Application Compliance & Security Lead
Johns Hopkins APL · Laurel, MD · Cybersecurity
About this role
Johns Hopkins APL is hiring a senior-level Application Security Engineer based in Laurel, MD. The posting calls out experience with Python, Java, AWS, GCP.
- Role
- Application Security Engineer
- Function
- security
- Level
- senior
- Track
- Individual contributor
- Location
- Laurel, MD
- Department
- Cybersecurity
- Posted
- May 11, 2026
More roles at Johns Hopkins APL
Job description
from Johns Hopkins APL careersAre you an authority in application security and compliance requirements, with experience in software development and tooling like SAST, DAST, and vulnerability analysis?
Do you thrive in an innovative environment where you can translate complex compliance requirements into practical guidance that empowers development teams?
If so, we’d love to have someone like you join our team at APL!
We are seeking an Application Security Leader to help us ensure our applications meet industry security standards while enabling our developers to work efficiently. You’ll be joining our enterprise applications team as the primary authority on application security and CMMC compliance, working at the intersection of compliance requirements, development practices, and security tooling. Our team builds and supports critically important applications across the laboratory, and you’ll play a key role in building a security-minded and developer-friendly culture. You’ll work with dedicated developers, information protection specialists, and compliance experts who are passionate about protecting sensitive information while delivering innovative solutions.
As an Application Compliance & Security Lead…
Foremost, you will be driving CMMC compliance strategy across our application portfolio, translating sophisticated requirements into actionable security controls that development teams can understand and implement.
- You’ll serve as the go-to resource for application teams on security and compliance matters, providing practical guidance on secure development practices and helping teams navigate CMMC, NIST 800-171, SSDF, and DFARS requirements.