Job Description
What you’ll do:
- Establish, maintain, and continuously improve company-wide secure SDLC policies, standards, control objectives, procedures, and supporting evidence requirements.
- Translate security policy into clear, achievable requirements for development, product, and platform teams without creating unnecessary delivery friction.
- Assess the maturity of development teams, CI/CD pipelines, source-control practices, build environments, and release processes; define and lead practical improvement roadmaps.
- Develop secure-development guidance, reference architectures, reusable patterns, security guardrails, exception processes, and developer enablement materials.
- Partner directly with development teams to identify, triage, prioritize, remediate, and verify application-security findings.
- Evaluate, implement, tune, and operationalize application-security tooling, including:
- Static application security testing (SAST)
- Dynamic application security testing (DAST)
- Software composition analysis (SCA)
- Secrets detection
- Infrastructure-as-code security scanning
- Container and image security scanning
- API and cloud-native application security controls
- Ensure security tooling produces actionable, appropriately prioritized findings and does not create unnecessary developer burden through excessive false positives.
- Lead or facilitate threat modeling, security requirements definition, and secure design or architecture reviews for high-risk applications, integrations, and material changes.
- Establish risk-based vulnerability management processes, including severity criteria, remediation service-level objectives, compensating controls, formal risk acceptance, escalation, and exception management.
- Develop and maintain processes for identifying, tracking, and remediating vulnerable third-party, open-source, and transitive dependencies.
- Establish open-source software governance, including component inventory, license identification, license review, approval workflows, and policy enforcement.
- Mature software supply-chain security practices, including:
- Machine-readable software bills of materials (SBOMs)
- Vulnerability Exploitability eXchange (VEX) or equivalent vulnerability-status communications
- Build and release provenance
- Artifact, package, container-image, and binary signing
- Artifact verification and trusted promotion processes
- Secure artifact repositories and package registries
- Approved dependency sources and package integrity verification
- SLSA-aligned build integrity, provenance, and release controls
- Partner with DevOps and platform engineering to secure CI/CD pipelines, including least-privilege access, protected branches, secure secret handling, hardened build environments, and release approvals.
- Establish requirements for secure source-code repositories, build systems, dependency registries, artifact repositories, and deployment pipelines.
- Support application vulnerability intake, coordinated disclosure, customer-facing security advisories, CVE triage where applicable, and product-security incident response.
- Create and lead a security champions program that provides developers with secure-coding guidance, training, office hours, practical tools, and a pathway for timely security engagement.
- Develop executive-ready metrics and reporting on secure-SDLC adoption, AppSec risk, remediation performance, control coverage, software supply-chain integrity, and program maturity.
- Support customer, regulatory, audit, and assurance activities related to secure-development and software supply-chain practices.
NIST’s Secure Software Development Framework (SSDF), documented in NIST SP 800-218, provides a practical foundation for secure-development practices across organizational preparation, software protection, secure production, and vulnerability response.
Required qualifications:
- 7+ years of experience in application security, product security, DevSecOps, secure software engineering, cybersecurity engineering, or a closely related field.
- Demonstrated experience designing, implementing, or maturing a secure SDLC or application-security program across multiple engineering teams.
- Strong working knowledge of secure coding practices, application-security testing, vulnerability management, software delivery, and DevSecOps principles.
- Experience working directly with developers to explain findings, guide remediation, and improve secure-development practices.
- Hands-on experience with SAST, DAST, SCA, dependency vulnerability management, secrets scanning, and related application-security tooling.
- Experience integrating security controls into source-control, CI/CD, build, release, and deployment workflows.
- Experience performing or facilitating threat modeling, security design review, architecture review, or security requirements definition.
- Knowledge of common application-security risks, including authentication, authorization, API security, insecure deserialization, injection vulnerabilities, insecure dependency use, secrets exposure, and business-logic vulnerabilities.
- Experience with software supply-chain security concepts, including SBOMs, dependency provenance, build integrity, artifact signing, release attestations, and secure artifact management.
- Experience with open-source software risk management, including vulnerable dependencies, transitive dependencies, license obligations, and governance processes.
- Familiarity with NIST SP 800-218 / SSDF, OWASP SAMM, SLSA, or comparable secure-development and supply-chain security frameworks.
- Ability to read and assess production code and scripts in one or more modern programming languages.
- Strong written and verbal communication skills, including the ability to explain technical risk and tradeoffs to developers, leaders, auditors, and nontechnical stakeholders.
Preferred qualifications:
- Experience implementing SLSA practices, signed software attestations, build provenance, hardened build systems, or release integrity controls.
- Experience with VEX, CSAF, SBOM formats such as SPDX or CycloneDX, and component or vulnerability intelligence workflows.
- Experience securing cloud-native applications, containers, Kubernetes, APIs, microservices, and infrastructure-as-code.
- Experience with common source-control, CI/CD, cloud, artifact-management, package-management, or container-registry platforms.
- Experience with tools such as Snyk, Checkmarx, Veracode, GitHub Advanced Security, GitLab security tools, Semgrep, SonarQube, OWASP ZAP, Burp Suite, Mend, Black Duck, or comparable technologies.
- Experience with NIST SP 800-171, NIST SP 800-53, CMMC, FedRAMP, ISO 27001, SOC 2, or other regulated-environment requirements.
- Experience supporting commercial software, government, defense, critical-infrastructure, or other high-assurance product environments.
- Relevant certifications such as CSSLP, CISSP, GWAPT, GWEB, OSWE, GIAC, cloud-security certifications, or comparable credentials.