DevSecOps and AI/Automation Engineer

Altera

San Jose (CA)

On-site

USD 130,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Altera is seeking an AppSec / DevSecOps Engineer to strengthen application and software supply chain security across a global organization. This role will embed security into the software development lifecycle through secure design, assessments, automated security testing, CI/CD security controls, developer enablement, and continuous improvement.

The team protects software, engineering platforms, cloud services, and intellectual property by embedding security throughout the development lifecycle

Qualifications

  • Responsibilities include defining secure SDLC standards, embedding security across planning, architecture, design, coding, testing, release, deployment and operations.
  • Develop security gates based on risk, data sensitivity, business criticality, and deployment model.
  • Implement and operate SAST, DAST, software composition analysis, secrets detection, container scanning, API security, and IaC scanning.

Responsibilities

  • Define and maintain secure software development lifecycle standards and guidance.
  • Embed security requirements across planning, architecture, design, coding, testing, release and deployment.
  • Develop security gates based on risk, data sensitivity and deployment model.
  • Support secure architecture reviews, threat modeling, and live risk assessments.
  • Establish secure coding standards for languages, frameworks, APIs, cloud services.

Job description

Job Details

Job Description:

Position Summary

The AppSec / DevSecOps Engineer will help strengthen application and software supply chain security across a global semiconductor organization. This role will embed security into the software development lifecycle through secure design, application security assessments, automated security testing, CI/CD security controls, developer enablement, and continuous improvement.

The role will support enterprise applications and digital platforms used across business operations, application development, engineering enablement, supply chain, intellectual property, corporate functions, and customer-facing services.

The successful candidate will combine application security expertise with practical DevSecOps engineering, automation, risk-based assessment, and strong collaboration with development and technology teams.

The Team

The Application Security and DevSecOps team helps protect the company's software, engineering platforms, cloud services, intellectual property, and business applications by embedding security throughout the development lifecycle.

The team works across product, application development, IT, cloud, infrastructure, supply chain, corporate technology, and other business functions to improve secure development practices, automate security controls, and reduce application and software supply chain risk.

Responsibilities
Secure SDLC Controls
  • Define and maintain secure software development lifecycle standards, procedures, control requirements, and developer guidance.
  • Embed security requirements across planning, architecture, design, coding, testing, release, deployment, and operations.
  • Develop security gates based on application risk, data sensitivity, business criticality, and deployment model.
  • Support secure architecture reviews, threat modeling, security requirements definition, and go-live risk assessments.
  • Establish secure coding standards for common programming languages, frameworks, APIs, cloud services, and development patterns.
  • Track security findings, remediation commitments, exceptions, compensating controls, and risk acceptance decisions.
  • Measure improvements in secure SDLC adoption, remediation timeliness, control coverage, and recurring vulnerability reduction.
DevSecOps Tooling, Standards, and Operations
  • Implement and operate SAST, DAST, software composition analysis, secrets detection, container scanning, API security, and infrastructure-as-code scanning.
  • Integrate security tooling into CI/CD pipelines using standardized patterns, APIs, plugins, connectors, and workflow automation.
  • Configure security gates, severity thresholds, suppression processes, exception workflows, and escalation paths.
  • Monitor tool health, scan coverage, pipeline failures, vulnerability backlogs, critical findings, and remediation performance.
  • Tune security tooling to improve finding accuracy, reduce false positives, and minimize unnecessary development disruption.
  • Establish processes for tool onboarding, configuration management, testing, upgrades, support, and retirement.
  • Develop reusable integrations, scripts, dashboards, reference implementations, and automation assets.
  • Support AI-assisted vulnerability triage, remediation recommendations, validation, and security workflow automation where appropriate.
Application Security Assessments
  • Perform application security assessments across web applications, APIs, microservices, mobile applications, cloud services, developer platforms, and engineering systems.
  • Conduct threat modeling, secure design reviews, architecture assessments, code reviews, vulnerability analysis, and penetration-test coordination.
  • Assess enterprise and business-critical applications, including web applications, APIs, cloud services, developer platforms, source code repositories, product lifecycle systems, supply chain platforms, and intellectual property systems.
  • Identify vulnerabilities, attack paths, insecure dependencies, authentication weaknesses, authorization issues, exposed secrets, and data protection risks.
  • Translate findings into practical remediation plans with severity, business impact, recommended actions, owners, and due dates.
  • Validate remediation through retesting, automated verification, evidence review, or compensating-control assessment.
  • Maintain application security risk registers and report material risks, aging findings, exceptions, and residual exposure.
  • Support security reviews for major application changes, cloud migrations, acquisitions, third-party platforms, and new technologies.
Cloud Secure Development Pipeline
  • Support secure development and deployment practices across Microsoft Azure, AWS, and hybrid environments.
  • Assess cloud-native services, containers, Kubernetes, serverless workloads, APIs, infrastructure-as-code, and CI/CD pipelines.
  • Implement controls for open-source dependencies, software bills of materials, artifact integrity, code signing, build security, secrets protection, and software provenance.
  • Pa
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

On-site
USD 100,000 - 130,000
DevSecOps Tech Lead
DevSecOps Tech Lead

CIBR Warriors • Charlotte (NC)

On-site
USD 120,000 - 150,000
Application Security (AppSec) / DevSecOps Engineer
Application Security (AppSec) / DevSecOps Engineer

Zoho • United States

Remote
USD 83,000 - 152,000
DevSecOps
DevSecOps

CareerUS Solutions • United States

On-site
USD 110,000 - 170,000
DevSecOps & Application Security III
DevSecOps & Application Security III

Lancesoft • United States

Remote
USD 110,000 - 117,000
DevSecOps and AI/Automation Engineer
DevSecOps and AI/Automation Engineer

Altera Corporation • San Jose (CA), Northern (KY)

Hybrid
USD 149,000 - 216,000
Secure DevSecOps Engineer – AI & Automation
Secure DevSecOps Engineer – AI & Automation

Altera • San Jose (CA)

On-site
USD 130,000 - 180,000
Senior InfoSec Engineer (SecDevOps) / New York
Senior InfoSec Engineer (SecDevOps) / New York

DigitalXNode • New York (NY)

On-site
USD 180,000 - 240,000
Restaurant d'entreprise
Indemnités de stage/alternance
DevSecOps Application Security Engineer
DevSecOps Application Security Engineer

Infosys • Richardson (TX)

On-site
USD 110,000 - 170,000
Application Security (AppSec) Engineer - W2 Only
Application Security (AppSec) Engineer - W2 Only

Saransh Inc • Maryland Heights (MO)

On-site
USD 110,000 - 160,000