AppSec Jobs
← Back to all jobs

Scientific Research Corporation

DevSecOps Engineer

North Charleston, South Carolina, United StatesWebsite

Full details on LinkedIn

The complete job description, requirements, and application details are available on the original posting.


About Scientific Research Corporation

Scientific Research Corporation (SRC), founded in 1988 and based in Atlanta, Georgia, is an engineering company that specializes in technology solutions for the U.S. Government, private industry, and international markets. SRC offers a wide range of high-quality products and technical services in areas such as information, communications, intelligence, electronic warfare, simulation, training, and instrumentation systems. The company's core capabilities include full lifecycle engineering services, cybersecurity operations, and the development of simulation and training systems. SRC supports military and federal customers with system integration, testing, and installation, particularly in command, control, communications, computers, and intelligence (C4I) systems. With a team of skilled engineers and scientists, SRC operates advanced laboratories and test facilities to ensure comprehensive support throughout program lifecycles. With over 2,600 employees and annual revenues exceeding $450 million, SRC serves a diverse customer base, including the U.S. Department of Defense and various federal agencies. The company is committed to delivering innovative solutions that meet the evolving needs of its clients in complex technological environments.

Industry

information technology & services

Employees

2,700

535 engineers

Revenue

$284M

Website

Visit →

Security at Scientific Research Corporation

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

  • Scientific Research Corporation's overall cyber mission and focus emphasize broad cyber programs and capabilities, including vulnerability assessments and information assurance.
  • Public materials reference "DevSecOps"environments in job postings, indicating an integration of security into engineering workflows, but no explicit phrasing describing a "developer-first"or "gatekeeping"approach was found.
  • There is no explicit public statement referencing an AppSec "risk-based approach"or specific mention of "threat modeling"on public-facing pages.
  • Similarly, no public blog posts, talks, or leader interviews with verbatim statements about AppSec pain points or goals were found.

Security Team

  • No public page describing the AppSec reporting chain (e.g., to CISO or CTO) or a centralized vs. embedded AppSec model was found.
  • Similarly, no public-facing leaders for AppSec were identified through SRC's public leadership bios or interviews, though LinkedIn searches revealed multiple cyber/security practitioners.
  • No public headcount or AppSec team size is disclosed.
  • Active job postings reference DevSecOps and Cyber Security roles, with multiple such postings found across various platforms, but no exact AppSec-specific postings were identified.
  • Common skill and tool patterns from job posts include DevSecOps processes and automation pipelines, container security and registries, Infrastructure as Code (IaC), and tools like HBSS, ACAS/Nessus, and SPLUNK.

Key Initiatives

No public evidence of a Security Champions program was found. Regarding "Shift Left"practices, job descriptions mention a "DevSecOps based environment"and responsibilities for secure container hosting, IaC/Configuration as Code, and automation pipelines, but specific public documentation of pre-commit hooks, IDE integrations, or CI/CD pipeline rules was not found. For Vulnerability Management, public job postings and cyber pages refer to vulnerability assessments and tools like ACAS/Nessus, continuous monitoring, and POA&Ms/SSPs, but no public SLAs, MTTR targets, or explicit ticketing process descriptions were available. Secure SDLC Artifacts mentioned in job postings include assessment and authorization documentation, continuous monitoring, STIGs, and system security plan artifacts, but no public statements about "security reviews for all major features"or mandatory threat modeling cadence were found. SRC's public site highlights recent program wins and cyber capabilities, but no AppSec-specific new programs, tool rollouts, or policy changes from the last six months are publicly available.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.