Remote · Staff/Principal · Remote
Applicants who checked fit first are 3.1× more likely to hear back
Your score for this role already exists
ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.
No credit card · 1 tap with Google
HIGH
Shield AI is actively reviewing profiles and moving candidates through the pipeline right now.
First 72 hours
Still inside it - posted 1h agoEarly applicants get seen before the pile builds.
Not a repost
The first time we've seen this listing - it hasn't been closed and reopened.
You almost certainly match several of these already. Unlock your skill map to see the matches, the gaps, and what to fix first.
* Establish, maintain, and continuously improve company-wide secure SDLC policies, standards, control objectives, procedures, and supporting evidence requirements.
* Translate security policy into clear, achievable requirements for development, product, and platform teams without creating unnecessary delivery friction.
* Assess the maturity of development teams, CI/CD pipelines, source-control practices, build environments, and release processes; define and lead practical improvement roadmaps.
* Develop secure-development guidance, reference architectures, reusable patterns, security guardrails, exception processes, and developer enablement materials.
* Partner directly with development teams to identify, triage, prioritize, remediate, and verify application-security findings.
* Evaluate, implement, tune, and operationalize application-security tooling, including:* Static application security testing (SAST)
* Dynamic application security testing (DAST)
* Software composition analysis (SCA)
* Secrets detection
* Infrastructure-as-code security scanning
* Container and image security scanning
* API and cloud-native application security controls
* Ensure security tooling produces actionable, appropriately prioritized findings and does not create unnecessary developer burden through excessive false positives.
* Lead or facilitate threat modeling, security requirements definition, and secure design or architecture reviews for high-risk applications, integrations, and material changes.
* Establish risk-based vulnerability management processes, including severity criteria, remediation service-level objectives, compensating controls, formal risk acceptance, escalation, and exception management.
* Develop and maintain processes for identifying, tracking, and remediating vulnerable third-party, open-source, and transitive dependencies.
* Establish open-source software governance, including component inventory, license identification, license review, approval workflows, and policy enforcement.
* Mature software supply-chain security practices, including:* Machine-readable software bills of materials (SBOMs)
* Vulnerability Exploitability eXchange (VEX) or equivalent vulnerability-status communications
* Build and release provenance
* Artifact, package, container-image, and binary signing
* Artifact verification and trusted promotion processes
* Secure artifact repositories and package registries
* Approved dependency sources and package integrity verification
* SLSA-aligned build integrity, provenance, and release controls
* Partner with DevOps and platform engineering to secure CI/CD pipelines, including least-privilege access, protected branches, secure secret handling, hardened build environments, and release approvals.
* Establish requirements for secure source-code repositories, build systems, dependency registries, artifact repositories, and deployment pipelines.
* Support application vulnerability intake, coordinated disclosure, customer-facing security advisories, CVE triage where applicable, and product-security incident response.
* Create and lead a security champions program that provides developers with secure-coding guidance, training, office hours, practical tools, and a pathway for timely security engagement.
* Develop executive-ready metrics and reporting on secure-SDLC adoption, AppSec risk, remediation performance, control coverage, software supply-chain integrity, and program maturity.
* Support customer, regulatory, audit, and assurance activities related to secure-development and software supply-chain practices.
NIST’s Secure Software Development Framework (SSDF), documented in NIST SP 800-218, provides a practical foundation for secure-development practices across organizational preparation, software protection, secure production, and vulnerability response.
Free · no signup
Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.
No spam. Just jobs and resources.
Why people use ASAI
Scored, not searched. Every role ranked against your actual profile.
Alerts as often as hourly. Reach new roles while the pile is still small.
Skill gaps, spelled out. See exactly which requirements you don't meet yet.
Verified jobs, only. Say no to ghost jobs. Your time deserves respect.
Keep browsing