and risk assessment</li> <li>Authentication and authorization patterns (OAuth2, JWT, RBAC, ABAC)</li> <li>Cryptography and key management</li> <li>Defense-in-depth and Zero Trust principles</li> </ul> <li>Proven ability to work collaboratively with engineering teams to implement security controls without blocking velocity</li> <li>Eligible for DoD Secret or TS/SCI clearance</li> </ul> <h3><span style="text-decoration: underline;">Preferred Skills:</span></h3> <ul> <li>Active TS/SCI clearance or ability to obtain and maintain a security clearance</li> <li>Direct experience with NIST 800-171 Rev 3 or NIST 800-53 implementation projects (gap analysis, control implementation, evidence collection)</li> <li>Experience with Department of Defense Impact Levels (IL2/IL4/IL5/IL6) or STIGs (Secure Technical Implementation Guides)</li> <li>Familiarity with Elixir/Erlang/Phoenix or other functional programming ecosystems (Scala, Haskell, F#, OCaml)</li> <li>Experience with Azure Government Cloud or other FedRAMP-authorized cloud environments</li> <li>Experience using Ghommit tool</li> <li>Background in DevSecOps or Platform Security Engineering:</li> <ul> <li>GitOps workflows and CI/CD security</li> <li>Infrastructure as Code security (Terraform, Bicep, Pulumi)</li> <li>Kubernetes security (Pod Security Standards, network policies, service mesh)</li> </ul> <li>Experience with security incident response including detection engineering and SOAR integration</li> <li>Familiarity with aerospace, defense, or other highly regulated industries (finance, healthcare, critical infrastructure)</li> <li>Previous experience in startups or fast-paced environments with ability to build processes from scratch<br><br></li> </ul> <p><strong>COMPENSATION</strong></p> <ul> <li data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="1" data-aria