$149,100 - $215,925 USD yearly
Originally posted 6 October 2026 by the employer.
About the role
This role focuses on strengthening application and software supply chain security across a global semiconductor organization by embedding security into the software development lifecycle.
What you'll do
- Define and maintain secure software development lifecycle standards, procedures, and control requirements.
- Implement and operate SAST, DAST, software composition analysis, secrets detection, container scanning, API security, and infrastructure-as-code scanning.
- Integrate security tooling into CI/CD pipelines using standardized patterns, APIs, and workflow automation.
- Perform application security assessments across web applications, APIs, microservices, mobile applications, cloud services, and engineering systems.
- Support secure development and deployment practices across Microsoft Azure, AWS, and hybrid environments.
- Provide practical guidance on secure coding, authentication, authorization, API security, secrets management, and cloud-native security.
What you'll need
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, Information Systems, or a related technical discipline.
- 6+ years of professional experience in AppSec, DevSecOps, secure SDLC, cloud security, cybersecurity engineering, or software security.
- Hands-on experience with secure SDLC, application security, secure-by-design, or DevSecOps activities.
- Experience with CI/CD or modern software engineering environments.
- Experience with at least three of the following: SAST, DAST, SCA, secrets scanning, IaC scanning, container security, API security, threat modeling, or vulnerability management.
- Experience with at least one cloud or cloud-native environment, including Microsoft Azure, AWS, Kubernetes, or container-based application environments.
- Experience using engineering, security workflow, or automation platforms such as Azure DevOps, GitHub, GitLab, Jenkins, Jira, or ServiceNow.
- Ability to conduct or support application security assessments and communicate findings to technical and nontechnical stakeholders.
Nice to have
- Experience supporting complex global, high-technology, regulated, or intellectual-property-intensive organizations.
- Experience securing enterprise applications, developer platforms, cloud services, source code repositories, business-critical systems, product lifecycle platforms, or intellectual property systems.
- Experience with Checkmarx, Fortify, Veracode, Semgrep, GitHub Advanced Security, CodeQL, SonarQube, Snyk, Mend, Black Duck, or comparable tools.
- Experience with Burp Suite, OWASP ZAP, Invicti, or comparable DAST and API security tools.
- Experience securing containers, Kubernetes, serverless applications, APIs, and infrastructure-as-code.
- Experience with Azure DevOps, GitHub Actions, GitLab CI/CD, Jenkins, Bitbucket, Argo CD, or comparable platforms.
- Familiarity with OWASP Top 10, OWASP ASVS, OWASP SAMM, NIST SSDF, BSIMM, SLSA, CIS Controls, or similar frameworks.
- Experience with SBOM, software provenance, artifact integrity, code signing, PKI, HSM, or dependency governance.
- Experience developing application security dashboards, key risk indicators, key performance indicators.
Skills: DevSecOps, application security, CI/CD pipelines, cloud security, software supply chain
This role has been open 3 days — well below the 51-day median for Infrastructure/Platform Software roles.
Infrastructure/Platform Software · Infrastructure Platform
|
Open roles in category
912
|
Median days open
51 d
|
Median salary
$229k
|
See the full market breakdown ▾Category comparison, skills in demand, and who else is hiring
| Metric | Altera | All employers we track in this specialty (912 roles · 86 employers) |
|---|---|---|
| Open roles in this specialty | 7 | 912 |
| Open roles in the wider Software, Firmware & Systems family | 24 | 6047 · 146 employers |
| Median days open | 9 d | 51 d (−42 d vs this employer) |
| Median salary (USD postings) | — | $229k |
Skills observed across this category: DevSecOps, application security, CI/CD pipelines, cloud security, software supply chain
Who's hiring in this category
- NVIDIA · 250 open roles · median 49 d
- Qualcomm · 60 open roles · median 61 d
- AMD · 51 open roles · median 28 d
- Cerebras · 40 open roles · median 74 d
- Graphcore · 38 open roles · median 101 d
- Intel Corporation · 33 open roles · median 21 d
How we counted: 912 open Infrastructure/Platform Software (Infrastructure Platform) roles from 86 employers tracked in the SemiconductorJobs index, counted 9 Oct 2026. Specialty figures count only roles carrying this exact specialty label, so an employer's related work in neighbouring specialties is not included there — it is counted in the wider Software, Firmware & Systems family row. Figures refresh nightly.