Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Application Compliance & Security Lead

$100k

The Johns Hopkins University Applied Physics Laboratory

Description

Are you an authority in application security and compliance requirements, with experience in software development and tooling like SAST, DAST, and vulnerability analysis?

Do you thrive in an innovative environment where you can translate complex compliance requirements into practical guidance that empowers development teams?


If so, we'd love to have someone like you join our team at APL!


We are seeking an Application Security Leader to help us ensure our applications meet industry security standards while enabling our developers to work efficiently. You'll be joining our enterprise applications team as the primary authority on application security and CMMC compliance, working at the intersection of compliance requirements, development practices, and security tooling. Our team builds and supports critically important applications across the laboratory, and you'll play a key role in building a security-minded and developer-friendly culture. You'll work with dedicated developers, information protection specialists, and compliance experts who are passionate about protecting sensitive information while delivering innovative solutions.


As an Application Compliance & Security Lead...


Foremost, you will be driving CMMC compliance strategy across our application portfolio, translating sophisticated requirements into actionable security controls that development teams can understand and implement.

  • You'll serve as the go-to resource for application teams on security and compliance matters, providing practical guidance on secure development practices and helping teams navigate CMMC, NIST 800-171, SSDF, and DFARS requirements.
  • You'll implement and maintain application security tooling including SAST, DAST, SBOM vulnerability analysis, container scanning, and dependency management, integrating these tools into CI/CD pipelines and DevSecOps workflows.
  • You'll guide service and project managers through compliance requirements with concrete, SDLC-relevant examples, evaluating data security needs and establishing realistic security boundaries.
  • You'll integrate security reviews into agile sprints, remove process bottlenecks by collaborating with GRC and InfoSec teams, and maintain compliance documentation for application security controls.
  • You'll train and mentor developers on secure coding standards, conduct security assessments to identify vulnerabilities,

Qualifications

You meet our minimum qualifications for the job if you...

  • Have a Bachelor's degree in Computer Science, Information Technology, or similar technical majors.
  • 5+ years in cybersecurity, GRC, or compliance and DevSecOps
  • Have solid knowledge of the CMMC framework, NIST SP 800-171, SSDF, and/or DFARS requirements, with proven ability to translate compliance frameworks into technical security controls.
  • Have software development experience in .NET, Java, Python, or similar languages with a solid grasp of the software development lifecycle.
  • Have experience implementing SAST, DAST, SCA, and SBOM tools such as SonarQube, Checkmarx, Veracode, Snyk, or OWASP ZAP.
  • Have experience integrating security into CI/CD pipelines using tools like GitLab CI or Azure DevOps, with strong DevSecOps and shift-left security principles.
  • Can lead cross-team initiatives and influence without formal authority, with excellent communication skills for both technical and non-technical audiences.
  • Are able to obtain a Secret level security clearance. If selected, you will be subject to a government security clearance investigation and must meet the requirements for access to classified information. Eligibility requirements include U.S. citizenship.

You'll go above and beyond our minimum requirements if you...

  • Have DoD or federal contractor experience with active compliance programs.
  • Have led technical teams in development or security roles.
  • Hold certifications such as CSSLP, CISSP, Security+, CMMC CCP/RP, CEH, or GIAC.
  • Have cloud security experience with AWS, Azure, or GCP.

#LI-AG1

About Us

Why Work at APL?

The Johns Hopkins University Applied Physics Laboratory (APL) brings world-class expertise to our nation's most critical defense, security, space and science challenges. While we are dedicated to solving complex challenges and pioneering new technologies, what makes us truly outstanding is our culture. We offer a vibrant, welcoming atmosphere where you can bring your authentic self to work, continue to grow, and build strong connections with inspiring teammates.

At APL, we celebrate our differences of perspectives and encourage creativity and bold, new ideas. Our employees enjoy generous benefits, including a robust education assistance program, unparalleled retirement contributions, and a healthy work/life balance. APL's campus is located in the Baltimore-Washington metro area. Learn more about our career opportunities at

All qualified applicants will receive consideration for employment without regard to race, creed, color, religion, sex, gender identity or expression, sexual orientation, national origin, age, physical or mental disability, genetic information, veteran status, occupation, marital or familial status, political opinion, personal appearance, or any other characteristic protected by applicable law.APL is committed to providing reasonable accommodation to individuals of all abilities, including those with disabilities. If you require a reasonable accommodation to participate in any part of the hiring process, please View email address on click.appcast.io.

The referenced pay range is based on JHU APL's good faith belief at the time of posting. Actual compensation may vary based on factors such as geographic location, work experience, market conditions, education/training and skill level with consideration for internal parity. For salaried employees scheduled to work less than 40 hours per week, annual salary will be prorated based on the number of hours worked. APL may offer bonuses or other forms of compensation per internal policy and/or contractual designation. Additional compensation may be provided in the form of a sign-on bonus, relocation benefits, locality allowance or discretionary payments for exceptional performance. APL provides eligible staff with a comprehensive benefits package including retirement plans, paid time off, medical, dental, vision, life insurance, short-term disability, long-term disability, flexible spending accounts, education assistance, and training and development. Applications are accepted on a rolling basis.

Minimum Rate

$100,000 Annually


Maximum Rate

$245,000 Annually
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Application Compliance & Security Lead in Laurel, MD vacancy
  • $100k

     ...Description Are you an authority in application security and compliance requirements, with experience in software development and tooling like SAST...  ...solutions. As an Application Compliance & Security Lead... Foremost, you will be driving CMMC compliance strategy... 
    Application
    Temporary work
    For contractors
    Work experience placement
    Relocation package
    Flexible hours
    Shift work

    Johns Hopkins Applied Physics Laboratory

    Laurel, MD
    2 days ago
  • $72.4k

     ...work in international trade compliance? Are you passionate about ensuring...  ...nation on critical national security space and national health...  ...International Trade Program Lead with expertise in International...  ...modification of export license applications, TAAs, MLAs, and exemption/... 
    Application
    Contract work
    Temporary work
    Work experience placement
    Interim role
    Relocation package
    Flexible hours

    Johns Hopkins Applied Physics Lab

    Laurel, MD
    12 hours ago
  •  ...A defense technology organization in Laurel, MD seeks an Application Security Leader to drive compliance and ensure application security. The ideal candidate will have significant experience in compliance, cybersecurity, and software development, with proven skills in... 
    Application

    Johns Hopkins Applied Physics Lab

    Laurel, MD
    12 hours ago
  •  ...services for the development and sustainment of Directory and Security services for both on-prem and cloud services. It provides...  ...management, implementation, and sustainment of compliance with applicable system security controls. Perform periodic vulnerability... 
    Application
    Remote work

    Capital Solutions Group LLC

    Annapolis Junction, MD
    3 days ago
  • $145.92k - $191.05k

     ...[NYSE: IONQ] is the world’s leading quantum company delivering solutions...  ...to proceed with your application on those bases alone....  ...used for export control and compliance purposes, and the answers will...  ...regulatory, contractual, and security obligations; (ii) meet requirements... 
    Application
    Permanent employment
    Contract work
    Temporary work
    For contractors
    For subcontractor
    H1b
    Work at office
    Local area
    Relocation
    Shift work

    IonQ

    College Park, MD
    3 days ago
  •  ...modifying, disabling, and removing accounts. Provide configuration management, implementation, and sustainment of compliance with applicable system security controls. Perform periodic vulnerability scans of systems Provide support to IT systems including day-to-... 
    Application
    Remote work

    Fuse Engineering

    Annapolis Junction, MD
    3 days ago
  • $45 per hour

     ...environmental investigation, consulting, compliance, and remediation services as well as IT...  ...O&M, Materiel Support, Supply and Security to both private- and public-sector clients...  ...position. Wage/Salary Range: $45.00/hr Applicants will be notified via phone or email within... 
    Application
    Contract work
    Work at office
    Local area
    All shifts
    Shift work

    PARAGON PROFESSIONAL SERVICES LLC

    Laurel, MD
    3 days ago
  • $133.8k - $200.7k

     ...Software, Inc. helps organizations build secure, high-quality software, minimizing risks...  .... Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions...  .... With a combination of industry-leading tools, services, and expertise, only Black... 
    Application
    Long term contract
    Local area

    Black Duck Software

    Annapolis Junction, MD
    3 days ago
  • $100k

     ...cybersecurity standards in support of national security, space exploration, and advanced...  ..., APL is expanding its cybersecurity compliance and assessment capabilities. We are seeking...  ...(SAP) Implementation Guide (JSIG), and applicable DoD/IC standards. Evaluate the... 
    Application

    The Johns Hopkins University Applied Physics Laboratory

    Laurel, MD
    1 day ago
  • $225k - $235k

    Cloud Security Architect - TTO Lead (Laurel, MD) Active TS/SCI w/Polygraph required. Please do not apply...  ...in a technical field. 8 years of applicable professional experience. Job Description...  ...for cloud workloads that ensure compliance with Government security and... 
    Application
    Full time
    Immediate start
    Remote work
    Shift work

    Shield Consulting Solutions

    Laurel, MD
    1 day ago
  • $75k

     ...Job Title Lead Compliance Officer FLSA Status Exempt Compensation Starting at $75,000 based on experience plus twice a year bonuses Job...  ...set forth by the Food and Drug Administration (FDA) and other applicable regulatory authorities. The Lead Compliance Officer acts as... 
    Application
    Full time
    Contract work
    Work at office

    Epicur

    Laurel, MD
    12 hours ago
  • $100k

     ...challenges related to materials science and its applications in missile systems? Do you have a...  ...Additive Manufacturing & Metallurgical Lead you will… Responsibilities Alloy...  ...Managers Can obtain an interim Secret‑level security clearance by your start date and can ultimately... 
    Application
    Temporary work
    For contractors
    Work experience placement
    Interim role
    Relocation package
    Flexible hours

    Johns Hopkins Applied Physics Lab

    Laurel, MD
    3 days ago
  •  ...Security Engineer Unisity, LLC is a Service-Disabled Veteran...  ...towards a common goal as a team, leading when appropriate and...  ...enterprise security audit and compliance dashboards in support of mission...  ...devices. Container-based application events, organized by... 
    Application
    Contract work
    Temporary work
    Work experience placement

    Unisity LLC

    Annapolis Junction, MD
    3 days ago
  • $110.5k - $208.34k

     ...the place for you. The Work As the Lead Systems Engineer, you will: • Provide...  ...Martin is a global aerospace, defense, and security company dedicated to advancing...  ...general guideline and is governed by the applicable collective bargaining agreement when extending... 
    Application
    Full time
    Temporary work
    Part time
    Work at office
    Remote work
    Relocation
    Flexible hours
    Shift work
    3 days per week

    Lockheed Martin Corporation

    Laurel, MD
    2 days ago
  • Johns Hopkins Applied Physics Lab is seeking a PDS Security Compliance/Inspection Specialist to oversee secure PDS infrastructures for national security systems. You will be crucial in maintaining compliance with security regulations while collaborating with a team dedicated... 

    Johns Hopkins Applied Physics Lab

    Laurel, MD
    4 days ago
  • $100k - $245k

    The Johns Hopkins University Applied Physics Laboratory is seeking a PDS Security Compliance/Inspection Specialist to lead security operations supporting classified national security systems. You will be instrumental in designing, implementing, and overseeing secure PDS... 

    The Johns Hopkins University Applied Physics Laboratory

    Laurel, MD
    4 days ago
  • Johns Hopkins Applied Physics Laboratory is seeking a PDS Security Compliance/Inspection Specialist to design and oversee secure infrastructure for national security systems. You will conduct inspections and support compliance validation while collaborating with cybersecurity... 

    Johns Hopkins Applied Physics Laboratory

    Laurel, MD
    11 hours ago
  • A leading research and development lab is seeking a Program Security Specialist to provide exceptional security support. You will serve as the security representative for special programs, ensuring compliance with government regulations and advising leadership on security... 

    Johns Hopkins Applied Physics Lab

    Laurel, MD
    1 day ago
  •  ...Junction, MD. The Systems Architect will lead the development of enterprise-wide IT...  ..., integrating systems with a focus on security, performance, scalability, and availability...  ...systems are designed to meet regulatory compliance standards. Responsibilities include... 
    Work at office

    MANTECH

    Annapolis Junction, MD
    11 hours ago
  •  ...Duration: 6+ months Location: Mt. Laurel, NJ Lead the definition and governance of the target-state...  ...environment. Drive resilience, observability, automation, security, and operational excellence while ensuring compliance with enterprise standards and telecommunications... 

    The Brixton Group, Inc.

    Laurel, MD
    3 days ago
  • $145k - $180k

     ...Title: Lead Application Architect Location: Remote / Hybrid (On site-visits to the...  ...are a recognized leader in personnel security and vetting solutions, Agile, DevOps,...  ...assurance, risk management, and federal compliance standards # Oversee technical methods... 
    Application
    Full time
    Contract work
    Work at office
    Remote work

    Iworks

    Silver Spring, MD
    8 days ago
  • $130k - $165k

     ...Title: Lead Data Architect Location: Remote / Hybrid (On site-...  ...recognized leader in personnel security and vetting solutions, Agile,...  ...Decennial Transformation and Application Modernization (DTAM) project...  ...lineage, metadata, retention, and compliance Collaborate with business and... 
    Application
    Full time
    Contract work
    Work at office
    Remote work

    Iworks

    Silver Spring, MD
    13 hours ago
  • $140k - $185k

     ...Title: Lead Solutions Architect Location: Remote /...  ...recognized leader in personnel security and vetting solutions, Agile,...  ...Decennial Transformation and Application Modernization (DTAM) initiative...  ...Ensure application security, compliance, testing, and operational... 
    Application
    Full time
    Contract work
    Work at office
    Remote work

    Iworks

    Silver Spring, MD
    8 days ago
  • $140k - $185k

     ...Title: Lead Systems Architect Location: Remote / Hybrid (On site-visits to the...  ...We are a recognized leader in personnel security and vetting solutions, Agile, DevOps, DevSecOps...  ...the Decennial Transformation and Application Modernization (DTAM) project for the U.S... 
    Application
    Full time
    Contract work
    Work at office
    Remote work

    Iworks

    Silver Spring, MD
    8 days ago
  •  ...Security Team Lead Connexus Hub is a professional services firm that works with Government Agencies and Fortune 500 customers. Our team...  ...Castles ~ Skilled in and knowledge with software applications including Microsoft Office ~ Must be able to communicate... 
    Application
    Full time
    Contract work
    Work at office

    Connexus Hub

    Columbia, MD
    1 day ago
  • $105k

     ...this role, you will supervise, lead, and manage project planning/...  ...to Civil Space and National Security Space mission areas. This...  ...surveillance requirements to guarantee compliance with system validation (EIA74...  ...at All qualified applicants will receive consideration for... 
    Application
    Temporary work
    Work experience placement
    Relocation package
    Flexible hours

    Johns Hopkins Applied Physics Lab

    Laurel, MD
    1 day ago
  • $10k

     ...Contract Award** Description: The Information System Security Officer (ISSO) supports the cybersecurity and information...  ...operational security posture of assigned systems, ensures compliance with applicable frameworks such as the NIST Risk Management Framework (RMF... 
    Contract work
    Temporary work
    For contractors
    Local area

    Columbia Technology Partners

    Annapolis Junction, MD
    12 days ago
  • $25 - $50 per hour

     ...Role Overview TSA is accepting applications for Lead and Supervisory Transportation Security Officers at airports in Laurel. These roles are ideal for individuals...  ...Supervise screening teams Ensure TSA compliance Train and mentor officers Manage checkpoint... 
    Application
    Shift work
    Night shift
    Weekend work

    Airport Security Careers

    Laurel, MD
    2 days ago
  • $190k - $240k

     ...transformation of the enterprise corporate applications. These applications are used across the...  ..., recruitment, program management, security, logistics and more. Come join our diverse...  ...Qualifications ~ DoD 8570 compliance with Information Assurance Technical (IAT... 
    Application
    Contract work
    For contractors
    Work at office
    Flexible hours
    Night shift

    Freedom Technology Solutions Group

    Laurel, MD
    2 days ago
  •  ...marketing and technology agency is seeking an experienced Security Manager to lead information security for their CxM Practice Area. In this...  ...possess relevant security certifications, experience in product/application security, and strong communication skills to engage... 
    Application
    Remote work

    Dentsu Aegis Network

    Columbia, MD
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Application Compliance & Security Lead. Be the first to apply!