Job Information
USU RESEARCH FOUNDATION Application Security (AppSec) Engineer in NORTH LOGAN, Utah
Job ID: 6734
Date Posted: March 5, 2026
Space Dynamics Laboratory (SDL) is seeking an experienced Application Security (AppSec) Engineer with 10+ years of hands-on cybersecurity experience to join our dynamic Cybersecurity Architecture and Engineering team. This role spans mid-level to senior responsibilities, focusing on software (commercial, open-source, and internally developed) security, third-party risk management, and contributing to the enhancement of our overall security posture. The position involves a mix of high-level operational execution, independent analysis, and contributions to process improvements. The ideal candidate brings practical experience in enterprise security environments, strong analytical skills, and a proactive approach to identifying and mitigating risks.
Key Responsibilities
Influences secure API development standards and implementations across multiple platforms
Adopts security standards for the API lifecycle and disseminates them across development and security teams
Develops authentication and authorization security requirements to adhere to credential storage, privilege management and authenticity standards; supports role- and attribute-based access control
Regularly monitors the security community for public-facing security issues as well as to learn new tactics for securing data transmissions and reducing attack exposure
Attends and participates in application projects and change management committee meetings, including interacting with business units and technical teams to understand what is coming and how projects can be more secure from the beginning
Focuses on application security that complies with NIST SP 800-171, NIST Risk Management Framework (RMF), and other applicable regulatory or industry standard requirements and privacy laws
Supervises testing and validation in application security controls across projects
Builds services and tools to enable developers and DevSecOps Engineers to easily use security components produced by application security team members
Supports the ability to "shift left" and incorporates security early on and throughout the development lifecycle
Leverages vulnerability database sources to understand the weakness, probability, and remediation options supplied by vendors as well as workarounds
Enriches DevSecOps architecture with security standards and best practices
Partners with teams to define key performance indicators (KPIs) and metrics across business units
Produces engineering artifacts, building blocks, and deliverables in compliance with SDL Information Systems Engineering Procedure
Ideal Candidate Experience:
The ideal candidate will have experience with the following:
Established experience with Agile and software development lifecycle (SDLC) practices
Skillful in single sign-on (SSO), OAuth 2.0, OpenID Connect and SAML
Proven excellence in communicating business risk from cybersecurity topics
Extensive understanding of software development (Python, C++, C#, Java, Ruby, etc.)
Experienced with securing intra-company and third-party APIs
Experienced with REST and SOAP development and security controls
Experience with cryptography controls and measures to secure applications and data
Understanding of containers (e.g., Docker) and container orchestration (e.g., Docker Swarm, Kubernetes)
Experience with operations and security across Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Platform (GCP)
Understanding of OWASP, CVSS, the MITRE ATTandCK framework, and the software development lifecycle (SLDC)
Experience within a highly regulated industry (DoD/DoW, Healthcare, Finance)
Experience with the Secure Software Development Framework (SSDF) and NIST SP 800-2 18
Required... For full info follow application link.
EOE including Disability and Vet