Senior AppSec & DevSecOps Leader

Credo

San Jose (CA)

On-site

USD 100,000 - 150,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Discretionary bonus
Equity
Medical benefits

Job summary

Credo seeks a Senior Application Security Engineer to advance Secure SDLC, mitigate app risks, and partner with software, firmware, and engineering teams through the development lifecycle.

The ideal candidate will lead security initiatives across software, firmware, cloud, and AI-enabled environments, with strong expertise in secure coding, threat modeling, vulnerability management, and DevSecOps.

Qualifications

  • 5+ years in application/product security with hands‑on work in secure design, threat modeling, code review, and vulnerability management.
  • Secure SDLC leadership including 3+ years implementing or managing SDLC programs and partnering with engineering teams throughout the lifecycle.
  • Strong application security expertise including secure coding principles, architecture reviews, API security, and remediation guidance.
  • Technical depth in C, C++, and Python with experience reviewing and securing applications in these languages.
  • DevSecOps and automation proficiency including GitHub/GitLab, CI/CD pipelines, SAST/DAST/SCA, container security, and security automation tooling.
  • Cross‑functional communication with the ability to mentor developers, influence secure development practices, and support audits or customer assessments.

Responsibilities

  • Secure SDLC Implementation: Implement and continuous improvement of the Secure Software Development Lifecycle (Secure SDLC) program.
  • Partner with engineering leadership to embed security requirements into software and firmware development processes.
  • Define security standards, secure coding guidelines, and security gates across the development lifecycle.
  • Drive adoption of security-by-design principles across products and services.
  • Application Security: Conduct application security reviews, architecture reviews, and threat modeling exercises.
  • Perform source code reviews and security assessments of internally developed applications and products.
  • Identify, assess, prioritize, and track remediation of application security vulnerabilities.
  • Support penetration testing activities and coordinate remediation efforts with development teams.
  • DevSecOps & Automation: Implement and manage SAST, DAST, SCA, Secrets Scanning, Container Security, and CI/CD security controls.
  • Collaborate with DevOps teams to automate security testing and vulnerability management processes.

Skills

Application security
Secure coding
Threat modeling
Vulnerability management
DevSecOps
CI/CD pipelines
SAST/DAST/SCA
Container security
Security automation
Mentoring developers

Tools

GitHub
GitLab
CI/CD tooling

Job description

Credo seeks a Senior Application Security Engineer to advance Secure SDLC, mitigate app risks, and partner with software, firmware, and engineering teams through the development lifecycle.

The ideal candidate will lead security initiatives across software, firmware, cloud, and AI-enabled environments, with strong expertise in secure coding, threat modeling, vulnerability management, and DevSecOps.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior AppSec Engineer: DevSecOps & Secure SDLC
Senior AppSec Engineer: DevSecOps & Secure SDLC

Tential Solutions • United States

On-site
USD 120,000 - 180,000
PTO
Benefits package
Career growth
Senior App Security Engineer - DevSecOps & Secure SDLC
Senior App Security Engineer - DevSecOps & Secure SDLC

Ascensus • Dresher

On-site
USD 120,000 - 170,000
Tuition reimbursement
Paid time off
Medical benefits
+2
Senior AppSec Architect for AI-Driven DevSecOps (Remote)
Senior AppSec Architect for AI-Driven DevSecOps (Remote)

CVS Health • Arizona

Hybrid
USD 175,000 - 335,000
Health benefits
Bonus/equity program
Senior AppSec Engineer — Build Secure AI Platforms
Senior AppSec Engineer — Build Secure AI Platforms

Cogent Security • San Francisco (CA)

On-site
USD 100,000 - 300,000
Senior AppSec Lead - Secure SDLC & Tooling
Senior AppSec Lead - Secure SDLC & Tooling

Objective Partners • Chicago (IL)

On-site
USD 140,000 - 180,000
AppSec Engineer – Secure SDLC & DoD
AppSec Engineer – Secure SDLC & DoD

Talentify • O'Fallon (IL)

On-site
USD 75,000 - 158,000
Hybrid App Security Engineer—Secure SDLC Leader
Hybrid App Security Engineer—Secure SDLC Leader

Packsize • Salt Lake City (UT)

Hybrid
USD 120,000 - 150,000
Senior AppSec Leader: Shape Our Secure SDLC
Senior AppSec Leader: Shape Our Secure SDLC

InfraTech Solutions LLC • Chicago (IL)

On-site
USD 140,000 - 210,000
Senior Application Security Engineer | Secure SDLC Leader
Senior Application Security Engineer | Secure SDLC Leader

Compunnel Inc. • Orlando (FL)

On-site
USD 80,000 - 120,000
Remote Senior AppSec Architect: AI & DevSecOps
Remote Senior AppSec Architect: AI & DevSecOps

CVS Health • Phoenix (AZ)

On-site
USD 175,000 - 335,000