Job Details
Job Description:
Position Summary
The AppSec / DevSecOps Engineer will help strengthen application and software supply chain security across a global semiconductor organization. This role will embed security into the software development lifecycle through secure design, application security assessments, automated security testing, CI/CD security controls, developer enablement, and continuous improvement.
The role will support enterprise applications and digital platforms used across business operations, application development, engineering enablement, supply chain, intellectual property, corporate functions, and customer-facing services.
The successful candidate will combine application security expertise with practical DevSecOps engineering, automation, risk-based assessment, and strong collaboration with development and technology teams.
The Team
The Application Security and DevSecOps team helps protect the company's software, engineering platforms, cloud services, intellectual property, and business applications by embedding security throughout the development lifecycle.
The team works across product, application development, IT, cloud, infrastructure, supply chain, corporate technology, and other business functions to improve secure development practices, automate security controls, and reduce application and software supply chain risk.
Responsibilities
Secure SDLC Controls
- Define and maintain secure software development lifecycle standards, procedures, control requirements, and developer guidance.
- Embed security requirements across planning, architecture, design, coding, testing, release, deployment, and operations.
- Develop security gates based on application risk, data sensitivity, business criticality, and deployment model.
- Support secure architecture reviews, threat modeling, security requirements definition, and go-live risk assessments.
- Establish secure coding standards for common programming languages, frameworks, APIs, cloud services, and development patterns.
- Track security findings, remediation commitments, exceptions, compensating controls, and risk acceptance decisions.
- Measure improvements in secure SDLC adoption, remediation timeliness, control coverage, and recurring vulnerability reduction.
DevSecOps Tooling, Standards, and Operations
- Implement and operate SAST, DAST, software composition analysis, secrets detection, container scanning, API security, and infrastructure-as-code scanning.
- Integrate security tooling into CI/CD pipelines using standardized patterns, APIs, plugins, connectors, and workflow automation.
- Configure security gates, severity thresholds, suppression processes, exception workflows, and escalation paths.
- Monitor tool health, scan coverage, pipeline failures, vulnerability backlogs, critical findings, and remediation performance.
- Tune security tooling to improve finding accuracy, reduce false positives, and minimize unnecessary development disruption.
- Establish processes for tool onboarding, configuration management, testing, upgrades, support, and retirement.
- Develop reusable integrations, scripts, dashboards, reference implementations, and automation assets.
- Support AI-assisted vulnerability triage, remediation recommendations, validation, and security workflow automation where appropriate.
Application Security Assessments
- Perform application security assessments across web applications, APIs, microservices, mobile applications, cloud services, developer platforms, and engineering systems.
- Conduct threat modeling, secure design reviews, architecture assessments, code reviews, vulnerability analysis, and penetration-test coordination.
- Assess enterprise and business-critical applications, including web applications, APIs, cloud services, developer platforms, source code repositories, product lifecycle systems, supply chain platforms, and intellectual property systems.
- Identify vulnerabilities, attack paths, insecure dependencies, authentication weaknesses, authorization issues, exposed secrets, and data protection risks.
- Translate findings into practical remediation plans with severity, business impact, recommended actions, owners, and due dates.
- Validate remediation through retesting, automated verification, evidence review, or compensating-control assessment.
- Maintain application security risk registers and report material risks, aging findings, exceptions, and residual exposure.
- Support security reviews for major application changes, cloud migrations, acquisitions, third-party platforms, and new technologies.
Cloud Secure Development Pipeline
- Support secure development and deployment practices across Microsoft Azure, AWS, and hybrid environments.
- Assess cloud-native services, containers, Kubernetes, serverless workloads, APIs, infrastructure-as-code, and CI/CD pipelines.
- Implement controls for open-source dependencies, software bills of materials, artifact integrity, code signing, build security, secrets protection, and software provenance.
- Pa