> Markdown version of [/jobs/ext/3041268-staff-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/3041268-staff-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Application Security Engineer - **Company:** H. E. Butt Grocery Company - **Location:** San Antonio, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), Microsoft Windows, Application Programming Interfaces (APIs), Agile Methodology, Amazon Web Services, Application Frameworks, Application Firewall, Application Performance Management, Microsoft Azure, Cloud Computing, Configuration Management, Software Documentation, Cyber Security, Computer Programming, Continuous Delivery, Continuous Integration, Linux, Digital Electronics, Web Development, Web Servers, Systems Analysis, Internet Protocol, Internet Security, Python (Programming Language), Key Management, Unix Shell, Log Analysis, Windows Servers, Network Load Balancing, Network Virtualization, PCI Data Security Standards, Windows PowerShell, Systems Development Life Cycle, Ansible, Shell Script, Software Engineering, Systems Integration, Software Vulnerability Management, Web Applications, Web Platforms, Pulumi, Scripting, Google Cloud, Network Access Control, Load Balancing, Software Security, Firewalls (Computer Science), Cloudformation, Api Gateway, Terraform, Network Server, Software Version Control, Block Storage, Serverless Computing, Golang - **Published:** September 23, 2026 - **Apply:** https://www.careerbuilder.com/job-details/staff-app-sec-engineer-austin-dallas-or-san-antonio-tx-san-antonio-tx--0b090ec1-4a85-47d5-aec1-346dae45d254 ## About the Role * 10+ years of experience developing / supporting system and security solutions in medium to large size enterprises * Experience building / integrating systems in cloud and on-premises environments using enterprise source code management tools and automation tooling. * Advanced working understanding of web applications, web servers, application firewalls, frameworks, and protocols related to web application development, deployment, and operation in the cloud * Working understanding of log analysis, application performance monitoring, API security, container security, AWS cloud security, Agile and other project management methodologies, PCI DSS, HIPAA regulations * Advanced skills in AWS, Azure, or Google Cloud Platform; Terraform, CloudFormation, Pulumi, or Ansible; Python, Golang, PowerShell, Java, or Shell script * Advanced skills in Linux-based and Windows Server operating systems management, secrets management, and vaulting technologies * Advanced skills using APIs to optimize tasks / achieve automation * Advanced skills in cloud resources: virtual networking, access controls (security groups, ACLs), service endpoints, application / network load balancing, API gateways, service principals, functions / serverless, storage buckets, containers, block storage, file shares Education: * A Bachelor's degree or comparable formal training, certification, or work experience in Cyber Security or Application Security Engineering Licenses/Certifications: * One more professional security certifications e.g CISSP, CISA, CEH, GIAC, cloud certifications from AWS, Azure, GCP., Agile Programming Methodologies, Amazon Web Services (AWS), Analysis Skills, Ansible, Application Framework, Application Programming Interface (API), Applications Security, Automation, Best Practices, Cloud Computing, Coaching, Computer Security, Computer Servers, Consulting, Continuous Deployment/Delivery, Continuous Integration, Firewalls, Go Programming Language (Golang), HIPAA (Health Insurance Portability and Accountability Act), Internet Application, Internet Protocols, Internet Security, Java, Linux Operating System, Load Balancing, Machine Tool, Mentoring, Microsoft Windows Azure, Microsoft Windows Operating System, Microsoft Windows Server, Network Access Control (NAC), PCI-DSS, Performance Analysis, Physical Demands, Project/Program Management, Python Programming/Scripting Language, Regulations, Regulatory Compliance, Retail, Security Compliance, Security Infrastructure, Security Monitoring, Software Development Lifecycle (SDLC), Software Engineering, Source Code/Configuration Management (SCM), System Integration (SI), Systems Administration/Management, Systems Analysis, Technical/Engineering Design, Testing, Unix Shell Programming, User Documentation, Web Programming, Web Server, Windows PowerShell ## Description Job Summary: As a Staff Application Security Engineer, you'll consult and collaborate with internal business team Partners and external vendors to collect requirements, build, and test specifications, and implement documented innovative technical solutions of security requirements. You'll also coach and mentor., * Masters CI / CD pipelines; creates patterns of automation, infrastructure deployment, maintenance, monitoring, security, and compliance using industry and enterprise best practices * Collaborates with Digital Tech teams to design / develop / analyze / implement systems software and applications * Builds security standards for teams; integrates platform, including container and vulnerability management tools within CI / CD pipelines * Serves as SME for application security; provides guidance / coaches on industry best practices and defense in-depth strategies for security posture of cloud-based digital platforms * Collaborates with project teams on testing / evaluation of new solutions; tests cloud configurations and infrastructure for vulnerabilities * Ensures cloud infrastructure complies with security and compliance control requirements * Designs, develops, documents, automates, implements security infrastructure in code * Ensures concise documentation to formalize security processes and guardrails * Guides development teams to apply secure automation patterns / encourage secure software development lifecycle (SSDLC) best practices * Coaches / mentors team Partners The responsibilities and essential functions outlined above describe the general nature and level of work assigned to this position. This is not an exhaustive list of all duties, responsibilities, and skills required. Duties and responsibilities may be modified at any time based on business needs. Employees may be required to perform other job-related tasks as requested by their supervisor, subject to reasonable accommodations. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Why segmenting your infrastructure into tiers makes your infrastructure design better](https://www.wearedevelopers.com/videos/1960-why-segmenting-your-infrastructure-into-tiers-makes-your-infrastructure-design-better) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Unleashing Potential Across Teams: The Power of Infrastructure as Code](https://www.wearedevelopers.com/videos/930-unleashing-potential-across-teams-the-power-of-infrastructure-as-code) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)