Senior Software Security Engineer / DevSecOps
GTN Technical Staffing · Dallas, TX
Apply & track with Apply EdgeSenior Security Software Engineer
Benefits
100% Company-Paid BenefitsOverviewOur client is seeking a hands-on Senior Security Software Engineer to build software, automation, and security capabilities that protect the platforms, infrastructure, and software delivery systems supporting a large-scale HPC and cloud environment.This role sits at the intersection of software engineering, platform security, vulnerability management, cloud security, and DevSecOps. The successful candidate will build internal security tooling, automate vulnerability detection and remediation, improve real-time security visibility, and work directly with engineering teams to embed security into how infrastructure and software are developed and operated.This is not a traditional SOC or governance role. It is designed for a strong engineer who can write production-quality code, integrate security platforms, and build scalable security solutions across complex cloud and infrastructure environments.Key ResponsibilitiesSecurity Software & AutomationDesign and build software and automation for vulnerability detection, remediation, reporting, and security posture management.Develop internal security tools, services, APIs, and integrations that improve security visibility and engineering accountability.Build event-driven and API-based integrations across vulnerability, endpoint, cloud, and platform security systems.Use Python, Go, Java, Bash, or similar languages to automate security workflows at scale.Improve reliability, scalability, and maintainability of security engineering platforms.Vulnerability Management & Platform SecurityBuild and mature vulnerability management capabilities across cloud, Linux, containers, Kubernetes, infrastructure, and software delivery environments.Identify, assess, prioritize, and drive remediation of vulnerabilities based on exploitability, asset criticality, and business impact.Develop scalable workflows for ownership, tracking, SLA management, and remediation.Perform security assessments, threat modeling, and attack-surface analysis.Partner with engineering teams to reduce recurring security issues and improve secure-by-default configurations.DevSecOps & Software Supply ChainIntegrate security controls into CI/CD pipelines and Infrastructure-as-Code workflows.Implement automated scanning, policy enforcement, and security validation during build and deployment.Support dependency scanning, container image security, artifact integrity, and software supply chain protections.Improve SSDLC practices without creating unnecessary friction for engineering teams.Support SBOM, signing, provenance, and related supply chain security initiatives.Cloud & Platform SecuritySecure environments across AWS, Azure, Kubernetes, Linux, and containerized infrastructure.Support runtime security, secrets management, identity, secure configuration, and platform hardening.Improve security visibility across distributed production environments.Partner closely with Platform Engineering, DevOps, and infrastructure teams on secure architecture.Detection, Incident Response & ReliabilityBuild and tune security monitoring and detection capabilities across platform environments.Investigate security-related production issues and support incident response, root-cause analysis, and remediation.Improve signal quality and reduce unnecessary alert noise.Build reporting around security SLAs, remediation timelines, and platform risk.Use postmortems and incident findings to drive long-term engineering improvements.Required Qualifications6+ years of experience in software engineering, security engineering, platform engineering, DevSecOps, application security, or related areas.Strong software development experience using Python, Go, Java, or similar languages.Experience building internal tools, services, APIs, automation, or distributed systems.Hands-on experience with vulnerability management and remediation at scale.Experience with tools such as Tenable, Qualys, Wiz, Prisma Cloud, CrowdStrike, Lacework, or similar platforms.Strong understanding of Linux, cloud infrastructure, containers, and modern platform environments.Experience with AWS and/or Azure.Familiarity with Kubernetes and containerized infrastructure.Experience integrating security controls into CI/CD pipelines and Infrastructure-as-Code workflows.Strong understanding of APIs, automation, and event-driven architectures.Understanding of CVSS, exploitability, vulnerability prioritization, and risk-based remediation.Strong troubleshooting, communication, and technical problem-solving skills.Preferred ExperienceBackground as a software engineer or backend engineer with meaningful security engineering experience.Experience building security platforms or automation used across large engineering organizations.Kubernetes security and runtime detection.Falco, eBPF-based security tooling, or similar technologies.Software supply chain security including SLSA, SBOMs, artifact signing, and Sigstore.Application and API security experience.Experience supporting FedRAMP, SOC 2, PCI, or similar compliance environments.Background in HPC, AI infrastructure, cloud platforms, or large-scale distributed systems.Experience working alongside incident response, detection engineering, threat intelligence, or SOC teams.Ideal CandidateThe ideal candidate is a software engineer first who has developed deep security expertise.This person should be comfortable writing production-quality code, building internal platforms and automation, integrating security tooling, and partnering directly with infrastructure and software engineering teams.The strongest candidates may come from backend engineering, platform engineering, security software engineering, DevSecOps, cloud security, or vulnerability engineering backgrounds, provided they have experience building security capabilities at scale.