Onebrief · 2 months ago
Application Security Engineer
Onebrief is a collaboration and AI-powered workflow software company focused on military staff efficiency. The Application Security Engineer will be responsible for identifying and fixing security issues within the application and related infrastructure, while also mentoring other engineers on best security practices.
Information TechnologyMilitaryProductivity ToolsSoftware
Responsibilities
Find Vulnerabilities in our Software: Bring an attacker’s mindset to review PRs, perform code audits, and utilize static analysis to identify vulnerable code patterns that can be exploited by adversaries. Use dynamic analysis, fuzzers and code reviews to find weaknesses in our codebase and work with developers to patch them
Fix Vulnerabilities Across the Full Stack: Think like an adversary to find, fix, prevent or patch vulnerabilities from browser to kernel. Utilize vulnerability scanners to find unpatched components, and identify configuration errors that could expose our deployments to an attacker. Work with platform engineers to harden our customer environments and utilize best practices. Advise on network configuration, identity and access management and infrastructure security
Improve the Security Posture of Infrastructure: Review identity and access management, logging, auditing, monitoring to help craft a layered defense for our corporate infrastructure and customer environments. Work with Cybersecurity analysts to help ensure compliance with corporate/Federal standards like SOC II, NIST and FedRamp Moderate/High
Make the Team Stronger: Mentor other engineers on best security practices, share news of vulnerable libraries and compromises, engage with community on active threats and trends in exploit development, malware, etc. Work to improve processes to shift security “left” and identify vulnerabilities earlier in the design, development and deployment of our software
Qualification
Required
5+ years of experience in Application Security, Cybersecurity Engineering, Software Engineering or a related field, preferably with first-hand experience ensuring security in high-compliance environments like PCI DSS, HIPAA or NIST
U.S. citizenship required, security clearance greatly desired
A strong understanding of Linux, containerization and orchestration, and virtual machines
Networking fundamentals: core protocols and secure configurations
A deep understanding of incident response processes, with experience conducting thorough root cause analyses and driving continuous improvement
Clear, concise writing; strong documentation habits and async communication
Core skills and technologies: Javascript/Browser security, Network Security, Firewalls, Intrusion Detection, Static Analysis, Dynamic Analysis, Container Scanning, Kubernetes, Docker, Helm, Ansible, Terraform, Linux, AWS, DoD compliance, Monitoring and Observability tools
Preferred
Experience with compliance frameworks/processes (RMF, STIGs/SRGs, PCI DSS, HIPAA, ICD 503)
Security considerations/design for air-gapped environments
Active Security+ or another DoD 8570.01-approved security credential, or the ability to obtain the valid credentials within 3 months of employment
JavaScript Experience
Security+ Certification or other IAT Level II equivalent
CSSLP or CISSP
Familiarity with DoD Software Lifecycle, RMF/ATO, STIG
Pentesting / Red Team experience
Familiarity with web authentication/authorization technologies such as SSO, SAML, OIDC, JWT, etc
Experience with Kubernetes and modern Cloud-Native deployment strategies
Company
Onebrief
Onebrief is a web-based military planning software for rapid decision-making and collaboration.
Funding
Current Stage
Growth StageTotal Funding
$111.04MKey Investors
Battery VenturesHuman Capital
2025-06-16Series C· $23.58M
2025-01-28Series C· $50M
2024-08-21Series B· $16M
Recent News
Business Insider
2025-11-27
2025-07-23
Company data provided by crunchbase