> Markdown version of [/jobs/ext/3028803-principal-software-engineer](https://www.wearedevelopers.com/jobs/ext/3028803-principal-software-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Software Engineer - **Company:** American Bureau of Shipping - **Location:** Houston, TX, United States - **Experience:** Expert - **Salary:** $94,800.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), .NET Framework, Application Programming Interfaces (APIs), Artificial Intelligence, Audit Trail, Automation of Tests, Unit Testing, Microsoft Azure, C Sharp (Programming Language), Cloud Computing, Software Quality, Continuous Integration, Cursor (Graphical User Interface Elements), DevOps, Distributed Systems, Python (Programming Language), Node.Js, Systems Development Life Cycle, Prometheus, Software Engineering, Strategies of Testing, Web Application Frameworks, Policy as Code, Data Logging, Data Processing, Enterprise Software Applications, Cloud Monitoring, GitHub Copilot, ReactJS, Delivery Pipeline, Grafana, Backend, Git, Vue.js, Data Layers, Event Driven Architecture, Build Management, AngularJS, Kubernetes, Information Technology, Playwright, Production Code, Terraform, Static Application Security Testing, Golang, Dynamic Application Security Testing - **Published:** September 22, 2026 - **Apply:** https://www.jofdav.com/jobs/59820692-principal-software-engineer ## About the Role * 10+ years of professional software engineering experience, including 3+ years at Staff or Principal level * Bachelor's degree in computer science (MS is preferred), Engineering, or a related field * Delivery experience in regulated or compliance-bound environments (CMMC, FedRAMP, SOC 2, ISO 27001) * Azure or Azure Government Cloud * Legacy modernization - decomposing monolithic enterprise applications into services * Hands-on delivery under CMMC, FedRAMP, SOC 2, or ISO 27001 control frameworks, including evidence and audit preparation * Supply chain security: SBOM generation, artifact signing, and provenance attestation (SLSA or equivalent) * Policy-as-code enforcement (OPA, Conftest, or equivalent) in delivery pipelines * Observability instrumentation (OpenTelemetry, Prometheus, Grafana, Azure Monitor) * Distributed systems and event-driven architecture * Database engineering depth across relational and non-relational stores Knowledge Skills and Abilities * Expert proficiency in a modern backend language (C#/.NET, Java, Python, Go, or Node.js) and a modern front-end framework (React, Angular, or Vue) * Demonstrated ownership of services in production - you have been the person accountable when your code failed at 2am * Automated testing depth: unit, integration, and end-to-end, with hands-on Playwright experience and a track record of enforcing coverage standards rather than aspiring to them * Working fluency with containerized deployment on Kubernetes and with infrastructure defined as code * Comfort operating in a Git-based delivery workflow where changes reach production through automated pipelines * Demonstrated production delivery using agentic coding tools (Claude Code, Cursor, GitHub Copilot Workspace, or equivalent), including sound judgment about where agent-generated code requires human architectural intervention * Ability to define review and verification standards for AI-generated code, using automated test coverage as the enforcement mechanism rather than manual inspection, including provenance and review attestation sufficient to satisfy audit requirements at agent-generated volume * Secure SDLC practice as a daily discipline: SAST/DAST, dependency and container scanning, secret detection, and remediation of findings at the source * Experience building services that produce audit-grade logging and automated compliance evidence rather than reconstructing it after the fact * Ability to explain technical tradeoffs clearly to non-technical stakeholders, Work is primarily sedentary; exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull, or otherwise move objects. ## Description You will write production code, design the systems it belongs to, and stay accountable for how it behaves after release. Most engineering roles stop at "feature complete." This one does not. You will define what a service looks like, build it, prove it works through automated testing, ship it through our delivery pipeline, and own its behaviour in production. You will set the technical standard for application engineering across the organization, architecture, code quality, and test discipline - and you will do it by building, not by reviewing from a distance. This is an AI-augmented role. We expect coding agents to be part of how you work daily, and we expect you to define what responsible, verifiable use of them looks like here. What You Will Do: * Ideation through design. Turn ambiguous business problems into technical direction. Produce architecture and interface designs that other engineers can build against. Make and defend technology selection and build-vs-buy decisions. * Full stack implementation. Design and build front end applications and the services, APIs, and data layers behind them. Write production code at a standard that raises the bar for the engineers around you. * Test strategy and coverage. Own the automated testing approach for your systems. Enforce unit test coverage as a merge gate. Build integration test suites against real service contracts. Author and maintain functional and end-to-end browser tests in Playwright, and keep them fast and non-flaky enough that teams trust them. * Delivery to production. Package your services as containers. Author the deployment configuration for your workloads and promote changes through the GitOps pipeline. You are expected to be fluent in the platform - reading and modifying the Terraform and Kubernetes manifests that describe your service - while our Platform/DevOps team owns the platform itself. * AI-augmented delivery. You use coding agents as a core part of how you work - decomposing problems into agent-executable units, directing multi-step implementation, and reviewing generated output with the same rigor you would apply to a strong junior engineer's pull request. You are expected to deliver scope that would conventionally require a larger team, and to establish the guardrails, review standards, and verification practices that let other engineers do the same safely. * Security and compliance as code. Security is a build gate, not a review meeting. You write code that clears automated SAST, DAST, dependency, secret, and container scanning on every commit, and you remediate findings at the source rather than deferring them to a backlog. You design services so that authentication, authorization, encryption, and data handling meet control requirements by construction. * Auditability and evidence generation. You instrument services to emit structured, tamper-evident audit logs covering access, privileged action, and data handling - sufficient to satisfy an auditor without manual reconstruction. Compliance evidence is produced automatically as a byproduct of the pipeline: test results, scan results, approvals, and deployment records are captured as artifacts at build time. You are expected to treat "we can prove it" as part of the definition of done. * You will work in a CMMC Level 2 environment. Familiarity with what that means for code provenance, change control, and access logging is a meaningful advantage. * Production accountability. Instrument what you build. Define the signals that indicate your service is healthy, participate in incident response for your systems, and drive permanent remediation rather than repeat mitigation. * Technical leadership. Mentor senior and mid-level engineers. Lead design reviews. Influence engineering direction across teams without formal authority. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Lessons learned from building a thriving Vue.js SaaS application](https://www.wearedevelopers.com/videos/1666-lessons-learned-from-building-a-thriving-vue-js-saas-application) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Navigating the Corporate Jungle: Life as a Developer in a large Company](https://www.wearedevelopers.com/videos/621-navigating-the-corporate-jungle-life-as-a-developer-in-a-large-company) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [What is Software Engineering in the Age of AI?](https://www.wearedevelopers.com/magazine/640-what-is-software-engineering-in-the-age-of-ai) - [What is Agentic Programming and Why Should Developers Care?](https://www.wearedevelopers.com/magazine/625-what-is-agentic-programming-and-why-should-developers-care) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Is Software Engineering Hard?](https://www.wearedevelopers.com/magazine/448-is-software-engineering-hard)