Назад
Company hidden
обновлено 4 часа назад

Director of Software Security (Cybersecurity)

164 500 - 305 500$
Тип работы
fulltime
Грейд
director
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Director of Software Security (Cybersecurity): Leading enterprise DevSecOps strategy, secure software architecture, and application security across the software lifecycle with an accent on cloud-native systems, regulatory compliance, and software supply chain integrity. Focus on integrating security into CI/CD pipelines, building AppSec programs, implementing CMMC and NIST controls, and guiding teams toward security ownership.

Location: San Jose, California, United States

Annual salary: $164,500–$305,500, plus potential bonus, equity, and benefits.

Company

hirify.global develops technology products and services and is expanding secure software development practices across its enterprise.

What you will do

  • Define and execute the enterprise DevSecOps strategy across development teams, integrating security controls into build, test, and release pipelines.
  • Establish secure reference architectures and security patterns for microservices, APIs, cloud-native applications, containers, Kubernetes, and serverless systems.
  • Lead CMMC, NIST, ISO 27001, CUI, audit, assessment, and continuous monitoring initiatives.
  • Build and scale the application security program, including vulnerability management, threat modeling, bug bounty, responsible disclosure, and security champions.
  • Secure cloud platforms, infrastructure-as-code, identities, access controls, secrets, software artifacts, dependencies, SBOMs, and provenance.
  • Lead AppSec engineers, DevSecOps engineers, and architects while partnering with Engineering, Product, Legal, and Compliance and reporting security posture to executive leadership and the board.

Requirements

  • 12–15+ years of cybersecurity experience, with a strong focus on application security and DevSecOps.
  • 5+ years of leadership experience at manager or director level.
  • Deep expertise in secure SDLC, DevSecOps pipelines, cloud-native architectures, container security, and CMMC, NIST, and ISO regulatory frameworks.
  • Experience in regulated industries such as defense, government, healthcare, or fintech.
  • Ability to define security policies, standards, development guidelines, KPIs, and risk-management alignment.

Nice to have

  • Experience with Checkmarx, Veracode, Burp Suite, Snyk, Black Duck, Jenkins, or GitHub Actions.
  • Familiarity with Kubernetes, Docker, service mesh security, Zero Trust, and identity-first security.
  • CISSP, CSSLP, CISM, or CCSP certification.

Culture & Benefits

  • Paid vacation and paid holidays.
  • 401(k) plan with employer match.
  • Employee stock purchase plan.
  • Medical, dental, and vision plan options.
  • Potential bonus and equity compensation.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →