обновлено 4 часа назад
Director of Software Security (Cybersecurity)
164 500 - 305 500$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Director of Software Security (Cybersecurity): Leading enterprise DevSecOps strategy, secure software architecture, and application security across the software lifecycle with an accent on cloud-native systems, regulatory compliance, and software supply chain integrity. Focus on integrating security into CI/CD pipelines, building AppSec programs, implementing CMMC and NIST controls, and guiding teams toward security ownership.
Location: San Jose, California, United States
Annual salary: $164,500–$305,500, plus potential bonus, equity, and benefits.
Company
develops technology products and services and is expanding secure software development practices across its enterprise.
What you will do
- Define and execute the enterprise DevSecOps strategy across development teams, integrating security controls into build, test, and release pipelines.
- Establish secure reference architectures and security patterns for microservices, APIs, cloud-native applications, containers, Kubernetes, and serverless systems.
- Lead CMMC, NIST, ISO 27001, CUI, audit, assessment, and continuous monitoring initiatives.
- Build and scale the application security program, including vulnerability management, threat modeling, bug bounty, responsible disclosure, and security champions.
- Secure cloud platforms, infrastructure-as-code, identities, access controls, secrets, software artifacts, dependencies, SBOMs, and provenance.
- Lead AppSec engineers, DevSecOps engineers, and architects while partnering with Engineering, Product, Legal, and Compliance and reporting security posture to executive leadership and the board.
Requirements
- 12–15+ years of cybersecurity experience, with a strong focus on application security and DevSecOps.
- 5+ years of leadership experience at manager or director level.
- Deep expertise in secure SDLC, DevSecOps pipelines, cloud-native architectures, container security, and CMMC, NIST, and ISO regulatory frameworks.
- Experience in regulated industries such as defense, government, healthcare, or fintech.
- Ability to define security policies, standards, development guidelines, KPIs, and risk-management alignment.
Nice to have
- Experience with Checkmarx, Veracode, Burp Suite, Snyk, Black Duck, Jenkins, or GitHub Actions.
- Familiarity with Kubernetes, Docker, service mesh security, Zero Trust, and identity-first security.
- CISSP, CSSLP, CISM, or CCSP certification.
Culture & Benefits
- Paid vacation and paid holidays.
- 401(k) plan with employer match.
- Employee stock purchase plan.
- Medical, dental, and vision plan options.
- Potential bonus and equity compensation.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 часов назад
Application Security Engineer (Cybersecurity)
86 900 - 198 000$
2 дня назад
Director of Product Security (Cybersecurity)
243 699 - 271 644$
5 дней назад
Sr Director, Cyber Security Operations / Deputy CISO (Cybersecurity)
204 400 - 306 550$
4 часа назад
Director, Application & AI Security (AI)
18 часов назад
Director, Field Security (Cybersecurity)
224 000 - 280 000$
2 дня назад
Senior Application Security Engineer (Cybersecurity)
109 500 - 208 500$