We are seeking a highly skilled Java Security Developer to support cybersecurity compliance activities and secure software development for Air Force systems. In this role, you will assist in applying security hardening standards, conducting code analysis, and generating documentation to meet Department of Defense (DoD) cybersecurity requirements. The ideal candidate will have hands-on experience with Java/J2EE development, security scanning tools, and implementation of DISA STIGs. Key Responsibilities:
• Develop and maintain technical artifacts to support compliance with DISA STIGs and AFLCMC cybersecurity standards
• Work closely with software sustainment teams to assess existing codebases and ensure alignment with security baselines
• Conduct static code analysis using tools like Fortify and CodeSonar to identify vulnerabilities and compliance gaps
• Compare system baselines to STIG checklists and document detailed findings and corrective actions
• Produce individual compliance reports for each software baseline reviewed (per CDRL A003)
• Provide expert guidance on remediation steps for non-compliant items
• Collaborate with stakeholders to ensure secure software development practices are embedded into project workflows Required Qualifications:
• Minimum 5 years of experience in secure software development and software security compliance
• Proficiency in Java and/or J2EE development
• Hands-on experience using Fortify and CodeSonar for static code analysis
• In-depth understanding of the DISA Application Security and Development STIG
• Familiarity with DoD cybersecurity documentation and compliance processes
• Active IAT Level II or IASAE Level II certification in accordance with DoDM 8140.03 and DAFMAN 17-1305
• Strong documentation skills with the ability to prepare compliance reports and technical analysis Preferred Skills:
• Experience working in a government or defense environment
• Knowledge of secure coding practices and SDLC methodologies
• Excellent communication and collaboration skills
Permanent