• Lead the architecture and engineering of security controls protecting source code repositories, development environments, build systems, software supply chains, and release processes
• Design and implement secure CI/CD pipeline patterns, artifact management controls, signing services, and deployment workflows
• Partner with security-by-design and application security testing teams to operationalize security requirements, vulnerability management, threat modeling outcomes, and release controls
• Establish and promote secure application and API security standards
• Collaborate with engineering teams to reduce application, API, and cloud attack surfaces
• Drive modernization of development and engineering environments
• Integrate security capabilities across source control, CI/CD platforms, cloud services, artifact repositories, governance tools, and security monitoring solutions
• Automate security controls and operational processes using APIs, infrastructure-as-code, and scripting technologies
• Establish security logging, monitoring, and detection requirements for software development and release environments
• Develop secure architecture guardrails, reference standards, operational procedures, and technical documentation
• Ensure auditable evidence for software supply chain controls, artifact integrity, release approvals, SBOM generation, and regulatory or customer assurance requirements
• Mentor engineers and influence cross-functional teams to adopt secure engineering practices across global product environments
Requirements
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field; or an equivalent combination of education and experience
- 7+ years of experience in cybersecurity, product security, application security, software engineering, DevSecOps, cloud security, or a related technical discipline
- 5+ years of hands‑on experience securing software development environments, source code platforms, CI/CD pipelines, or software supply chains
- Expert‑level experience designing and operating security controls across cloud, SaaS, enterprise, and product engineering environments
- Strong knowledge of software supply chain security, source code protection, secrets management, privileged access management, artifact integrity, dependency governance, and secure release practices
- Deep understanding of application and API security principles, including OWASP Top 10, OWASP API Security Top 10, secure coding practices, and modern authentication and authorization models
- Experience troubleshooting complex issues involving source control systems, build platforms, deployment pipelines, artifact repositories, and release management processes
- Experience implementing path‑to‑production controls including policy enforcement, release gates, exception management, evidence collection, and deployment readiness criteria
- Demonstrated ability to communicate technical risk and recommendations effectively to engineering leadership and executive stakeholders
- Proven ability to influence diverse teams and drive adoption of secure, innovative, and agile engineering practices
- Strong written, verbal, and stakeholder‑management skills
- Professional certifications such as CISSP, CSSLP, CCSP, GIAC GWEB, GWAPT, GCSA, AWS Security Specialty, Microsoft Certified: Cybersecurity Architect Expert, or equivalent security certifications
- Hands‑on experience with GitHub, GitLab, Azure DevOps, Bitbucket, or similar platforms, including branch protection, code review workflows, signed commits, repository permissions, and secret scanning
- Experience securing CI/CD platforms such as Jenkins, GitHub Actions, Azure DevOps, and GitLab CI, along with artifact repositories, package registries, and deployment automation solutions
- Knowledge of secure product architecture, deployment security, artifact signing, provenance, SBOM practices, and release integrity controls
- Familiarity with software supply chain security frameworks and practices including SLSA, NIST SSDF, OWASP SAMM, and OWASP Top 10
- Experience applying application and API security principles across web, cloud, mobile, embedded, and service‑based architectures
- Experience using Terraform, AWS CloudFormation, Open Policy Agent, Python, PowerShell, and policy‑as‑code approaches to automate security controls
- Understanding of modern product security threats including dependency confusion, malicious packages, source code tampering, credential theft, build pipeline compromise, and release artifact manipulation
- Experience supporting regulated environments aligned with ISO 27001, SOC 2, NIST, CMMC, IEC 62443, or comparable frameworks
- Travel: Less than 25%
Core Competencies
Demonstrates expertise in designing and implementing security controls for software development environments, CI/CD pipelines, and cloud services, while ensuring compliance with industry standards. Proven ability to mentor teams and drive the adoption of secure engineering practices across diverse environments.
Highest-signal resume keywords
- Cybersecurity Expertise
- CI/CD Pipeline Security
- Application Security Principles
- Security Control Design
- Regulatory Compliance Experience
ATS Optimization Keywords
Hard Skills
- Software Supply Chain Security
- Secure Coding Practices
- Infrastructure-as-Code
- API Security
- Threat Modeling
- Vulnerability Management
- Artifact Integrity
- Secrets Management
- Policy Enforcement
- Deployment Automation
Soft Skills
- Stakeholder Management
- Technical Communication
- Influencing Teams
- Mentoring Engineers
- Collaboration
Certifications & Qualifications
- CISSP
- CSSLP
- CCSP
- GIAC GWEB
- GWAPT
- GCSA
- AWS Security Specialty
- Microsoft Certified: Cybersecurity Architect Expert
Industry Keywords
- ISO 27001
- SOC 2
- NIST
- CMMC
- IEC 62443
- OWASP Top 10
- SLSA
- NIST SSDF
- OWASP SAMM
- Secure Release Practices
Tools & Technologies
- GitHub
- GitLab
- Azure DevOps
- Jenkins
- Terraform
- AWS CloudFormation
- Open Policy Agent
- Python
- PowerShell
- Security Monitoring Solutions