1,419,246open jobs
82,989companies
210,832added this week
Browse all
Salary
$149k – $216k per year
Location
In office (San Jose)
Seniority
Senior · 6+ years exp
Visa
H-1B filings in 12 months: 71 · for this role: 8
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 9, 2026. First seen by Alion on Oct 5, 2026. Altera scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Altera is an American programmable logic company whose field programmable gate array business was founded in 1983, acquired by Intel in 2015 and separated again as a standalone company in 2025 when the private equity firm Silver Lake took a majority stake. It designs FPGAs and structured application specific integrated circuits used where a design must be reconfigurable after manufacture, which makes them common in communications infrastructure, industrial control, automotive, aerospace, defence and test equipment. Headquartered in San Jose, the company sells its Agilex and Cyclone device families alongside the Quartus design software engineers use to program them.

Job Details:

Job Description:

Position Summary

The AppSec / DevSecOps Engineer will help strengthen application and software supply chain security across a global semiconductor organization. This role will embed security into the software development lifecycle through secure design, application security assessments, automated security testing, CI/CD security controls, developer enablement, and continuous improvement.

The role will support enterprise applications and digital platforms used across business operations, application development, engineering enablement, supply chain, intellectual property, corporate functions, and customer-facing services.

The successful candidate will combine application security expertise with practical DevSecOps engineering, automation, risk-based assessment, and strong collaboration with development and technology teams.

The Team

The Application Security and DevSecOps team helps protect the company’s software, engineering platforms, cloud services, intellectual property, and business applications by embedding security throughout the development lifecycle.

The team works across product, application development, IT, cloud, infrastructure, supply chain, corporate technology, and other business functions to improve secure development practices, automate security controls, and reduce application and software supply chain risk.

Responsibilities:

Secure SDLC Controls

  • Define and maintain secure software development lifecycle standards, procedures, control requirements, and developer guidance.
  • Embed security requirements across planning, architecture, design, coding, testing, release, deployment, and operations.
  • Develop security gates based on application risk, data sensitivity, business criticality, and deployment model.
  • Support secure architecture reviews, threat modeling, security requirements definition, and go-live risk assessments.
  • Establish secure coding standards for common programming languages, frameworks, APIs, cloud services, and development patterns.
  • Track security findings, remediation commitments, exceptions, compensating controls, and risk acceptance decisions.
  • Measure improvements in secure SDLC adoption, remediation timeliness, control coverage, and recurring vulnerability reduction.

DevSecOps Tooling, Standards, and Operations

  • Implement and operate SAST, DAST, software composition analysis, secrets detection, container scanning, API security, and infrastructure-as-code scanning.
  • Integrate security tooling into CI/CD pipelines using standardized patterns, APIs, plugins, connectors, and workflow automation.
  • Configure security gates, severity thresholds, suppression processes, exception workflows, and escalation paths.
  • Monitor tool health, scan coverage, pipeline failures, vulnerability backlogs, critical findings, and remediation performance.
  • Tune security tooling to improve finding accuracy, reduce false positives, and minimize unnecessary development disruption.
  • Establish processes for tool onboarding, configuration management, testing, upgrades, support, and retirement.
  • Develop reusable integrations, scripts, dashboards, reference implementations, and automation assets.
  • Support AI-assisted vulnerability triage, remediation recommendations, validation, and security workflow automation where appropriate.

Application Security Assessments

  • Perform application security assessments across web applications, APIs, microservices, mobile applications, cloud services, developer platforms, and engineering systems.
  • Conduct threat modeling, secure design reviews, architecture assessments, code reviews, vulnerability analysis, and penetration-test coordination.
  • Assess enterprise and business-critical applications, including web applications, APIs, cloud services, developer platforms, source code repositories, product lifecycle systems, supply chain platforms, and intellectual property systems.
  • Identify vulnerabilities, attack paths, insecure dependencies, authentication weaknesses, authorization issues, exposed secrets, and data protection risks.
  • Translate findings into practical remediation plans with severity, business impact, recommended actions, owners, and due dates.
  • Validate remediation through retesting, automated verification, evidence review, or compensating-control assessment.
  • Maintain application security risk registers and report material risks, aging findings, exceptions, and residual exposure.
  • Support security reviews for major application changes, cloud migrations, acquisitions, third-party platforms, and new technologies.

Cloud Secure Development Pipeline

  • Support secure development and deployment practices across Microsoft Azure, AWS, and hybrid environments.
  • Assess cloud-native services, containers, Kubernetes, serverless workloads, APIs, infrastructure-as-code, and CI/CD pipelines.
  • Implement controls for open-source dependencies, software bills of materials, artifact integrity, code signing, build security, secrets protection, and software provenance.
  • Partner with Cloud Engineering and DevOps teams to embed security checks into infrastructure provisioning and deployment workflows.
  • Identify and remediate vulnerable dependencies, exposed secrets, insecure configurations, and compromised build components.
  • Contribute to secure cloud application standards, reference architectures, and DevSecOps patterns.

Developer Enablement and Collaboration

  • Partner with software developers, architects, DevOps engineers, product owners, cloud teams, infrastructure teams, and enterprise technology organizations.
  • Provide practical guidance on secure coding, authentication, authorization, API security, secrets management, dependency risk, and cloud-native security.
  • Develop training, workshops, office hours, knowledge articles, remediation playbooks, and secure coding guidance.
  • Support developers in interpreting scan results and resolving complex or recurring vulnerabilities.
  • Contribute to security champion programs and communities of practice.
  • Promote security-by-design while enabling efficient software delivery and engineering productivity.

Metrics, Reporting, and Continuous Improvement

  • Develop dashboards and reports covering:
  • SAST, DAST, SCA, secrets, and IaC scanning coverage
  • Critical and high-severity vulnerability aging
  • Remediation service-level performance
  • CI/CD security-gate adoption
  • Application assessment completion
  • Exception volume and aging
  • Tool health and scan reliability
  • Secure SDLC maturity
  • Developer training and adoption
  • Conduct quality reviews of assessment reports, scan results, remediation evidence, exceptions, and control performance.
  • Identify improvements in automation, data quality, developer experience, tool effectiveness, and program maturity.

Individual Contributor Expectations

  • Independently own assigned AppSec, DevSecOps, tooling, assessment, and remediation workstreams.
  • Deliver high-quality technical analysis, documentation, automation, and recommendations with limited supervision.
  • Build reusable security engineering assets and share knowledge across development and security teams.
  • Manage workstream priorities, risks, dependencies, deliverables, and stakeholder expectations.
  • Exercise sound judgment when evaluating vulnerabilities, exceptions, compensating controls, and business risk.
  • Mentor developers and security practitioners through technical guidance, workshops, code reviews, and knowledge sharing.
  • Maintain current knowledge of application security threats, cloud technologies, development practices, and security tooling.
  • Promote a practical, collaborative, and outcomes-focused security culture.

What Success Looks Like

During the first six to twelve months, you will be expected to:

  • Establish consistent secure SDLC control requirements across priority development and engineering organizations.
  • Increase adoption of SAST, DAST, SCA, secrets detection, container, and IaC scanning within approved CI/CD pipelines.
  • Improve remediation timeliness for critical and high-severity application security findings.
  • Reduce false positives and improve the actionability of automated security findings.
  • Complete prioritized application security assessments and threat models for critical business and enterprise applications.
  • Improve coverage of cloud, container, API, and software supply chain security controls.
  • Deliver reusable automation, integrations, standards, and developer guidance.
  • Establish reliable AppSec metrics, dashboards, exception processes, and reporting.
  • Strengthen collaboration between security, development, cloud, infrastructure, engineering, and product teams.

Salary Range

The pay range below is for Bay Area California only. Actual salary may vary based on a number of factors including job location, job-related knowledge, skills, experiences, trainings, etc. We also offer incentive opportunities that reward employees based on individual and company performance.

$149,100 - $215,925 USD

We use artificial intelligence to screen, assess, or select applicants for the position. Applicants must be eligible for any required U.S. export authorizations.

Qualifications:

Minimum Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, Information Systems, or a related technical discipline; equivalent experience may be considered.
  • 6+ years of professional experience in AppSec, DevSecOps, secure SDLC, cloud security, cybersecurity engineering, software security, or a related discipline.
  • Hands-on experience with secure SDLC, application security, secure-by-design, or DevSecOps activities.
  • Experience with CI/CD or modern software engineering environments.
  • Experience with at least three of the following: SAST, DAST, SCA, secrets scanning, IaC scanning, container security, API security, threat modeling, or vulnerability management.
  • Experience translating cybersecurity policies, standards, or control requirements into technical controls, engineering requirements, security procedures, or SDLC workflows.
  • Experience with at least one cloud or cloud-native environment, including Microsoft Azure, AWS, Kubernetes, or container-based application environments.
  • Experience using engineering, security workflow, or automation platforms such as Azure DevOps, GitHub, GitLab, Jenkins, Jira, or ServiceNow.
  • Ability to conduct or support application security assessments and communicate findings to technical and nontechnical stakeholders.
  • Strong written and verbal communication skills, attention to detail, and ability to manage multiple priorities.
  • Ability to work independently and collaborate effectively across geographically distributed teams.

Preferred Qualifications

  • Experience supporting complex global, high-technology, regulated, or intellectual-property-intensive organizations.
  • Experience securing enterprise applications, developer platforms, cloud services, source code repositories, business-critical systems, product lifecycle platforms, or intellectual property systems.
  • Experience with Checkmarx, Fortify, Veracode, Semgrep, GitHub Advanced Security, CodeQL, SonarQube, Snyk, Mend, Black Duck, or comparable tools.
  • Experience with Burp Suite, OWASP ZAP, Invicti, or comparable DAST and API security tools.
  • Experience securing containers, Kubernetes, serverless applications, APIs, and infrastructure-as-code.
  • Experience with Azure DevOps, GitHub Actions, GitLab CI/CD, Jenkins, Bitbucket, Argo CD, or comparable platforms.
  • Familiarity with OWASP Top 10, OWASP ASVS, OWASP SAMM, NIST SSDF, BSIMM, SLSA, CIS Controls, or similar frameworks.
  • Experience with SBOM, software provenance, artifact integrity, code signing, PKI, HSM, or dependency governance.
  • Experience developing application security dashboards, key risk indicators, key performance indicators, and executive reporting.
  • Experience with AI-enabled cybersecurity, secure AI development, or AI-assisted security automation.

Technical Skills and Technologies

  • Application Security: Threat modeling, secure code review, architecture review, penetration-test coordination, OWASP Top 10, OWASP ASVS, API security, and vulnerability management.
  • Security Testing: SAST, DAST, SCA, secrets detection, IaC scanning, container scanning, fuzzing, and dynamic API testing.
  • CI/CD: Azure DevOps, GitHub Actions, GitLab, Jenkins, Bitbucket, Argo CD, build pipelines, release gates, and deployment automation.
  • Cloud Security: Microsoft Azure, AWS, cloud-native workloads, serverless services, Kubernetes, containers, IAM, logging, and workload protection.
  • Software Supply Chain: SBOM, SLSA, dependency governance, artifact integrity, code signing, software provenance, PKI, and HSM.
  • Automation: Python, PowerShell, Bash, REST APIs, JSON, YAML, webhooks, workflow automation, and security-tool integrations.
  • Platforms: Jira, ServiceNow, Microsoft Power BI, Tableau, GitHub, GitLab, and comparable reporting or workflow platforms.
  • Frameworks: NIST SSDF, NIST CSF, OWASP SAMM, BSIMM, CIS Controls, ISO/IEC 27001, and applicable SOX/ITGC requirements.

Certifications

A relevant certification is preferred but not required. Examples include:

  • Certified Secure Software Lifecycle Professional - CSSLP
  • GIAC Web Application Penetration Tester - GWAPT
  • GIAC Web Application Defender - GWEB
  • Offensive Security Web Expert - OSWE
  • Offensive Security Certified Professional - OSCP
  • Certified Information Systems Security Professional - CISSP
  • Certified Cloud Security Professional - CCSP
  • Microsoft Certified: Cybersecurity Architect Expert
  • AWS Certified Security - Specialty
  • Relevant application security, cloud security, or DevSecOps certification

Equivalent hands-on experience may be considered in lieu of certification.

Job Type:

Regular

Shift:

Shift 1 (United States of America)

Primary Location:

San Jose, California, United States

Additional Locations:

Posting Statement:

All qualified applicants will receive consideration for employment without regard to race, color, religion, religious creed, sex, national origin, ancestry, age, physical or mental disability, medical condition, genetic information, military and veteran status, marital status, pregnancy, gender, gender expression, gender identity, sexual orientation, or any other characteristic protected by local law, regulation, or ordinance.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,419,246 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

AI/ML
Similar stack
Same company
San Jose
$172k – $257k per year • Equity • In office • Full-Time • 6+ years exp • Bachelor's Degree • Boulder
Python
AI/ML
Ray Serve
LoRA
vLLM
AI Agents
SGLang
PEFT
AWS Bedrock
Ray
Machine Learning
DevOps
GCP
CI/CD
AWS
Kubernetes
Apply
$142k – $212k per year • Hybrid • Full-Time • 6+ years exp • Bachelor's Degree • Redwood City
Python
Java
AI/ML
LangGraph
AutoGen
LangChain
Model Context Protocol
Vertex AI
Embeddings
Prompt Engineering
Function Calling
AI Agents
Semantic Kernel
AWS Bedrock
CrewAI
LLM
RAG
Hybrid Search
OpenAI
Anthropic
A2A
Human-in-the-Loop
Context Engineering
Knowledge Graph
LLM Guardrails
Multi-Agent Systems
Tool Use
DevOps
Rest API
GCP
GitHub Actions
Azure
CI/CD
AWS
Apply
AI Engineer 1 day ago
$200k per year • In office • 6+ years exp • Bachelor's Degree • Chicago
Python
AI/ML
Model Context Protocol
Prompt Engineering
Function Calling
AI Agents
LLM
Tool Use
DevOps
Platform Engineering
Apply
AI Engineer 1 day ago
$200k per year • In office • 6+ years exp • Bachelor's Degree • New York
Python
AI/ML
Model Context Protocol
Prompt Engineering
Function Calling
AI Agents
LLM
Tool Use
DevOps
Platform Engineering
Apply
$95k – $159k per year • In office • Full-Time • Philadelphia
Python
Java
Scala
Python
pySpark
Databases
Neo4j
Databricks
ElasticSearch
OpenSearch
AI/ML
Spark
MLFlow
Embeddings
AI Agents
NLP
AWS Bedrock
TensorFlow
PyTorch
LLM
RAG
Semantic Search
OpenAI
Amazon SageMaker
Structured Outputs
Semantic Search
Knowledge Graph
LLM Guardrails
Machine Learning
DevOps
Azure
CI/CD
AWS
Analytics
A/B Testing
Apply
In office • Full-Time • Pune
Python
PowerShell
Bash
DevOps
Terraform
Ansible
Red Hat
OpenShift
Helm
Azure DevOps
GitHub Actions
Prometheus
GitLab CI
Azure
CI/CD
ArgoCD
Jenkins
Git
AWS
Docker
Kubernetes
Grafana
Configuration Management
Bamboo
Amazon EKS
Amazon EC2
Amazon S3
IAM
Amazon CloudWatch
API Gateway
Linux
Management
Agile
Apply
In office • Full-Time • 10+ years exp • George Town
JavaScript
TypeScript
SQL
C#
C#
ASP.NET Core
WPF
Databases
Oracle
Frontend
Angular
React.js
DevOps
Azure DevOps
Azure
CI/CD
Git
Windows
Management
Agile
Scrum
Apply
Lead Data Scientist 3 days ago
≈ $26k – $47k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Bengaluru • Pune • Mumbai • Gurgaon • Noida
Python
SQL
Databases
Snowflake
Weaviate
Databricks
Chroma
Milvus
Pinecone
AI/ML
LangGraph
LangChain
Claude
LlamaIndex
Vertex AI
Fine-tuning
Prompt Engineering
Multimodal AI
AI Agents
Semantic Kernel
Llama
Mistral
AWS Bedrock
CrewAI
Gemini
LLM
RAG
OpenAI
LLMOps
Machine Learning
DevOps
Rest API
GCP
Azure
CI/CD
AWS
Docker
Kubernetes
Apply
≈ $23k – $47k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Bengaluru
DevOps
GCP
Azure
CI/CD
AWS
SLI/SLO/SLA
Management
Agile
Scrum
Kanban
Apply
≈ $9.5k – $28k per year (Estimated) • Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Bengaluru • Hyderabad
JavaScript
SQL
C#
C#
.NET
Databases
MS SQL
AI/ML
Copilot
DevOps
Azure DevOps
Azure
Management
Agile
Apply
$119k – $172k per year • In office • Contractor • 3+ years exp • Bachelor's Degree • San Jose
Python
TypeScript
AI/ML
Fine-tuning
Embeddings
Prompt Engineering
AI Agents
LLM
RAG
Semantic Search
OpenAI
Semantic Search
Knowledge Graph
Recommender Systems
Machine Learning
DevOps
Rest API
GCP
Azure
AWS
Docker
Kubernetes
Analytics
A/B Testing
Apply
AI Automation Intern 21 days ago
In office • Internship • Bachelor's Degree • Bengaluru
Python
JavaScript
SQL
AI/ML
Prompt Engineering
AI Agents
RAG
DevOps
Git
GitHub
Management
n8n
Zapier
Power Automate
Apply
AI Engineer 30 days ago
In office • Full-Time • 1+ year exp • Bachelor's Degree • Shanghai
Python
Go
C++
Databases
Milvus
FAISS
AI/ML
LangChain
LlamaIndex
Prompt Engineering
AI Agents
LLM
RAG
Edge AI
Apply
≈ $61k – $143k per year (Estimated) • In office • Full-Time • Shanghai
Python
C++
C++
PyTorch C++
AI/ML
LangChain
LlamaIndex
Quantization
AI Agents
PyTorch
LLM
RAG
Hugging Face
Multi-Agent Systems
Apply
$100k – $138k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • San Jose
Python
SQL
DevOps
CI/CD
Analytics
Tableau
Power BI
Looker
Apply
≈ $150k – $449k per year (Estimated) • In office • Internship • Bachelor's Degree • San Jose
Python
C++
C++
TensorFlow C++
PyTorch C++
AI/ML
Reinforcement Learning
Diffusion Models
TensorFlow
PyTorch
LLM
Recommender Systems
Machine Learning
DevOps
Linux
Apply
≈ $153k – $456k per year (Estimated) • In office • Internship • PhD • San Jose
AI/ML
CUDA Toolkit
Embeddings
RLHF
Quantization
Chain-of-Thought
NLP
LLM
CUDA
Triton
DPO
SFT
GRPO
Post-training
Recommender Systems
Speculative Decoding
Agentic Workflows
Apply
≈ $153k – $458k per year (Estimated) • In office • Internship • PhD • San Jose
AI/ML
Multimodal AI
AI Agents
NLP
ML-Agents
Recommender Systems
Machine Learning
Apply
≈ $147k – $439k per year (Estimated) • In office • Internship • PhD • San Jose
Python
Java
C++
AI/ML
Computer Vision
NLP
Machine Learning
Apply
≈ $154k – $461k per year (Estimated) • In office • Internship • PhD • San Jose
Python
C++
C++
PyTorch C++
AI/ML
Reinforcement Learning
Multimodal AI
NLP
Transfer Learning
PyTorch
Contrastive Learning
SFT
Post-training
Pre-training
Recommender Systems
Machine Learning
Apply
See all jobs
This is one of many
1,419,246 more open roles from verified company boards, updated every day.