Director of Software Security

Posted 8 Days Ago
Be an Early Applicant
San Jose, CA, USA
In-Office
165K-306K Annually
Expert/Leader
Artificial Intelligence • Cloud • Hardware • Software • Semiconductor
The Role
Lead enterprise AppSec and DevSecOps strategy, secure software architecture, and compliance (CMMC, NIST, ISO). Drive secure SDLC, CI/CD integration, cloud/container security, vulnerability management, software supply chain integrity, and report security posture to executives while managing AppSec and DevSecOps teams.
Summary Generated by Built In
At Cadence, we hire and develop leaders and innovators who want to make an impact on the world of technology.

Cadence InfoSec is seeking a Director of Software Security to lead the strategy, architecture, and execution of secure software development practices across the enterprise. This role will drive DevSecOps transformation, ensure compliance with regulatory frameworks (including CMMC), and embed security throughout the software lifecycle (SDLC).

Key Responsibilities

DevSecOps Strategy & Leadership

  • Define and execute enterprise DevSecOps strategy across all development teams

  • Integrate security controls into CI/CD pipelines (build, test, release)

  • Establish “shift-left” security practices across the SDLC

  • Drive adoption of secure coding, SAST, DAST, and SCA tools

Secure Software Architecture

  • Define reference architectures for secure microservices, APIs, and cloud-native apps

  • Establish security patterns for containers, Kubernetes, and serverless

  • Lead threat modeling initiatives 

  • Ensure secure API design and zero trust principles

Regulatory Compliance & CMMC

  • Lead compliance initiatives for:

    • Cybersecurity Maturity Model Certification (CMMC 2.0)

    • NIST SP 800-171r2 /800-53

    • ISO 27001

  • Ensure software systems meet federal, defense, and privacy regulations

  • Coordinate audits, assessments, and continuous monitoring programs

  • Implement controls for handling Controlled Unclassified Information (CUI)

Cloud & Platform Security

  • Secure DevOps pipelines across cloud platforms:

    • Amazon AWS

    • Microsoft Azure

    • Google Cloud

    • IBMC cloud

    • Cadence software service and products

  • Implement infrastructure-as-code (IaC) security scanning

  • Define secrets management, identity, and access controls

Application Security Program

  • Build and scale AppSec program across all product lines

  • Define vulnerability management lifecycle (discovery → remediation → validation)

  • Establish bug bounty / responsible disclosure programs

  • Integrate security into Agile and CI/CD workflows

Supply Chain & Software Integrity

  • Secure software supply chain (SBOM, dependency scanning)

  • Implement artifact signing, provenance, and integrity validation

Governance & Risk Management

  • Define policies, standards, and secure development guidelines

  • Establish KPIs: vulnerability remediation SLA, code coverage, pipeline security

  • Align software security with enterprise risk management

  • Report posture to executive leadership and board

Leadership & Cross-Functional Influence

  • Lead teams of AppSec engineers, DevSecOps engineers, and architects

  • Partner with Engineering, Product, Legal, and Compliance teams

  • Build security champions program within development teams

  • Influence engineering culture toward security ownership

Required Qualifications

  • 12–15+ years in cybersecurity, with strong focus on application security and DevSecOps

  • 5+ years in leadership (manager/director level)

  • Deep expertise in:

    • Secure SDLC and DevSecOps pipelines

    • Cloud-native architectures and container security

    • Regulatory frameworks (CMMC, NIST, ISO)

  • Experience in regulated industries (defense, government, healthcare, fintech)

Preferred Qualifications

  • Hands-on experience with tools such as:

    • SAST: Checkmarx, Veracode

    • DAST: Burp Suite

    • SCA: Snyk, Black Duck

    • CI/CD: Jenkins, GitHub Actions

  • Familiarity with Kubernetes, Docker, and service mesh security

  • Certifications:

    • CISSP, CSSLP

    • CISM or CCSP

  • Experience with Zero Trust and identity-first security

Key Skills

  • DevSecOps Transformation

  • Secure Software Architecture

  • Regulatory Compliance (CMMC, NIST, ISO)

  • Application Security & Threat Modeling

  • Software Supply Chain Security (SBOM, SLSA)

  • Cloud & Container Security

  • Executive Communication & Strategy

The annual salary range for California is $164,500 to $305,500. You may also be eligible to receive incentive compensation: bonus, equity, and benefits. Sales positions generally offer a competitive On Target Earnings (OTE) incentive compensation structure. Please note that the salary range is a guideline and compensation may vary based on factors such as qualifications, skill level, competencies and work location. Our benefits programs include: paid vacation and paid holidays, 401(k) plan with employer match, employee stock purchase plan, a variety of medical, dental and vision plan options, and more.

We’re doing work that matters. Help us solve what others can’t.

Skills Required

  • 12-15+ years in cybersecurity with strong focus on application security and DevSecOps
  • 5+ years in leadership (manager/director level)
  • Deep expertise in secure SDLC and DevSecOps pipelines
  • Deep expertise in cloud-native architectures and container security
  • Expertise with regulatory frameworks (CMMC, NIST SP 800-171/800-53, ISO 27001)
  • Experience in regulated industries (defense, government, healthcare, fintech)
  • Hands-on experience with SAST, DAST, and SCA tools (Checkmarx, Veracode, Burp Suite, Snyk, Black Duck)
  • Familiarity with CI/CD tools and pipelines (Jenkins, GitHub Actions)
  • Familiarity with Kubernetes, Docker, and service mesh security
  • Relevant certifications (CISSP, CSSLP, CISM, CCSP)

Cadence Design Systems Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Cadence Design Systems and has not been reviewed or approved by Cadence Design Systems.

  • Equity Value & Accessibility A discounted ESPP with a lookback feature and equity included in total compensation make ownership broadly accessible and potentially meaningful. Structured compensation at an industry leader adds predictability to equity participation.
  • Healthcare Strength Medical, dental, and vision coverage are described as solid, with mental‑health/EAP and fertility support enhancing the offering. The breadth across core care and family‑building needs strengthens the healthcare package.
  • Leave & Time Off Breadth Global Recharge Days, volunteer time off, and companywide breaks indicate a comprehensive time‑off framework. In addition, many salaried roles are described as having flexible or generous PTO policies.

Cadence Design Systems Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Jose, CA
8,216 Employees
Year Founded: 1988

What We Do

Cadence enables electronic systems and semiconductor companies to create the innovative end products that are transforming the way people live, work and play. Cadence® software, hardware and IP are used by customers to deliver products to market faster. The company's Intelligent System Design strategy helps customers develop differentiated products—from chips to boards to intelligent systems—in mobile, consumer, cloud, data center, automotive, aerospace, IoT, industrial and other market segments. Cadence is listed as one of Fortune Magazine's 100 Best Companies to Work For.

Similar Jobs

YCharts Logo YCharts

Enterprise Account Executive

Cloud • Fintech • Software • Financial Services
Remote or Hybrid
United States
142 Employees
100K-260K Annually
Hybrid
5 Locations
289097 Employees
Hybrid
2 Locations
289097 Employees
Easy Apply
Hybrid
3 Locations
4405 Employees
240K-305K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account