Head of Application Security

Analog Devices, Inc.

Wilmington (MA)

On-site

USD 219,000 - 301,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, vision and dental coverage
401k
Paid vacation
Holidays
Sick time
Other benefits

Job summary

Analog Devices, Inc. in the United States seeks a Head of Application Security to lead ADI’s security strategy across application, AI, and product security.

You will embed secure-SDLC into the DevOps/CI-CD pipeline, govern AI security including LLM controls, and mature PSIRT capabilities for firmware and hardware. You will build and scale a multidisciplinary team, translate risk into business terms for executives and the Board, and partner with engineering to enable secure, trusted products

Qualifications

  • 15+ years in cybersecurity leadership in large-scale environments.
  • Experience building DevSecOps programs and secure-SDLC.
  • Deep knowledge of AI security governance and ITAR/compliance.

Responsibilities

  • Lead strategy and operations for application, AI, and product security.
  • Embed secure-SDLC into DevOps and CI/CD pipelines.
  • Grow and mentor a multidisciplinary security team.

Skills

Security leadership
DevSecOps
Secure SDLC
CI/CD security
SAST
SBOM tooling

Education

Bachelor's degree in Engineering/CS/Cybersecurity

Tools

SAST tools
SCA tools
DAST tools
SBOM tooling

Job description

About Analog Devices

Analog Devices, Inc. (NASDAQ: ADI) is a global semiconductor leader that bridges the physical and digital worlds to enable breakthroughs at the Intelligent Edge. ADI combines analog, digital, AI, and software technologies into solutions that combat climate change, reliably connect humans and the world, and help drive advancements in automation and robotics, mobility, healthcare, energy and data centers. With revenue of more than $11 billion in FY25, ADI ensures today's innovators stay Ahead of What's Possible. Learn more at www.analog.com and on LinkedIn and X.

Head of Application Security

The leader of Application, AI and Product Security is a senior leadership role responsible for protecting the software, artificial intelligence, and products at the heart of ADI’s business. Reporting to the Chief Information Security Officer (CISO), this leader ensures that everything ADI builds and ships is secure by design - worthy of the trust of our automotive, aerospace and defense, healthcare, and industrial customers, and resilient against the most capable threat actors. As ADI accelerates at the Intelligent Edge, embedding software, AI, and connectivity into the components the world depends on, this role makes security a competitive advantage. This role is a "build-and-scale" mandate spanning three connected disciplines. This leader will stand up and mature a developer-first application security (DevSecOps) capability across ADI’s software development lifecycle; establish a risk-managed AI security and governance program covering generative AI, large language models, and emerging agentic AI use cases; and grow a company-wide product security practice – building on ADI’s existing product security incident response and coordinated vulnerability disclosure capabilities – for the products ADI designs, manufactures, and ships. Working across IT, LRO, and the business (Software & Digital Platforms, Engineering Enablement, Global Operations & Technology), the role connects these threads into a single, risk-managed security strategy that drives alignment, informs executive and Board decision-making, and strengthens the resilience and trustworthiness of ADI’s technology. Sequencing matters in this role. The immediate priority is application security embedded into ADI’s DevOps / CI-CD environment; the near-term priority is a risk-managed AI security program, beginning with generative AI and LLM governance and controls before extending to agentic AI; and the third priority is maturing a full-scope, company-wide product security practice. The leader will establish a disciplined discovery and stakeholder-alignment period before scaling execution across all three.

Key Responsibilities

Lead the strategy, build-out, and operation of ADI’s application security, AI security, and product security capabilities, including:

  • Application Security (DevSecOps): Establish and mature secure software development lifecycle (secure-SDLC) policy, standards, reference architectures, and tooling (SAST, SCA, DAST, secret scanning); harden the software supply chain – source repositories, Continuous Integration / Continuous Delivery/Deployment (CI/CD) pipelines, build systems, credentials, and dependencies – and drive software bill of materials (SBOM) generation and trusted-publishing at scale.
  • AI Security: Define and operate a risk-managed AI security and governance program aligned to recognized frameworks (e.g., NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, MITRE ATLAS), beginning with generative AI and LLM controls, and operations, and extending to secure agentic AI use cases including non-human / agent identity, action guardrails, and human-in-the-loop controls.
  • Product Security: Grow a company-wide, risk-managed product security practice anchored to a secure product development lifecycle standard (e.g., IEC 62443-4-1) and embedded into the New Product Introduction (NPI) process; own and mature ADI’s Product Security Incident Response Team (PSIRT) capability, coordinated vulnerability disclosure, CVE/CVSS practice, and SBOM/HBOM strategy for shipped firmware and hardware.

Serve as a trusted strategic advisor to the CISO, executive leadership, and the Board of Directors – translating complex application, AI, and product security exposure into clear, quantified business, customer, and financial impact, and shaping the narrative around key security decisions, priorities, and tradeoffs.

Build, lead, and develop a high-performing, multidisciplinary team; make deliberate build / borrow / buy decisions and cultivate a broad network of security champions embedded across engineering and the business units. Champion a security-by-design, paved-road culture in which the secure path is the fast path – earning adoption from engineering and improving velocity while reducing risk, with measurable coverage, adoption, and risk-burndown reporting. Align application, AI, and product security to the regulatory and customer requirements that govern ADI’s markets – including automotive (ISO/SAE 21434, ISO 26262), aerospace and defense (ITAR/EAR, CMMC), healthcare (IEC 62304, FDA cybersecurity guidance), and industrial (IEC 62443) – and support customer-facing trust, audits, and attestations. Integrate application, AI, and product security risk into ADI’s enterprise risk model, establish and chair cross-functional governance with a clear risk-acceptance and exception process, and report posture, key risk indicators, and program progress to executive and Board-level audiences.

Lead response to significant application, AI, or product security incidents, including decision-making, regulatory engagement, external communications, and post-incident learning. Operate with a high degree of autonomy in a fast-paced, evolving environment; identify opportunities to improve how ADI secures its software, AI, and products, and establish scalable standards and best practices. Lead and scale a high-performing multidisciplinary organization across application, AI, and product security, establishing the structure, priorities, and accountability needed to deliver impactful enterprise security outcomes for ADI Build a strong talent bench by attracting, developing, and retaining top security talent, strengthening leadership capability, and fostering a collaborative culture of agility, ownership, and continuous improvement Serves as a credible, trusted partner to internal stakeholders and engineering teams, ensuring security standards enable delivery, strengthen product trust, and support ADI’s innovation and growth priorities.

Required Qualifications
  • Bachelor’s degree required, preferably in Engineering, Computer Science, Cybersecurity, or a related technical field (or equivalent experience).
  • 15+ years of progressive cybersecurity experience, including significant experience in a senior security leadership role (e.g., Deputy CISO, CISO, or a Senior Director/Executive Director leading application, product, or AI security) in a large-scale, complex environment.
  • 15+ years of sponsoring and managing complex programs and projects.
  • A breadth of program delivery across application delivery, product and cybersecurity is preferred.
  • Proven experience building, leading, and scaling security functions across large, global engineering organizations, with a track record of building high-performing teams and sustaining engagement through organizational change.
  • Deep expertise establishing secure-SDLC / DevSecOps programs and embedding automated security testing (SAST/SCA/DAST/secret scanning) into CI/CD pipelines, with hands‑on understanding of software supply‑chain security, threat modeling, and secure code / design review.
  • Working knowledge of AI/GenAI security and governance frameworks and controls – including model risk, data leakage, prompt‑injection defense, and AI incident response – and familiarity with the emerging risks of agentic AI.
  • Experience with product security, PSIRT / coordinated vulnerability disclosure, and SBOM / software-supply-chain transparency, and the ability to interpret and map requirements from security and safety frameworks relevant to ADI’s markets (e.g., IEC 62443, ISO/SAE 21434, ISO 26262, IEC 62304, NIST CSF, CMMC, ITAR/EAR).
  • Demonstrated ability to translate highly complex technical risk into clear, quantified, business‑focused terms (e.g., FAIR or equivalent) and communicate to both technical and non‑technical audiences, including executives and the Board.
  • Strong executive presence and stakeholder‑management skills, with experience working directly with senior leadership and influencing across organizational boundaries.
  • Demonstrated ability to operate with significant autonomy, navigate ambiguity, and balance strategic thinking with hands‑on execution in a dynamic, fast‑paced environment.
Ideal Qualifications
  • Advanced degree and relevant certifications (e.g., CISSP, CISM).
  • Experience in the semiconductor, electronics, or advanced‑hardware industry, or in another regulated, IP‑intensive, or critical‑infrastructure‑adjacent environment (e.g., aerospace/defense, automotive, medical devices, or life sciences).
  • Experience operating in export‑controlled and regulated environments (e.g., ITAR/EAR, CMMC).
  • Experience standing up a new security capability or function from the ground up, including establishing governance, standards, and scalable operating models across a large organization.
  • Experience supporting Board‑level communications, enterprise risk reviews, or executive decision forums on cybersecurity posture and strategy.

For positions requiring access to technical data, Analog Devices, Inc. may have to obtain export licensing approval from the U.S. Department of Commerce - Bureau of Industry and Security and/or the U.S. Department of State - Directorate of Defense Trade Controls. As such, applicants for this position – except US Citizens, US Permanent Residents, and protected individuals as defined by 8 U.S.C. 1324b(a)(3) – may have to go through an export licensing review process.

Analog Devices is an equal opportunity employer. We foster a culture where everyone has an opportunity to succeed regardless of their race, color, religion, age, ancestry, national origin, social or ethnic origin, sex, sexual orientation, gender, gender identity, gender expression, marital status, pregnancy, parental status, disability, medical condition, genetic information, military or veteran status, union membership, and political affiliation, or any other legally protected group. EEO is the Law: Notice of Applicant Rights Under the Law.

Job Req Type

Experienced

Required Travel

Yes, 10% of the time

Shift Type

1st Shift/Days

Compensation and Benefits

The expected wage range for a new hire into this position is $219,200 to $301,400. Actual wage offered may vary depending on work location, experience, education, training, external market data, internal pay equity, or other bona fide factors. This position qualifies for a discretionary performance‑based bonus which is based on personal and company factors.

  • medical, vision and dental coverage
  • 401k
  • paid vacation
  • holidays
  • sick time
  • other benefits

Analog Devices, Inc. (NASDAQ: ADI) is a global semiconductor leader that bridges the physical and digital worlds to enable breakthroughs at the Intelligent Edge. ADI combines analog, digital, AI and software technologies to solve challenges across sectors. With revenue of more than $11 billion in FY25, ADI ensures today's innovators stay Ahead of What's Possible. Learn more at www.analog.com and on LinkedIn and X. Come join ADI – a place where Innovation meets Impact. For more than 55 years, Analog Devices has been inventing new breakthrough technologies that transform lives. At ADI you will work alongside the brightest minds to collaborate on solving complex problems that matter from autonomous vehicles, drones and factories to augmented reality and remote healthcare. ADI fosters a culture that focuses on employees through beneficial programs, aligned goals, continuous learning opportunities, and practices that create a more sustainable future.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Head of Application Security
Head of Application Security

Analog Devices • Wilmington (MA)

On-site
USD 219,000 - 301,000
Medical, vision and dental coverage
401k
Paid vacation
+1
Head of Application Security
Head of Application Security

1010 Analog Devices Inc. • Wilmington (MA)

On-site
USD 219,000 - 301,000
Medical, Vision and Dental Coverage
401k
Paid Vacation
+3
Associate Product Applications Engineer
Associate Product Applications Engineer

1322 Analog Devices Gen. Trias • Wilmington (MA)

On-site
USD 68,000 - 94,000
Medical coverage
Vision coverage
Dental coverage
+5
Forward Deployed Engineer
Forward Deployed Engineer

1010 Analog Devices Inc. • San Jose (CA)

On-site
USD 230,000 - 316,000
Medical, Vision, and Dental coverage
401k
Paid vacation, holidays, and sick time
Staff Mixed-Signal Design Engineer
Staff Mixed-Signal Design Engineer

Analog Devices, Inc. • Wilmington (MA)

Hybrid
USD 131,000 - 190,000
Medical
Dental
Vision
+12
Senior Engineer, Digital Design (Physical)
Senior Engineer, Digital Design (Physical)

Analog Devices • Wilmington (MA)

On-site
USD 117,000 - 161,000
Discretionary performance-based bonus
Medical, vision and dental coverage
401k
+4
Senior Mixed-Signal IC Design Engineer
Senior Mixed-Signal IC Design Engineer

1010 Analog Devices Inc. • Wilmington (MA)

Hybrid
USD 110,000 - 152,000
Hybrid work model
Product Engineer
Product Engineer

1014 AD Federal • Durham (NC)

On-site
USD 85,000 - 120,000
Medical
Dental
Sick and vacation leaves
+6
Senior Mixed-Signal IC Design Engineer
Senior Mixed-Signal IC Design Engineer

Analog Devices, Inc. • Wilmington (MA)

Hybrid
USD 110,000 - 152,000
medical
dental
401(k)
+11
Product Engineer
Product Engineer

Analog Devices • Durham (NC)

On-site
USD 90,000 - 120,000
Medical
Dental
Disability insurance
+2