> Markdown version of [/jobs/ext/2037770-software-security-engineer](https://www.wearedevelopers.com/jobs/ext/2037770-software-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Security Engineer - **Company:** Booz Allen Hamilton Inc. - **Location:** San Antonio, TX, United States - **Salary:** $55,200.0 - $126,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Agile Methodology, Artificial Intelligence, Applications Architecture, User Authentication, Cloud Computing Security, Cloud Engineering, Cyber Security, Information Systems, Scrum Methodology, Software Architecture, Software Engineering, Software Vulnerability Management, Delivery Pipeline, Software Security, Mitre Att&ck, Git, SC Clearance, Kubernetes, Information Technology, Software Version Control, Devsecops, Serverless Computing, Static Application Security Testing, Programming Languages, Microservices, Dynamic Application Security Testing - **Published:** August 12, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88010717/1 ## About the Role * Experience effectively managing multiple priorities * Ability to use a programming language to solve problems without the use of AI * Ability to break down problems into manageable pieces and iterate on a problem solving process * Ability to obtain a Secret clearance * Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or Engineering Nice If You Have: * Experience utilizing application security tools such as SAST, DAST, SCA, IaC scanning, container security, API security, secrets detection, and software composition analysis * Experience with Git distributed version control * Experience with Agile, Scrum, and DevSecOps operating models * Experience in cybersecurity, application security, cloud security, cloud engineering, or software engineering * Knowledge of software supply chain security concepts, including SBOMs, dependency management, code signing, artifact integrity, and secure build pipelines * Knowledge of secure software development principles, modern application architectures, and modern software architectures, including cloud-native, microservices, APIs, containers, Kubernetes, and serverless environments * Knowledge of authentication, authorization, cryptography, API security, and cloud security * Knowledge of vulnerability management processes, risk prioritization methodologies, and remediation workflows * Knowledge of industry frameworks such as NIST SSDF, NIST AI RMF, and MITRE ATT&CK * Ability to quickly learn new skills independently to solve a complex problem ## Description Integrates security practices throughout the software development lifecycle to enhance and maintain the security posture of software. Applies basic principles, theories, and concepts, and limited industry knowledge. Solves routine problems of limited scope and complexity and refers more complex issues to higher levels. Works under direct supervision. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)