Stand out for this role — generate a tailored resume and cover letter in about a minute.
Itron is seeking a senior Information Security leader to advance product security across software development, cloud, and engineering environments. You will secure source code, software supply chains, CI/CD pipelines, and architectures while enabling agile development practices.
You will collaborate with Product Development, DevOps, Cloud Engineering, Enterprise Architecture, and Cybersecurity teams to implement scalable security solutions protecting Itron products and services through the
Demonstrated ability to communicate technical risk and recommendations effectively to engineering leadership and executive stakeholdersExperience troubleshooting complex issues involving source control systems, build platforms, deployment pipelines, artifact repositories, and release management processesStrong knowledge of software supply chain security, source code protection, secrets management, privileged access management, artifact integrity, dependency governance, and secure release practices7+ years of experience in cybersecurity, product security, application security, software engineering, DevSecOps, cloud security, or a related technical disciplineProven ability to influence diverse teams and drive adoption of secure, innovative, and agile engineering practicesExpert-level experience designing and operating security controls across cloud, SaaS, enterprise, and product engineering environmentsBachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field; or an equivalent combination of education and experienceDeep understanding of application and API security principles, including OWASP Top 10, OWASP API Security Top 10, secure coding practices, and modern authentication and authorization modelsExperience implementing path-to-production controls including policy enforcement, release gates, exception management, evidence collection, and deployment readiness criteria5+ years of hands-on experience securing software development environments, source code platforms, CI/CD pipelines, or software supply chainsStrong written, verbal, and stakeholder-management skillsIf you are excited about this role but your past experiences don’t perfectly align with every requirement, we encourage you to apply anyway. In the end, you may be just who we are looking for!Professional certifications such as CISSP, CSSLP, CCSP, GIAC GWEB, GWAPT, GCSA, AWS Security Specialty, Microsoft Certified: Cybersecurity Architect Expert, or equivalent security certificationsHands-on experience with GitHub, GitLab, Azure DevOps, Bitbucket, or similar platforms, including branch protection, code review workflows, signed commits, repository permissions, and secret scanningExperience securing CI/CD platforms such as Jenkins, GitHub Actions, Azure DevOps, and GitLab CI, along with artifact repositories, package registries, and deployment automation solutionsKnowledge of secure product architecture, deployment security, artifact signing, provenance, SBOM practices, and release integrity controlsFamiliarity with software supply chain security frameworks and practices including SLSA, NIST SSDF, OWASP SAMM, and OWASP Top 10Experience applying application and API security principles across web, cloud, mobile, embedded, and service-based architecturesExperience using Terraform, AWS CloudFormation, Open Policy Agent, Python, PowerShell, and policy-as-code approaches to automate security controlsUnderstanding of modern product security threats including dependency confusion, malicious packages, source code tampering, credential theft, build pipeline compromise, and release artifact manipulationExperience supporting regulated environments aligned with ISO 27001, SOC 2, NIST, CMMC, IEC 62443, or comparable frameworks