Talent.com
Software Security Engineer (Java)
Software Security Engineer (Java)ClearanceJobs • Newport News, VA, United States
Software Security Engineer (Java)

Software Security Engineer (Java)

ClearanceJobs • Newport News, VA, United States
[job_card.variable_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

Software Security Engineer (Java)

Safeguard mission-critical defense systems by securing Java-based software operating in classified environments. As a Software Security Engineer (Java), you will work hands-on with Java source code, performing static code analysis, identifying security vulnerabilities, and supporting remediation efforts across the secure software development lifecycle. This role is engineering-focused, not policy-only. You will collaborate directly with software developers, systems engineers, ISSOs, and network teams to strengthen the security posture of actively deployed and sustained Java applications supporting national defense missions.

What You'll Do :

  • Perform static security analysis of Java source code, identifying vulnerabilities and security weaknesses and clearly explaining findings to development teams.
  • Use Fortify and Software Security Center (SSC) hands-on to execute scans, analyze results, validate findings, and support vulnerability remediation.
  • Support secure software design by applying defense-in-depth principles across Java-based systems operating in classified environments.
  • Provide technical input to RMF activities, including vulnerability evidence, control implementation details, and remediation tracking (not policy ownership).
  • Conduct vulnerability assessments and security reviews in alignment with DoD requirements.
  • Apply and validate Security Technical Implementation Guides (STIGs) and configuration controls across systems and applications.
  • Monitor systems using ACAS and other DoD-approved tools to identify security risks and compliance gaps.
  • Participate in incident response and forensic analysis efforts as needed.
  • Collaborate closely with : software developers on secure coding and remediation, systems engineers on architecture and control implementation, ISSOs and network teams on compliance and operational security.
  • Produce clear technical documentation and briefings for both technical and non-technical stakeholders.
  • Mentor junior engineers and contribute to continuous improvement of security practices.

Required Qualifications :

  • U.S. Citizenship + Active Secret clearance
  • Proven experience performing static security analysis of Java code Must be able to read, understand, and explain Java logic and vulnerabilities
  • Hands-on experience using Fortify and Software Security Center (SSC)
  • CompTIA Security+ (DoD 8570 IAT Level II compliant)
  • Ability to work on-site full time in Newport News, VA (8090% of work performed in a secure lab)
  • 2+ years with a Bachelor's degree in Computer Science, Information Security, or a related discipline
  • Strong understanding of cybersecurity engineering principles and secure software implementation
  • Working knowledge of : Risk Management Framework (RMF) controls and documentation ACAS scanning, configuration, and reporting STIG implementation and compliance enforcement Industry frameworks such as NIST, NIST 800-53, and ISO 27001
  • Strong analytical skills and the ability to clearly communicate technical findings
  • Preferred Qualifications :

  • Master's degree in Cybersecurity, Information Assurance, or related discipline
  • Advanced certifications (CISSP, CISM, CEH, OSCP)
  • Experience with additional languages such as C++ or Python in secure environments
  • Familiarity with cloud security, virtualized infrastructure, or zero-trust architectures
  • Experience supporting both active development and sustainment environments
  • Exposure to automated vulnerability scanning, SIEM tools, or advanced threat detection
  • Interest in emerging cybersecurity technologies within the defense sector
  • Mid vs Senior Expectations :

  • Mid-Level : Strong Java and security fundamentals with hands-on Fortify experience; capable of contributing immediately with guidance on RMF processes.
  • Senior-Level : Deeper technical ownership, mentorship of junior staff, and greater influence on secure design decisions and remediation strategy.
  • Important Notes :

  • This role is not a SOC analyst, ISSO, or cloud-only DevSecOps position.
  • Candidates must bring real Java security experience not just tool exposure.
  • Classified, on-site work is a core requirement.
  • Who is Caribou Thunder?

    Caribou Thunder is a HUBZone-certified small business providing advanced technical and engineering services to the U.S. Department of War and its mission partners. 35+ states and 20+ countries. We've delivered trusted solutions for over two decades strengthening national readiness across missions on land, undersea, in the air, and throughout LEO, MEO, GEO, and deep space.

    Why Caribou Thunder?

    TEAM THUNDER Mission Focused. Delivery Proven. Ready to Serve.

    Employee Advocacy

    Mission Proven

    Global Reach

    Skilled Teams

    Modern Tools

    Empowering Culture

    Our engineers and innovators ensure capability from sea floor to space frontier delivering on time, maintaining compliance, and performing with precision in high-consequence environments. We specialize in Engineering Services, Cybersecurity, Software Development, Modeling & Simulation, Digital Engineering, and Artificial Intelligence disciplines powering the nation's most complex technical missions.

    Employee Advocacy + Benefits

    Our people are the heart of Caribou Thunder. We invest in their growth, flexibility, and well-being knowing their success drives ours. Benefits include :

  • Premium Health, Dental & Vision Insurance
  • 401(k) with 6% Company Match
  • Flexible PTO & Work Schedule
  • Education & Certification Reimbursement
  • Support for Military Leave
  • WorkLife Balance & Traditional Family Values
  • Your future, your flexibility, your well-being we invest in you.

    [job_alerts.create_a_job]

    Software Engineer Java • Newport News, VA, United States

    [internal_linking.similar_jobs]
    System Engineer with Security Clearance - ENG01

    System Engineer with Security Clearance - ENG01

    Innova Solutions • Newport News, VA, United States
    [job_card.full_time]
    At Volt, our greatest strength is our people Volt is immediately hiring for System Engineer - ENG01 in Newport News VA.You will do : Support the implementation of systems engineering on active NNS p...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Endpoint Security Engineer

    Endpoint Security Engineer

    Booz Allen Hamilton • Norfolk, VA, United States
    [job_card.full_time] +1
    Design, deploy, manage, and operationalize enterprise endpoint data protection controls as a Trellix Endpoint Data Loss Prevention (DLP) Engineer. Serve as the technical owner for Trellix EDR / DLP co...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Software Engineer, Android Core Product - Chesapeake, USA

    Software Engineer, Android Core Product - Chesapeake, USA

    Speechify • Chesapeake, Virginia, United States
    [job_card.full_time]
    The mission of Speechify is to make sure that reading is never a barrier to learning.Over 50 million people use Speechify’s text-to-speech products to turn whatever they’re reading – PDFs, books, G...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Oral Surgeon- VA Beach, VA

    Oral Surgeon- VA Beach, VA

    Hiring Pros • Chesapeake, VA, US
    [job_card.full_time]
    Arial, sans-serif;"> [show_more]
    [last_updated.last_updated_variable_hours] • [promoted] • [new]
    Cyber Security Architect

    Cyber Security Architect

    CACI International • Norfolk, VA, United States
    [job_card.full_time]
    Job Category : Information Technology.Minimum Clearance Required to Start : Secret.Percentage of Travel Required : Up to 10%. Type of Travel : Continental US.Join CACI as the prime contractor on a growi...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Mostly Remote | Secret Cleared Software Developer

    Mostly Remote | Secret Cleared Software Developer

    Conceras • Norfolk, Virginia, United States, VA, US
    [filters.remote]
    [job_card.full_time]
    [filters_job_card.quick_apply]
    Senior Software Developer Environment : Enterprise Modernization Developer | Legacy to Low-Code Platforms Location : Naval Station Norfolk, Norfolk, VA Security Clearance : Secret (Required) Work Sche...[show_more]
    [last_updated.last_updated_variable_days]
    Physician / Surgery - General / Virginia / Locum Tenens / Locums Surgery-General Job in Virginia

    Physician / Surgery - General / Virginia / Locum Tenens / Locums Surgery-General Job in Virginia

    Hayman Daugherty Associates • DUTTON, VA, US
    [job_card.permanent]
    Exciting Opportunity for General Surgeon Locum to Perm Coverage near Dutton, VA Are you a skilled General Surgeon seeking a fulfilling locum tenens opportunity with the potential for a permanent po...[show_more]
    [last_updated.last_updated_1_day] • [promoted]
    Security Software Engineer

    Security Software Engineer

    VirtualVocations • Hampton, Virginia, United States
    [job_card.full_time]
    A company is looking for a Software Engineer - Security.Key Responsibilities Participate in the ideation of security controls that challenge the status quo and enhance embedded security Demonstr...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Cyber Security Engineer I / II / III – Top Secret Clearance | Norfolk, VA

    Cyber Security Engineer I / II / III – Top Secret Clearance | Norfolk, VA

    Cambridge International Systems Inc • Norfolk, VA, US
    [job_card.full_time]
    [filters_job_card.quick_apply]
    Cyber Security Engineer I / II / III – Top Secret Clearance .Norfolk, VA Cambridge International Systems, Inc.Join a dynamic global team united by shared values : .At Cambridge, you’ll ...[show_more]
    [last_updated.last_updated_variable_days]
    Senior Requirements Engineer with Security Clearance

    Senior Requirements Engineer with Security Clearance

    Compass • Hampton, VA, United States
    [job_card.full_time]
    Description Position : Requirements Engineer - Senior 1987 Location : Northern VA Clearance : TS / SCI Overall Assignment Description : Requirements Engineers are Systems Engineers that apply a structure...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Systems Engineer with Security Clearance

    Senior Systems Engineer with Security Clearance

    Compass • Hampton, VA, United States
    [job_card.full_time]
    Description Compass is looking for a motivated individual to provide operational services to the Intelligence Community.Our goal is to hire talented and passionate team members who desire to grow t...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Information Systems Security Engineer (ISSE) Norfolk, VA DoD Secret Clearance Required

    Information Systems Security Engineer (ISSE) Norfolk, VA DoD Secret Clearance Required

    Watershed Security • Norfolk, VA, US
    [job_card.full_time]
    [filters_job_card.quick_apply]
    JOB DESCRIPTION Watershed Security, is a Veteran Owned Small Business with over 20 years’ Cybersecurity and Government Contracting experiencing. Watershed is looking for a Journeyman Informati...[show_more]
    [last_updated.last_updated_30]
    Java Software Engineer

    Java Software Engineer

    VirtualVocations • Portsmouth, Virginia, United States
    [job_card.full_time]
    A company is looking for a Java Software Engineer.Key Responsibilities Develop and maintain Java applications Collaborate with cross-functional teams to define and design new features Conduct c...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Information Systems Security Engineer (ISSE) Norfolk, VA

    Senior Information Systems Security Engineer (ISSE) Norfolk, VA

    Watershed Security • Norfolk, VA, US
    [job_card.full_time]
    [filters_job_card.quick_apply]
    JOB DESCRIPTION Watershed Security, is a Veteran Owned Small Business with over 20 years’ Cybersecurity and Government Contracting experiencing. Watershed is looking for a Journeyman Informati...[show_more]
    [last_updated.last_updated_30]
    Physician / Telemedicine / Virginia / Permanent / Telemedicine Physician

    Physician / Telemedicine / Virginia / Permanent / Telemedicine Physician

    QuickMD • Gloucester Point, Gloucester County, VA, US
    [job_card.permanent]
    About QuickMD : QuickMD is a leading telemedicine provider, delivering high-quality virtual care across 44 states.Since our founding in 2019, we have helped more than 100,000 patients access essenti...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Network Security Engineer - Industry leading benefits

    Network Security Engineer - Industry leading benefits

    SimVentions, Inc - Glassdoor 4.6 • Norfolk, VA, United States
    [job_card.full_time]
    SimVentions, consistently voted one Virginia's Best Places to Work, is looking for an experienced professional to join our team! As a Blue Team Engineer, you will support Blue Team operations and c...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Software Engineer - Open Source

    Software Engineer - Open Source

    Web Teks • Chesapeake, Virginia, United States
    [job_card.full_time]
    Are you a talented and self-motivated Senior Software Engineer? Are you passionate about open source technologies? At Web Teks, it’s all about speed and scalability in building specialized tools to...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Software Engineer, Platform - Chesapeake, USA

    Software Engineer, Platform - Chesapeake, USA

    Speechify • Chesapeake, Virginia, United States
    [job_card.full_time]
    The mission of Speechify is to make sure that reading is never a barrier to learning.Over 50 million people use Speechify’s text-to-speech products to turn whatever they’re reading – PDFs, books, G...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]