> Markdown version of [/jobs/ext/2219813-security-engineer](https://www.wearedevelopers.com/jobs/ext/2219813-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** CareerCircle - **Location:** San Antonio, TX, United States (Remote available) - **Experience:** Expert - **Salary:** $131,300.0 - $237,350.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Software System Penetration Testing, Cloud Computing, Cloud Engineering, Cyber Security, Continuous Integration, Linux, Identity and Access Management, Integrated Development Environments, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Python (Programming Language), Key Management, Network Layer, Network Protocols, Release Management, Ansible, Red Team (Cyber Security), Reverse Engineering, Secure Coding, Security Information and Event Management, Software Deployment, Software Engineering, Software Vulnerability Management, Scripting, Computer Network Operations, Large Language Models, Infrastructure as Code (IaC), Gitlab, Containerization, Gitlab-ci, Kubernetes, Production Code, Terraform, Api Management, Docker, Jenkins, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 25, 2026 - **Apply:** https://www.careercircle.com/jobs/all/all/usa/tx/san-antonio/9a364a82-20ec-4656-809f-db3242603e0c ## About the Role * 8+ years of professional experience in security engineering, secure software development, or infrastructure security. * Experience securing and using agentic tooling for writing and maintaining production code, managing cloud infrastructure, and release management frameworks. * Experience owning security outcomes for a technical product from ideation to production, and influencing engineering teams toward secure design without direct authority. * Experience hardening software deployments, networks, and production infrastructure at scale. * Experience securing software clusters for online/cloud as well as on-prem or air-gapped installations. * Experience with threat modeling, vulnerability management, and secure development practices across first- and third-party code. * Familiarity with NIST RMF, continuous ATO, and control automation., * 15+ years Hands-on experience securing and hardening Linux systems at the OS and network layer * Expertise in at least one scripting language (Python preferred) * Working knowledge of network protocols, cryptographic fundamentals, and key management * Experience with infrastructure-as-code and containerization (Ansible/Terraform, Docker/Kubernetes) * Experience administering or securing a CI/CD system (GitLab CI, Jenkins, or similar), * Experience working in accredited/classified environments, including cross-domain solutions * Offensive security background - penetration testing, red team, or serious CTF experience * Detection engineering or SIEM experience * Experience with embedded, real-time, or otherwise constrained platforms * Exposure to reverse engineering or vulnerability research * Relevant certifications (CISSP, OSCP, GCIH) - useful, not required * Non-human/agent identity and secrets management - short-lived credentials, scoping, and audit for autonomous actors, which is a genuinely different problem than human IAM. * Sandboxing and egress control for code-executing agents. * Familiarity with NIST AI RMF and the fact that continuous-ATO control automation now has to cover AI system controls, not just traditional ones. * Using LLMs to accelerate the compliance grind control narrative drafting, evidence collection, POA&M triage. ## Description CI/CD Gitlab Writing Ansible Tooling On Prem Jenkins Auditing Research Ideation Equities Scripting Terraform Hardening Pipelines Operations Management Automation Kubernetes Market Data AI Security Supply Chain Cryptography Law Enforcement Threat Modeling Production Code Ancient History Containerization Threat Detection Operating Systems Docker (Software) Network Protocols Release Management Workflow Management Penetration Testing Evidence Collection GIAC Certifications Security Engineering Software Engineering Software Development Cloud Infrastructure Artificial Intelligence Development Environment Infrastructure Security Research And Development Internet Of Things (IoT) Vulnerability Management Computer Network Operations Infrastructure as Code (IaC) Python (Programming Language) GIAC Certified Incident Handler Plan Of Action And Milestones (POA&M) Application Programming Interface (API) Offensive Security Certified Professional Security Information And Event Management (SIEM) Certified Information Systems Security Professional, We are looking for a Security Engineer to own the security posture of the environments where we build, test, and deliver advanced AI-cyber capabilities. You will be embedded with software engineers, reverse engineers, and vulnerability researchers, hardening the infrastructure, supply chains and pipelines on while guiding their secure development. The work includes guiding and reviewing build integrity and supply chain review to threat modeling our own tooling. If you have ever looked at a supply chain & development environment and immediately started listing the ways you would secure it, this is the job. You will be the person the team trusts to tell them when something is a real risk and when it is just noise As an AI Security Integration Engineer on our team, you will bridge the gap between traditional security infrastructure and modern programmatic defense. You will guide the secure development and evolution of software vulnerability tooling. Your primary focus will be working with the development team to maintainmaintaining the tool security posture utilizing continuous ATO. review workflows and pipelines by leveraging Python, assessing robust API integrations, maintained exploring AI/LLM orchestration to rapidly scale threat detection and response capabilities. Support ATO and continuous vuln management., CI/CD Gitlab Writing Ansible Tooling On Prem Jenkins Auditing Research Ideation Equities Scripting Terraform Hardening Pipelines Operations Management Automation Kubernetes Market Data AI Security Supply Chain Cryptography Law Enforcement Threat Modeling Production Code Ancient History Containerization Threat Detection Operating Systems Docker (Software) Network Protocols Release Management Workflow Management Penetration Testing Evidence Collection GIAC Certifications Security Engineering Software Engineering Software Development Cloud Infrastructure Artificial Intelligence Development Environment Infrastructure Security Research And Development Internet Of Things (IoT) Vulnerability Management Computer Network Operations Infrastructure as Code (IaC) Python (Programming Language) GIAC Certified Incident Handler Plan Of Action And Milestones (POA&M) Application Programming Interface (API) Offensive Security Certified Professional Security Information And Event Management (SIEM) Certified Information Systems Security Professional +0 ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)