4 hours ago
Base Salary
$143k - $214k/yr
Responsibilities
- Establish and improve company-wide secure SDLC policies, standards, control objectives, procedures, and evidence requirements.
- Assess engineering, source-control, CI/CD, build, and release maturity and lead improvement roadmaps.
- Implement and operationalize SAST, DAST, SCA, secrets detection, infrastructure-as-code, container, image, API, and cloud-native security controls.
- Partner with developers to identify, prioritize, remediate, and verify application-security findings.
- Lead threat modeling, security requirements definition, secure design reviews, and architecture reviews for high-risk applications and changes.
- Establish risk-based vulnerability management, remediation objectives, risk acceptance, escalation, and exception-management processes.
- Manage third-party, open-source, and transitive dependency risks, including software composition and license governance.
- Mature software supply-chain security through SBOMs, VEX, provenance, signing, artifact verification, trusted promotion, and secure repositories.
- Partner with DevOps and platform engineering to secure CI/CD pipelines, build environments, source repositories, registries, and deployment workflows.
- Support vulnerability intake, coordinated disclosure, security advisories, CVE triage, and product-security incident response.
- Create and lead a security champions program with training, office hours, secure-coding guidance, and developer tools.
- Produce executive-ready metrics and reporting and support customer, regulatory, audit, and assurance activities.
Requirements
- 7+ years of experience in application security, product security, DevSecOps, secure software engineering, cybersecurity engineering, or a closely related field.
- Experience designing, implementing, or maturing secure SDLC or application-security programs across multiple engineering teams.
- Strong knowledge of secure coding, application-security testing, vulnerability management, software delivery, and DevSecOps principles.
- Experience working directly with developers to explain findings, guide remediation, and improve secure-development practices.
- Hands-on experience with SAST, DAST, SCA, dependency vulnerability management, secrets scanning, and related security tooling.
- Experience integrating security controls into source-control, CI/CD, build, release, and deployment workflows.
- Experience performing or facilitating threat modeling, security design and architecture reviews, or security requirements definition.
- Knowledge of application-security risks including authentication, authorization, API security, insecure deserialization, injection, insecure dependencies, secrets exposure, and business-logic vulnerabilities.
- Experience with SBOMs, dependency provenance, build integrity, artifact signing, release attestations, and secure artifact management.
- Experience with open-source software risk management, transitive dependencies, license obligations, and governance processes.
- Familiarity with NIST SP 800-218/SSDF, OWASP SAMM, SLSA, or comparable frameworks.
- Ability to read and assess production code and scripts in one or more modern programming languages.
- Strong written and verbal communication skills for explaining technical risk and tradeoffs to technical and nontechnical stakeholders.
- Preferred experience includes SLSA, signed attestations, VEX, CSAF, SPDX, CycloneDX, cloud-native applications, containers, Kubernetes, APIs, microservices, infrastructure-as-code, and security platforms.
- Preferred tools experience includes Snyk, Checkmarx, Veracode, GitHub Advanced Security, GitLab security tools, Semgrep, SonarQube, OWASP ZAP, Burp Suite, Mend, or Black Duck.
- Preferred experience includes NIST SP 800-171, NIST SP 800-53, CMMC, FedRAMP, ISO 27001, SOC 2, regulated environments, and relevant security certifications.
Benefits
- Full-time regular employees receive pay within the listed range, bonus, benefits, and equity; the posting does not provide a specific salary amount.
- Temporary employees receive pay within the listed range and a temporary benefits package applicable after 60 days of employment.
- Offers are contingent on a cleared background and possible reference check.
- Military fellows and part-time employees are not eligible for benefits.
- Shield AI is an equal opportunity and affirmative action employer and provides accommodation support for disabilities or special needs.
Tech Stack
KubernetesSonarQube
Categories
About Shield AI
Shield AI builds autonomous systems for military and national security customers, combining its Hivemind autonomy software with V-BAT and X-BAT unmanned aircraft and Aechelon simulation technologies. The privately held company sells hardware, software, and related services to U.S. and allied defense agencies. Founded in 2015 and headquartered in San Diego, it operates across the U.S., Europe, the Middle East, and Asia-Pacific, and its technology is used in operational deployments.
