Senior AppSec & DevSecOps Leader

Credo

San Jose (CA)

On-site

USD 100,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Discretionary bonus
Equity
Medical benefits

Job summary

Credo seeks a Senior Application Security Engineer to advance Secure SDLC, mitigate app risks, and partner with software, firmware, and engineering teams through the development lifecycle.

The ideal candidate will lead security initiatives across software, firmware, cloud, and AI-enabled environments, with strong expertise in secure coding, threat modeling, vulnerability management, and DevSecOps.

Qualifications

  • 5+ years in application/product security with hands‑on work in secure design, threat modeling, code review, and vulnerability management.
  • Secure SDLC leadership including 3+ years implementing or managing SDLC programs and partnering with engineering teams throughout the lifecycle.
  • Strong application security expertise including secure coding principles, architecture reviews, API security, and remediation guidance.
  • Technical depth in C, C++, and Python with experience reviewing and securing applications in these languages.
  • DevSecOps and automation proficiency including GitHub/GitLab, CI/CD pipelines, SAST/DAST/SCA, container security, and security automation tooling.
  • Cross‑functional communication with the ability to mentor developers, influence secure development practices, and support audits or customer assessments.

Responsibilities

  • Secure SDLC Implementation: Implement and continuous improvement of the Secure Software Development Lifecycle (Secure SDLC) program.
  • Partner with engineering leadership to embed security requirements into software and firmware development processes.
  • Define security standards, secure coding guidelines, and security gates across the development lifecycle.
  • Drive adoption of security-by-design principles across products and services.
  • Application Security: Conduct application security reviews, architecture reviews, and threat modeling exercises.
  • Perform source code reviews and security assessments of internally developed applications and products.
  • Identify, assess, prioritize, and track remediation of application security vulnerabilities.
  • Support penetration testing activities and coordinate remediation efforts with development teams.
  • DevSecOps & Automation: Implement and manage SAST, DAST, SCA, Secrets Scanning, Container Security, and CI/CD security controls.
  • Collaborate with DevOps teams to automate security testing and vulnerability management processes.

Skills

Application security
Secure coding
Threat modeling
Vulnerability management
DevSecOps
CI/CD pipelines
SAST/DAST/SCA
Container security
Security automation
Mentoring developers

Tools

GitHub
GitLab
CI/CD tooling

Job description

Credo seeks a Senior Application Security Engineer to advance Secure SDLC, mitigate app risks, and partner with software, firmware, and engineering teams through the development lifecycle.

The ideal candidate will lead security initiatives across software, firmware, cloud, and AI-enabled environments, with strong expertise in secure coding, threat modeling, vulnerability management, and DevSecOps.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AppSec Engineer: Secure DevOps & Cloud Defense + Equity
AppSec Engineer: Secure DevOps & Cloud Defense + Equity

Make Choteau Home • Montana

Remote
USD 120,000 - 155,000
Medical, dental, vision coverage
401(k)
Paid time off
+2
Senior AppSec & DevSecOps Engineer
Senior AppSec & DevSecOps Engineer

Censys • United States

On-site
USD 172,000 - 216,000
Senior AppSec Engineer - Secure SDLC & DevSecOps
Senior AppSec Engineer - Secure SDLC & DevSecOps

Vanguard • Town of Charlotte (NY)

Hybrid
USD 120,000 - 180,000
Strategic App Security Architect for DevSecOps & Cloud
Strategic App Security Architect for DevSecOps & Cloud

Recru • Spring (TX)

On-site
USD 180,000 - 240,000
AppSec Architect: Secure SDLC & DevSecOps Lead
AppSec Architect: Secure SDLC & DevSecOps Lead

TechDigital Group • Maryland Heights (MO)

On-site
USD 120,000 - 160,000
Hybrid App Security Engineer—Secure SDLC Leader
Hybrid App Security Engineer—Secure SDLC Leader

Packsize • Salt Lake City (UT)

Hybrid
USD 120,000 - 150,000
Senior Manager, App Security & Secure DevOps
Senior Manager, App Security & Secure DevOps

Koitecc Solutions • Massachusetts

On-site
USD 118,000 - 261,000
Senior Application Security Engineer | Secure SDLC Leader
Senior Application Security Engineer | Secure SDLC Leader

Compunnel Inc. • Orlando (FL)

On-site
USD 80,000 - 120,000
Lead AppSec Engineer — AI-Driven Secure SDLC Expert
Lead AppSec Engineer — AI-Driven Secure SDLC Expert

DSM-H Consulting • Chicago (IL)

On-site
USD 120,000 - 180,000
Senior AppSec Architect for AI-Driven Apps
Senior AppSec Architect for AI-Driven Apps

CBIZ • Independence Township (OH)

Hybrid
USD 140,000 - 200,000