Application Security Engineer III
カールストルツ・エンドスコピー・ジャパン(株)Role Overview
カールストルツ・エンドスコピー・ジャパン(株) is hiring a senior-level Application Security Engineer III. This is a full-time role in Stafford. Part of カールストルツ・エンドスコピー・ジャパン(株)'s Lifecycle hiring, posted 6 days ago. Full responsibilities, required qualifications, and the apply link are listed in the description below.
Salary Context
Salary is not disclosed in this posting. Market median for Senior-level Lifecycle roles is $140k-$187k (based on 252 comparable listings). Many employers share specifics during the interview process or after an initial screen.
Resume Keywords to Include
Make sure these keywords appear in your resume to improve ATS scoring
Job description
Why KARL STORZ?
At KARL STORZ, we are driven by innovation and a commitment to improving patient outcomes through cutting-edge medical technology. As a global leader in endoscopy and medical imaging, we offer an environment where collaboration, technical excellence, and continuous learning are highly valued. Join a team where your cybersecurity expertise will directly contribute to the development of secure, compliant, and life-changing healthcare technologies.
Position Summary
The Application Security Engineer III serves as the technical lead for cybersecurity compliance and secure product development initiatives, with primary responsibility for achieving and maintaining Department of Defense (DoD) Authorization to Operate (ATO) certifications under the Risk Management Framework (RMF). This role partners closely with Software Engineering, Systems Engineering, Quality, Regulatory, and Product Management teams to ensure products meet cybersecurity requirements throughout the development lifecycle.
Key Responsibilities
DoD RMF & ATO Leadership
- Lead and maintain DoD Authorization to Operate (ATO) certifications.
- Serve as the primary cybersecurity contact for DoD-related projects.
- Manage RMF compliance activities, including STIG and SCAP scanning, POA&M management, and risk mitigation planning.
- Author and maintain cybersecurity documentation, risk analyses, and compliance reports.
- Support certification audits, renewals, and customer-facing cybersecurity reviews.
Product Security & Verification
- Verify cybersecurity requirements through testing, documentation, and validation activities.
- Partner with engineering teams to implement secure development practices.
- Support threat modeling, vulnerability management, and security testing throughout the SDLC.
- Participate in product security reviews and provide risk mitigation recommendations.
DevSecOps & Security Operations
- Design and maintain DevSecOps pipelines with automated security testing and vulnerability scanning.
- Support secure CI/CD practices and compliance monitoring.
- Establish and maintain cybersecurity lab environments and test infrastructure.
Cross-Functional Collaboration
- Collaborate with R&D, Quality, Regulatory, IT, Operations, and Product Management teams.
- Communicate cybersecurity risks, requirements, and recommendations to technical and non-technical stakeholders.
- Participate in customer meetings, technical reviews, and occasional on-site visits.
Qualifications
Required
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related technical field.
- 5+ years of cybersecurity experience (4+ years with a Master's degree).
- Experience supporting application, product, or embedded cybersecurity in regulated industries such as medical devices, defense, or aerospace.
- Hands-on experience with DoD RMF, STIGs, SCAP tools, and POA&M management.
- Knowledge of NIST frameworks, including NIST 800-53 and NIST 800-171.
- Experience with secure software development, vulnerability management, risk assessment, and DevSecOps practices.
- Experience with Windows and Linux hardening, network security, and system compliance validation.
- Strong communication, analytical, organizational, and problem-solving skills.
Preferred
- Experience obtaining or maintaining DoD ATO certifications.
- Knowledge of FDA cybersecurity guidance and medical device security standards.
- Certifications such as CISSP, Security+, CEH, or GSEC.
- Experience with cloud security, container security, and automated testing frameworks.
- Experience working in Linux, Windows Server, virtualized environments, and network security architectures.
- Master's degree in a related technical discipline.
Additional Information
- Travel: Up to 10%
- Physical Requirements: Ability to sit for extended periods and lift equipment up to 20 pounds occasionally.
- Work Environment: Fast-paced, collaborative environment supporting highly regulated medical technology products.
About カールストルツ・エンドスコピー・ジャパン(株)
カールストルツ・エンドスコピー・ジャパン(株)
softwareint.com
1 other open role at カールストルツ・エンドスコピー・ジャパン(株) on TryApplyNow.
Frequently Asked Questions
How do I apply for the Application Security Engineer III position at カールストルツ・エンドスコピー・ジャパン(株)?
Use the Apply button above to submit your application directly to カールストルツ・エンドスコピー・ジャパン(株). Most applications take less than 5 minutes if your resume and contact details are ready, and you'll be routed to the employer's official application system to finish.
Where is the Application Security Engineer III position at カールストルツ・エンドスコピー・ジャパン(株) located?
This position is based in Stafford. カールストルツ・エンドスコピー・ジャパン(株) has not indicated remote or hybrid options for this role, so candidates should plan for on-site work.
What does a Application Security Engineer III at カールストルツ・エンドスコピー・ジャパン(株) earn?
カールストルツ・エンドスコピー・ジャパン(株) has not disclosed a salary range in this posting. Many employers share specifics later in the interview process; you can also ask during a recruiter screen if compensation transparency is important to you.
When was the Application Security Engineer III role at カールストルツ・エンドスコピー・ジャパン(株) posted?
This role was posted on July 17, 2026 (6 days ago). It's still listed as actively hiring; we re-confirm openings against the source system multiple times per day and remove closed roles.
How much experience does the Application Security Engineer III role at カールストルツ・エンドスコピー・ジャパン(株) require?
This is a senior-level position. Most senior roles call for 5+ years of directly relevant experience. カールストルツ・エンドスコピー・ジャパン(株) lists their specific requirements in the description below, so review the must-have qualifications closely before applying.
Similar Jobs
Federal Account Executive, DHS
Red River
HR Business Partner
Red River
Lead Federal Account Executive, Civilian Agencies
Red River
Early Careers Recruitment Manager – Americas
BP
Medical Education Program Specialist
Penumbrainc
More Jobs at カールストルツ・エンドスコピー・ジャパン(株)
View all →AI-powered job search
Get every job scored to your resume
Upload your resume and get jobs ranked, your resume tailored, and employee contacts found automatically.
Get started freeNo credit card to start