> Markdown version of [/jobs/ext/160716-software-security-analyst](https://www.wearedevelopers.com/jobs/ext/160716-software-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Security Analyst - **Company:** TrellisWare Technologies, Inc - **Location:** San Diego, CA, United States - **Experience:** Experienced - **Salary:** $115,000.0 - $185,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Software System Penetration Testing, C++ (Programming Language), CompTIA Security+, Cyber Security, Distributed Revision Control, Embedded Software, Federal Information Processing Standards (FIPS), Github, Python (Programming Language), Key Management, Network Protocols, Open Web Application Security, Program Analysis, Reverse Engineering, Secure Coding, Software Engineering, Tripwire, Software Security, Information Technology, Tenable Nessus, Nessus, CIS Benchmarks, Qualys, Vulnerability Analysis - **Published:** May 31, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=9c2440a1ae84771c ## About the Role Do you have experience in Vuls?, Do you have a Bachelor's degree?, * Bachelor's degree in Computer Science, Cybersecurity, or Information Technology or related field of study required. * Minimum of 5 years' industry experience with at least three years in software development and at least two years in auditing and vulnerability testing. * Proficiency with Python, C/C++ and an understanding of operating systems, and network protocols. * Experience performing penetration testing (ethical hacking) and security scans. * At least one certification: CompTIA Security+, CISSP, OSCP, or SANS/GIAC. To be considered for this position, you would need to meet, at a minimum, the knowledge, skills, and abilities listed here: * Experience with the full software development life cycle, including system design, threat modeling, and secure code implementation. * Familiarity with encryption devices and secure key management required. * Familiarity with embedded software defined tactical radio security required. * Experience with threat modeling, secure coding practices, and identification of software vulnerabilities. * Experience with cybersecurity scanning tools; Nessus, Qualys VMDR, Trivy, or Rapid7. * Experience with NIST, ISO 27001, CIS Controls or OWASP. * C++, Python, or Java. * Distributed revision control systems (GitHub). * You can think on your feet - you are analytical, pay attention to detail and are able to communicate your thought process both written and verbally. * You are able, and enjoy working independently as well as in a team environment. * Strong collaborative drive and interpersonal skills. * Strong initiative, proactive work ethic and prioritization skills. * Trustable judgement and analytical problem-solving skills. * Effective execution and decision making. * Champion of change and promotes innovation. * Strong written and verbal communication skills. The physical demands described here represent those that must be met in order to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable those with qualified disabilities. * Able to frequently sit, stand, walk, use hands to fingers, handle or feel, reach within hands and arm's length, stoop, kneel, and crouch, talk and hear. * Regularly required to sit for extended periods of time; frequently required to use office equipment such as PC, printer, telephone, etc. * Able to regularly lift and/or move up to 10 pounds, frequently lift and/or move up to 25 pounds, and occasionally lift and/or move up to 50 pounds. * Specific vision abilities required by this job include close vision, distance vision, color vision, peripheral vision, depth perception, and ability to adjust focus. Additional requirements are: * U.S. Citizenship. ## Description * Conduct software product security assessments and vulnerability testing. + Regular scanning and penetration testing. + Threat analysis. + Static and dynamic analysis and security testing. + Maintain currency of evolving security threats, technologies, and regulatory changes. * Analyze and review functional system design specifications, and ensure security policy compliance. + Participate in software system architectural and component design reviews . + Reverse engineer software components for hidden bugs or malicious code. * Evaluate and ensure secure COMSEC key and certificate distribution, authentication, and assignment. * Investigate security related incidents. + Determine root cause and verify mitigation updates. * Document and present product security compliance using standard professional practices and corporate defined engineering processes. + FIPS 140 compliance. + NIST STIG compliance. * Develop relationships with team members built on trust and respect. ## Related Videos - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)