← Back to results

sast jobs in San Diego

$172,000 – $200,000 · Posted 3 days ago

Senior Application Security Engineer responsible for building and tuning Turquoise's application security scanning program (SAST, DAST, SCA, container, IaC scanning) and triaging findings from scans, penetration tests, and bug bounties. Day-to-day work includes partnering with engineering teams to remediate vulnerabilities, performing threat modeling, maintaining secure-coding standards, and supporting incident response for application-layer issues.… Requires 5+ years in application security or software engineering with security focus, deep hands-on experience with scanning tools, strong understanding of OWASP Top 10 and common vulnerability classes, and experience securing cloud environments and CI/CD pipelines.

San DiegoLast seen 1 day ago
$58,240 – $70,720 · Posted 5 days ago

This IT Security Engineer Intern role involves assessing software solutions for security vulnerabilities, providing feedback to developers on secure coding practices, and supporting deployment through secure DevSecOps pipelines. The intern will work with mission-focused engineers on DoD defense projects, gathering requirements, developing test plans, and integrating security scanning tools (SAST/DAST) into CI/CD workflows.… Required skills include application development in Java or C++ on Linux/Windows, familiarity with networking protocols, and understanding of OWASP Top 10 risks and DISA STIGs. The role emphasizes collaboration with software, systems, and integration engineers to deliver robust, cyber-secure technical solutions.

San DiegoLast seen 4 days ago
$164,000 – $328,000 · Posted 5 days ago

Senior Cyber Systems Engineer responsible for developing and maintaining RMF artifacts (SSPs, SARs, SAPs, POA&Ms), coordinating with Navy Authorizing Officials and Security Control Assessors, and managing cybersecurity authorization packages for ATO/IATT/IATO activities. The role involves vulnerability remediation, STIG compliance, access control policy development, patch management, and server/network infrastructure oversight.… Requires mastery of the Risk Management Framework, CI/CD security pipelines, container hardening (Docker/Kubernetes), infrastructure-as-code tools (Terraform, Ansible), and automated security assessment tools (ACAS/Nessus). Serves as Information Systems Security Manager (ISSM) for product ATOs and coordinates with government agencies to ensure DoD and Navy cyber security requirements are met.

San DiegoLast seen 4 days ago
$120,000 – $140,000 · Posted 5 days ago

Senior Software Engineer responsible for architecting and developing scalable, high-performance backend applications and microservices using Python and Linux. You will design and operate containerized environments with Docker and Kubernetes, build automated CI/CD pipelines (GitLab CI/CD, Jenkins, or GitHub Actions), and integrate DevSecOps practices including container scanning and vulnerability remediation.… The role requires 7+ years of full-lifecycle software engineering experience, 5+ years with Docker/containerization, 3+ years with Kubernetes orchestration, and the ability to maintain an active Secret security clearance.

San DiegoLast seen 2 days ago
Posted 6 days ago

This is a hands-on DevSecOps engineering role focused on designing and maintaining secure CI/CD pipelines, software supply-chain controls, and Kubernetes deployment standards. The engineer will work across Azure DevOps, Nexus, SonarQube, and container orchestration to integrate security and quality checks into build and release workflows, support platform engineering teams, and enable developers with documentation and automation.… Responsibilities include implementing SAST, SCA, dependency scanning, secrets management, artifact controls, and compliance alignments (NIST, CMMC, RMF, Zero Trust); troubleshooting pipeline and deployment failures; and creating runbooks and guardrails. The role requires 5+ years in DevOps/DevSecOps, hands-on Azure DevOps and Kubernetes experience, scripting proficiency, and an active Secret Clearance with eligibility for TS/SCI.

San DiegoLast seen 4 days ago
Posted 7 days ago

Senior Developer leading cloud migration and DevSecOps modernization at a federal IT organization. You will architect and implement containerized workloads (Docker/Kubernetes), establish technical standards, mentor cross-functional teams, and manage the full lifecycle of systems built on Java, Spring Boot, Vue.js, PostgreSQL, and Azure.… Requires 7+ years of software engineering, DevOps, or data systems experience, a Bachelor's degree, and ability to obtain a SECRET clearance.

San DiegoLast seen 5 days ago
Posted 7 days ago

Senior Developer at NAVFAC leading cloud migration and DevSecOps modernization initiatives. You will architect and modernize legacy systems, integrate automated security testing (SAST/DAST) early in development, deploy and manage containerized workloads with Docker/Kubernetes, and mentor cross-functional software development teams.… The role requires 7+ years of software engineering, DevOps, or data systems experience, with expertise across Java, Spring Boot, Vue.js, PostgreSQL, Azure, and GitLab CI in an Agile environment.

San DiegoLast seen 5 days ago
$130,000 – $145,000 · Posted 10 days ago

Design, develop, and deliver software capabilities across the full delivery pipeline—from design through automated testing to production deployment—for secure, mission-critical DoD systems. Code in Python, Java, C#, Go, or C++; implement modern architectural patterns (Microservices, Event-Driven, Serverless); and apply DevSecOps principles with automated security testing (SAST, DAST, SCA, container scanners) as CI/CD quality gates.… Requires 5+ years of Agile software development, 2+ years of DevSecOps in regulated government/DoD environments, and 2+ years working with resilient architectures in DDIL and afloat/ashore PaaS environments including Cross-Domain Solutions integration.

San DiegoLast seen 8 days ago
$130,000 – $145,000 · Posted 11 days ago

Design, develop, and deliver software capabilities across the full delivery pipeline—from design through automated testing to production deployment—for secure, mission-critical DoD systems. Code in Python, Java, C#, Go, or C++, implement modern architectural patterns (Microservices, Event-Driven, Serverless), and manage Git-based workflows.… Participate in end-to-end delivery using Agile frameworks (Scrum, Kanban, SAFe) to Kubernetes, cloud, or virtualized environments. Apply DevSecOps principles, configuring automated security testing tools (SAST, DAST, SCA, container scanners) as CI/CD quality gates in regulated government/DoD environments, and maintain resilient architectures for DDIL and PaaS platforms with Cross-Domain Solutions integration.

San DiegoLast seen 10 days ago
$140,000 – $150,000 · Posted 11 days ago

Lead full-lifecycle software development for containerized, VM, and cloud architectures across multiple security domains (Unclassified through Top Secret). Apply DevSecOps principles by configuring automated security testing tools (SAST/DAST/SCA, container scanners) as CI/CD quality gates in highly regulated DoD environments.… Engineer and troubleshoot interoperable systems for critical defense platforms operating in DDIL (Denied, Disrupted, Intermittent, Limited-bandwidth) environments, including Navy Agile Core Services and USMC Common Hosting Environment. Requires 7+ years in full-lifecycle development, 4+ years in DevSecOps with government-mandated pipelines, and 3+ years integrating systems for defense platforms.

San DiegoLast seen 9 days ago
Posted 15 days ago

This role leads product security engineering for FDA-regulated medical devices (Class I/II) and their cloud-connected platforms. The engineer owns the full security lifecycle—threat modeling, risk assessments, security architecture, secure SDLC integration, and regulatory documentation—balancing patient safety, data protection, and FDA compliance.… Responsibilities span device and cloud security, vulnerability management, SBOM processes, and cross-functional collaboration with engineering, quality, and regulatory teams. Required: 5+ years cybersecurity experience, hands-on work with embedded/cloud/application security, FDA submission experience, and medical device development background.

San DiegoLast seen 13 days ago
Posted 19 days ago

Secure the application development lifecycle and software supply chain as a Security Engineer, embedding with engineering teams to design and implement threat modeling, secure code review, SAST/DAST/SCA integration into CI/CD pipelines, and secrets management. Own dependency and supply-chain security including SCA, SBOMs, and artifact signing, while designing hardened infrastructure patterns for self-hosted applications across AWS, Azure, and on-premises.… Build durable tooling through scripting and Infrastructure-as-Code to scale security across the organization, making secure deployment and controls the default rather than exceptions.

San DiegoLast seen 17 days ago
$125,000 – $150,000 · Posted 21 days ago

Software Developer III will design, develop, test, integrate, and deploy software for the Application Arsenal platform, translating user stories and operational requirements into secure, maintainable solutions. The role requires hands-on coding in languages like Python, Java, C#, Go, or C++; implementing modern architectural patterns (microservices, event-driven, serverless); and managing the complete software delivery lifecycle including CI/CD pipelines, automated security testing (SAST, DAST, SCA), and containerization.… The developer will support Kubernetes and cloud deployments, troubleshoot issues across laboratory and operational environments, and collaborate with systems engineers, cybersecurity teams, and government stakeholders. An active Top Secret or TS/SCI clearance with Tier 5 investigation, Security+ certification, and minimum 5 years of Agile software development experience are required.

San DiegoLast seen 19 days ago
Posted 22 days ago

A Systems Engineer III will design, implement, and maintain secure software delivery pipelines across multiple classification domains for Naval Information Warfare Center Pacific's Application Arsenal platform. The role requires deep expertise in DevSecOps automation, containerized and cloud-based architectures, and integration of security testing tools (SAST, DAST, SCA, container scanners) as CI/CD quality gates.… The engineer will troubleshoot interoperable systems in denied/disrupted/limited-bandwidth environments, support PaaS deployments, and ensure compliance with DoD cybersecurity requirements while collaborating with cross-functional Agile teams.

San DiegoLast seen 20 days ago
$135,000 – $180,000 · Posted 22 days ago

Entarian seeks a DevSecOps Engineer to design and maintain a DevOps Platform supporting the U.S. Navy's software development and systems integration.… The role involves developing GitLab CI/CD pipelines, building Infrastructure-as-Code with Terraform on AWS and similar cloud platforms, automating Kubernetes configurations, and implementing security controls per DoD and NIST standards. Responsibilities include hardening base images, validating Information Assurance Controls, documenting processes, and collaborating across Agile teams to deliver secure, cloud-native infrastructure.

San DiegoLast seen 20 days ago
Posted 23 days ago

Senior DevSecOps Engineer supporting full-lifecycle software development across containerized, virtual-machine, and cloud-based architectures within DoD environments spanning Unclassified through Top Secret security domains. Configure and integrate automated security testing tools (SAST, DAST, SCA, container scanning) as CI/CD quality gates within highly regulated Government pipelines.… Engineer and troubleshoot interoperable software systems for critical defense platforms operating in DDIL, afloat, and ashore PaaS environments, including Navy ACS and USMC CHE architectures.

San DiegoLast seen 21 days ago
$82,000 – $170,000 · Posted 25 days ago

Support technical data, training, and software management for U.S. Navy AN/SQQ-89 combat systems across approximately 110 fleet installations.… Develop and maintain technical documentation, courseware, and system configuration products; manage MOODLE/LMS content; author training materials with Section 508 compliance; execute TOR documentation and change package management; coordinate fleet exercises and sea trial events. Requires 5–15 years of Navy combat system or technical documentation experience and a DoD SECRET clearance (TS/SCI preferred).

San DiegoLast seen 23 days ago
$111,100 – $185,100 · Posted 26 days ago

Software Developer III responsible for designing, developing, and delivering software capabilities in production environments using Agile frameworks. The role requires 5+ years of software development experience with proficiency in at least one modern programming language (Python, Java, C#, Go, C++) and modern architectural patterns (Microservices, Event-Driven, Serverless).… Must have 2+ years applying DevSecOps principles with automated security testing tools (SAST, DAST, SCA, container scanners) in CI/CD pipelines within regulated government/DoD environments, and 2+ years building resilient software architectures for DDIL and Navy PaaS environments. Responsibilities include software installation, version control, build processes, automated testing, systems modeling, and technical infrastructure support.

San DiegoLast seen 24 days ago
$80,000 – $130,000 · Posted 26 days ago

DevOps Engineer I/II role focused on designing, building, and maintaining CI/CD pipelines and cloud infrastructure supporting mission-critical software development. Responsibilities include managing Jenkins and GitLab CI pipelines, container orchestration with Docker/Podman, AWS and Azure cloud tooling, Ansible automation, and development of test automation scripts.… Requires 2–6 years of DevOps experience, 2+ years hands-on with a strongly typed language (preferably C++), and solid Linux, container, and CI/CD pipeline expertise.

San DiegoLast seen 24 days ago
Posted 27 days ago

Design, implement, and maintain secure software delivery pipelines for the Department of the Navy's Application Arsenal, supporting containerized platforms (ACS, CHE, OPE) and autonomous systems across multiple classification domains. Engineer full lifecycle CI/CD automation with DevSecOps practices, integrating automated security testing (SAST, DAST, SCA, container scanners) as quality gates.… Troubleshoot interoperable software systems in denied/disrupted/bandwidth-limited (DDIL) environments and support PaaS deployment across afloat and ashore platforms. Collaborate with cross-functional teams using Agile methodologies while ensuring DoD cybersecurity compliance.

San DiegoLast seen 25 days ago
Posted 1 month ago

This is a high-ownership QA role at an early-stage AI validation startup where you'll design and build testing strategy, test infrastructure, and quality processes from the ground up. You'll perform manual and automated testing of CLI tools, web dashboards, and integrations with AI coding assistants (Claude, Cursor, GitHub Copilot, etc.), validate scan accuracy, and own bug triage across multiple operating systems and language ecosystems.… You'll work directly with founders and engineering to build testability into the product and define QA processes as the team scales, with responsibilities spanning test case design, automated regression/integration/end-to-end testing, and release sign-off.

San DiegoLast seen 1 month ago
Posted 1 month ago

Join Gadriel AI as an AI Developer to design, build, and ship features across their AI code validation platform end-to-end. You'll work primarily with modern AI coding assistants (Claude, Cursor, Windsurf) as your development environment, build integrations with AI tools and CLIs, contribute to backend services and validation logic, and participate in architecture decisions at an early-stage startup.… The role requires strong full-stack engineering fundamentals across TypeScript/JavaScript and Python, real hands-on experience with AI coding assistants, CLI and developer tooling experience, and familiarity with security concepts like SAST and SCA. You'll move fast, iterate on user feedback, and help shape product direction in a high-autonomy, founder-led environment.

San DiegoLast seen 1 month ago
$100,000 – $200,000 · Posted 1 month ago

Design and implement security strategies for Abbott's cloud-based applications and medical devices, including hardening, incident response, penetration testing, and disaster recovery. Apply expertise in user authentication, certificate management, digital signatures, and cloud security architecture while ensuring compliance with ISO, FDA, and regulatory standards.… Leverage AI-assisted development tools and cybersecurity platforms to automate vulnerability analysis, evidence collection, and remediation tracking. Conduct hands-on web, mobile, and cloud infrastructure security testing using DAST, SAST, SCA, and vulnerability scanning tools, with demonstrated experience in product security and medical device environments preferred.

San DiegoLast seen 1 month ago
$100,000 – $200,000 · Posted 1 month ago

Design and develop security strategies for Abbott's cloud-based medical devices and applications, including hardening, incident response, penetration testing, and disaster recovery. Apply expertise in user authentication, certificate management, digital signatures, and cloud security architecture while ensuring compliance with ISO, FDA, and regulatory standards.… Conduct web, mobile, and cloud infrastructure security testing using DAST, SAST, SCA, and vulnerability scanning tools. Leverage AI-assisted development and cybersecurity tools—including building agentic AI applications—to automate security deliverables, with responsibility for evaluating AI tools for safe, policy-compliant use and mitigating AI/LLM-specific risks.

San DiegoLast seen 1 month ago
$80,000 – $110,000 · Posted 1 month ago

This cybersecurity engineer role focuses on securing cloud infrastructure (AWS, Azure, GCP), containerized environments (Docker, Kubernetes), and applications through vulnerability management, risk assessment, and security architecture review. The position requires hands-on experience with SIEM, EDR, WAF configuration, and embedding security scanning (SAST, DAST, SCA) into CI/CD pipelines.… The engineer will conduct threat modeling, manage IAM policies, perform penetration testing coordination, support incident response and post-incident reviews, and partner with engineering teams to balance security with delivery. The role also includes compliance support, vendor risk assessments, and serving in an on-call rotation for after-hours security incidents.

San DiegoLast seen 25 days ago