> Markdown version of [/jobs/ext/1399751-software-security-lead-principal-software](https://www.wearedevelopers.com/jobs/ext/1399751-software-security-lead-principal-software). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Security Lead - Principal Software... - **Company:** RTX - **Location:** Tucson, AZ, United States - **Experience:** Expert - **Salary:** $107,500.0 - $204,500.0 - **Contract:** Contract - **Skills:** Agile Methodology, Software Applications, ARM Architecture, Bug Tracking Systems, C++ (Programming Language), Linux, Linux on Embedded Systems, Perl (Programming Language), Embedded Software, Serial ATA, Field-Programmable Gate Array (FPGA), Python (Programming Language), Network Security, Object-Oriented Software Development, PCI Express, Scrum Methodology, Secure Coding, Software Configuration Management, VxWorks, Transport Layer Security, Software Security, Hardware Infrastructure, U-Boot, Devsecops, Programming Languages - **Published:** July 23, 2026 - **Apply:** https://www.juju.com/job/00000000gism2n ## About the Role Ability to obtain INTERIM U.S. government issued security clearance is required prior to start date, + Bachelors degree in Science, Technology, Engineering or Mathematics (STEM) and 8 years of related experience + Experience in object-oriented software design and embedded development using languages such as C and or C++ Experience with Xilinx UltaScale+ MPSoC, Versal, or similar Embedded Processors + Experience with embedded OS like VxWorks, Embedded Linux, or similar + Embedded Software Security and Cryptographic Algorithm experience + Experience with Secure Boot concepts + Understanding of secure coding principles, architecture and implementation of secure coding best practices + **The ability to obtain and maintain a US security clearance. U.S. citizenship is required as only U.S. citizens are eligible for a security clearance** Qualifications We Prefer: + Experience with validation and verification of software applications + Experience/Knowledge of any of the following: + Linux/Unix environment + Interfacing with FPGAs + Interfacing with low-level memory drivers + Inter-processor communication + ARM Architecture + Experience designing, implementing, testing, or fielding real-time security-oriented solutions on Department of Defense (DoD) programs (embedded experience highly preferred) + Experience using security-relevant tools and devices for security auditing, network security, host/server security, communication security, or policy management. + Experience in Agile and DevSecOps environments + Experience in an Agile/Scrum/Kanban frameworks and development environments + Experience using software configuration management and bug tracking tools + Experience with Python / Perl + Knowledge of modern computer architecture and hardware technologies including: + PCIe, GPIO, I2C, SATA + Field Programmable Gate Arrays (FPGAs) ## Description The Software Security Sensors and Effectors Department within the Software Product Assurance (SPA) Center is looking for a highly motivated individual to fill a Software Security Lead (SSL) position in Tucson, AZ. The SSL will work with Systems and Software Architects, and program stakeholders to ensure that software security is embedded in the program's processes and customer deliverables. The SSL will work with the relevant stakeholders to ensure the capture and development of any security relevant requirements. They must consider the architectural and design impacts to the solution while ensuring those requirements are met. The SSL must help the program adhere to secure coding practices and the Software Product Assurance Command Media by: + Act as the Technical Lead and possibly the Agile Product owner for the Software Security Team + Primary owner of the software security implementation to ensure compliance with System Security requirements + Adopt and implement secure coding standards for each programming language used + Drive off-nominal testing by ensuring the software will remain in a secure state during failure conditions and developing negative test cases for bypassing security + Consider using compiler, interpreter and build tool features that improve executable security and ensure the compiler does not optimize out any security-critical behaviors As part of the overall software security process, the SSL partnered with the Systems Security Lead, must provide the software assurance implementation for the Program Protection Implementation Plan (PPIP). This includes a software vulnerability risk assessment on reused code and the final delivery, and a Software Bill of Materials (SBOM) on the final delivery. The ideal candidate, working individually or as part of a team, will be responsible for applying secure coding principles to the design and development of hardened software applications. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Why Security-First Development Helps You Ship Better Software Faster](https://www.wearedevelopers.com/videos/1568-why-security-first-development-helps-you-ship-better-software-faster) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)