Director of Software Security

Cadence Design Systems
San Jose
Workplace: OnsiteFull timeFunction: Executive & General ManagementExperience: 12-15 yearsSkills: ["Devsecops","Security architecture","Regulatory compliance","Application security","Threat modeling","Software supply chain security","Cloud security","Container security","Vulnerability management","Agile","Ci/cd security"]

Lead DevSecOps transformation and secure software lifecycle across the enterprise. Define secure architectures for microservices, APIs, and cloud-native apps; drive regulatory compliance (CMMC, NIST, ISO) and audits; secure cloud platforms and supply chains; build and scale an AppSec program with cross-functional influence.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Cadence Design Systems
Cadence Design Systems
3 months ago

Director of Software Security

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 16 hours agoStatus: Live

Job Summary

Lead DevSecOps transformation and secure software lifecycle across the enterprise. Define secure architectures for microservices, APIs, and cloud-native apps; drive regulatory compliance (CMMC, NIST, ISO) and audits; secure cloud platforms and supply chains; build and scale an AppSec program with cross-functional influence.
Location: San Jose
Workplace: Onsite
Employment Type: Full time
Job Function: Executive & General Management
Seniority: Director level

Key Responsibilities

  • •Define and execute enterprise DevSecOps strategy across all development teams; integrate security controls into CI/CD pipelines (build, test, release) and establish shift-left security in the SDLC; drive adoption of secure coding, SAST, DAST, and SCA tools
  • •Define reference architectures for secure microservices, APIs, and cloud-native apps; establish security patterns for containers, Kubernetes, and serverless; lead threat modeling initiatives; ensure secure API design and zero trust principles
  • •Lead compliance initiatives for CMMC 2.0, NIST SP 800-171r2/800-53, ISO 27001; coordinate audits, assessments, and continuous monitoring; implement controls for handling CUI
  • •Secure DevOps pipelines across cloud platforms (AWS, Azure, Google Cloud, IBM Cloud); implement infrastructure-as-code (IaC) security scanning; define secrets management and IAM controls
  • •Build and scale AppSec program across all product lines; define vulnerability management lifecycle; establish bug bounty / responsible disclosure programs; integrate security into Agile and CI/CD workflows

Key Requirements

  • •12–15+ years in cybersecurity, with strong focus on application security and DevSecOps
  • •5+ years in leadership (manager/director level)
  • •Deep expertise in: Secure SDLC and DevSecOps pipelines
  • •Cloud-native architectures and container security
  • •Regulatory frameworks (CMMC, NIST, ISO)
Experience:12-15 yearsCybersecurityAppSecDevSecOpsCloud-nativeRegulated industries
Skills:DevsecopsSecurity architectureRegulatory complianceApplication securityThreat modelingSoftware supply chain securityCloud securityContainer securityVulnerability managementAgileCi/cd security
Certifications:CISSPCSSLPCISMCCSP
Tech Stack:AWSAzureGoogle CloudIBM CloudKubernetesDockerJenkinsGitHub ActionsSASTDASTSCASBOMIaCCI/CD

Company Brief

Cadence Design Systems
Provides electronic design automation (EDA) software, IP, and services for semiconductor and systems companies to design, verify, and implement integrated circuits, systems-on-chip, and electronic systems across industries including communications, automotive, and consumer electronics.
Industry: Developer Tools
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Jose, United States
Founded: 1988
Glassdoor
Glassdoor: 3.9
WebsiteLinkedInGlassdoor