Job Summary:
Cadence is a technology company seeking a Director of Software Security to lead secure software development practices across the enterprise. This role involves driving DevSecOps transformation, ensuring compliance with regulatory frameworks, and embedding security throughout the software lifecycle.
Responsibilities:
โข Define and execute enterprise DevSecOps strategy across all development teams
โข Integrate security controls into CI/CD pipelines (build, test, release)
โข Establish โshift-leftโ security practices across the SDLC
โข Drive adoption of secure coding, SAST, DAST, and SCA tools
โข Define reference architectures for secure microservices, APIs, and cloud-native apps
โข Establish security patterns for containers, Kubernetes, and serverless
โข Lead threat modeling initiatives
โข Ensure secure API design and zero trust principles
โข Lead compliance initiatives for: Cybersecurity Maturity Model Certification (CMMC 2.0), NIST SP 800-171r2 /800-53, ISO 27001
โข Ensure software systems meet federal, defense, and privacy regulations
โข Coordinate audits, assessments, and continuous monitoring programs
โข Implement controls for handling Controlled Unclassified Information (CUI)
โข Secure DevOps pipelines across cloud platforms: Amazon AWS, Microsoft Azure, Google Cloud, IBMC cloud, Cadence software service and products
โข Implement infrastructure-as-code (IaC) security scanning
โข Define secrets management, identity, and access controls
โข Build and scale AppSec program across all product lines
โข Define vulnerability management lifecycle (discovery โ remediation โ validation)
โข Establish bug bounty / responsible disclosure programs
โข Integrate security into Agile and CI/CD workflows
โข Secure software supply chain (SBOM, dependency scanning)
โข Implement artifact signing, provenance, and integrity validation
โข Define policies, standards, and secure development guidelines
โข Establish KPIs: vulnerability remediation SLA, code coverage, pipeline security
โข Align software security with enterprise risk management
โข Report posture to executive leadership and board
โข Lead teams of AppSec engineers, DevSecOps engineers, and architects
โข Partner with Engineering, Product, Legal, and Compliance teams
โข Build security champions program within development teams
โข Influence engineering culture toward security ownership
Qualifications:
Required:
โข 12โ15+ years in cybersecurity, with strong focus on application security and DevSecOps
โข 5+ years in leadership (manager/director level)
โข Deep expertise in: Secure SDLC and DevSecOps pipelines, Cloud-native architectures and container security, Regulatory frameworks (CMMC, NIST, ISO)
โข Experience in regulated industries (defense, government, healthcare, fintech)
Preferred:
โข Hands-on experience with tools such as: SAST: Checkmarx, Veracode, DAST: Burp Suite, SCA: Snyk, Black Duck, CI/CD: Jenkins, GitHub Actions
โข Familiarity with Kubernetes, Docker, and service mesh security
โข Certifications: CISSP, CSSLP, CISM or CCSP
โข Experience with Zero Trust and identity-first security
Company:
Cadence is a market leader in AI and digital twins, pioneering the application of computational software to accelerate innovation in the engineering design of silicon to systems. Founded in 1988, the company is headquartered in San Jose, USA, with a team of 10001+ employees. The company is currently Late Stage.