{"id":1946537,"url":"https://alion.io/job/altera-devsecops-and-aiautomation-engineer","title":"DevSecOps and AI/Automation Engineer","company":{"id":5328,"name":"Altera","domain":"altera.com","url":"https://alion.io/company/altera","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"A","score":89,"open_postings":15,"ghost_share":0,"stale_share":0.2,"repost_share":0.067,"time_to_fill_p50_days":71,"computed_at":"2026-10-10T05:45:15Z"}},"role":"AI/ML","role_family":"AI/ML","seniority":"senior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["San Jose, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":149100,"max":215925,"currency":"USD","period":"year","gross":null,"usd_annual":215925},"salary_estimate":null,"experience_years_min":6,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Azure DevOps","optional":false},{"name":"CI/CD","optional":false},{"name":"Configuration Management","optional":false},{"name":"GitHub","optional":false},{"name":"GitLab","optional":false},{"name":"Jenkins","optional":false},{"name":"Jira","optional":false},{"name":"Kubernetes","optional":false},{"name":"ServiceNow","optional":false},{"name":"Threat Modeling","optional":false},{"name":"ArgoCD","optional":true},{"name":"Bitbucket","optional":true},{"name":"Burp Suite","optional":true},{"name":"Checkmarx","optional":true},{"name":"CodeQL","optional":true},{"name":"Fortify","optional":true},{"name":"GitHub Actions","optional":true},{"name":"GitLab CI","optional":true},{"name":"IAM","optional":true},{"name":"Invicti","optional":true},{"name":"Mend","optional":true},{"name":"NIST CSF","optional":true},{"name":"OWASP","optional":true},{"name":"OWASP ASVS","optional":true},{"name":"OWASP SAMM","optional":true},{"name":"OWASP Top 10","optional":true},{"name":"OWASP ZAP","optional":true},{"name":"PKI","optional":true},{"name":"Power BI","optional":true},{"name":"PowerShell","optional":true},{"name":"Python","optional":true},{"name":"Rest API","optional":true},{"name":"SBOM","optional":true},{"name":"Semgrep","optional":true},{"name":"SLSA","optional":true},{"name":"Snyk","optional":true},{"name":"SonarQube","optional":true},{"name":"Tableau","optional":true},{"name":"Veracode","optional":true}],"status":"live","first_seen_at":"2026-10-05T00:00:00Z","employer_posted_date":"2026-10-05","last_verified_at":"2026-10-10T22:35:24Z","board_verified":true,"closed_at":null,"days_open":6,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":6},"description":"Job Details:\nJob Description:\nPosition Summary\nThe AppSec / DevSecOps Engineer will help strengthen application and software supply chain security across a global semiconductor organization. This role will embed security into the software development lifecycle through secure design, application security assessments, automated security testing, CI/CD security controls, developer enablement, and continuous improvement.\nThe role will support enterprise applications and digital platforms used across business operations, application development, engineering enablement, supply chain, intellectual property, corporate functions, and customer-facing services.\nThe successful candidate will combine application security expertise with practical DevSecOps engineering, automation, risk-based assessment, and strong collaboration with development and technology teams.\nThe Team\nThe Application Security and DevSecOps team helps protect the company’s software, engineering platforms, cloud services, intellectual property, and business applications by embedding security throughout the development lifecycle.\nThe team works across product, application development, IT, cloud, infrastructure, supply chain, corporate technology, and other business functions to improve secure development practices, automate security controls, and reduce application and software supply chain risk.\nResponsibilities:\nSecure SDLC Controls\nDefine and maintain secure software development lifecycle standards, procedures, control requirements, and developer guidance. \nEmbed security requirements across planning, architecture, design, coding, testing, release, deployment, and operations. \nDevelop security gates based on application risk, data sensitivity, business criticality, and deployment model. \nSupport secure architecture reviews, threat modeling, security requirements definition, and go-live risk assessments. \nEstablish secure coding standards for common programming languages, frameworks, APIs, cloud services, and development patterns. \nTrack security findings, remediation commitments, exceptions, compensating controls, and risk acceptance decisions. \nMeasure improvements in secure SDLC adoption, remediation timeliness, control coverage, and recurring vulnerability reduction. \nDevSecOps Tooling, Standards, and Operations\nImplement and operate SAST, DAST, software composition analysis, secrets detection, container scanning, API security, and infrastructure-as-code scanning. \nIntegrate security tooling into CI/CD pipelines using standardized patterns, APIs, plugins, connectors, and workflow automation. \nConfigure security gates, severity thresholds, suppression processes, exception workflows, and escalation paths. \nMonitor tool health, scan coverage, pipeline failures, vulnerability backlogs, critical findings, and remediation performance. \nTune security tooling to improve finding accuracy, reduce false positives, and minimize unnecessary development disruption. \nEstablish processes for tool onboarding, configuration management, testing, upgrades, support, and retirement. \nDevelop reusable integrations, scripts, dashboards, reference implementations, and automation assets. \nSupport AI-assisted vulnerability triage, remediation recommendations, validation, and security workflow automation where appropriate. \nApplication Security Assessments\nPerform application security assessments across web applications, APIs, microservices, mobile applications, cloud services, developer platforms, and engineering systems. \nConduct threat modeling, secure design reviews, architecture assessments, code reviews, vulnerability analysis, and penetration-test coordination. \nAssess enterprise and business-critical applications, including web applications, APIs, cloud services, developer platforms, source code repositories, product lifecycle systems, supply chain platforms, and intellectual property systems. \nIdentify vulnerabilities, attack paths, insecure dependencies, authentication weaknesses, authorization issues, exposed secrets, and data protection risks. \nTranslate findings into practical remediation plans with severity, business impact, recommended actions, owners, and due dates. \nValidate remediation through retesting, automated verification, evidence review, or compensating-control assessment. \nMaintain application security risk registers and report material risks, aging findings, exceptions, and residual exposure. \nSupport security reviews for major application changes, cloud migrations, acquisitions, third-party platforms, and new technologies. \nCloud Secure Development Pipeline\nSupport secure development and deployment practices across Microsoft Azure, AWS, and hybrid environments. \nAssess cloud-native services, containers, Kubernetes, serverless workloads, APIs, infrastructure-as-code, and CI/CD pipelines. \nImplement controls for open-source dependencies, software bills of materials, artifact integrity, code signing, build security, secrets protection, and software provenance. \nPartner with Cloud Engineering and DevOps teams to embed security checks into infrastructure provisioning and deployment workflows. \nIdentify and remediate vulnerable dependencies, exposed secrets, insecure configurations, and compromised build components. \nContribute to secure cloud application standards, reference architectures, and DevSecOps patterns. \nDeveloper Enablement and Collaboration\nPartner with software developers, architects, DevOps engineers, product owners, cloud teams, infrastructure teams, and enterprise technology organizations. \nProvide practical guidance on secure coding, authentication, authorization, API security, secrets management, dependency risk, and cloud-native security. \nDevelop training, workshops, office hours, knowledge articles, remediation playbooks, and secure coding guidance. \nSupport developers in interpreting scan results and resolving complex or recurring vulnerabilities. \nContribute to security champion programs and communities of practice. \nPromote security-by-design while enabling efficient software delivery and engineering productivity. \nMetrics, Reporting, and Continuous Improvement\nDevelop dashboards and reports covering: \nSAST, DAST, SCA, secrets, and IaC scanning coverage \nCritical and high-severity vulnerability aging \nRemediation service-level performance \nCI/CD security-gate adoption \nApplication assessment completion \nException volume and aging \nTool health and scan reliability \nSecure SDLC maturity \nDeveloper training and adoption \nConduct quality reviews of assessment reports, scan results, remediation evidence, exceptions, and control performance. \nIdentify improvements in automation, data quality, developer experience, tool effectiveness, and program maturity. \nIndividual Contributor Expectations\nIndependently own assigned AppSec, DevSecOps, tooling, assessment, and remediation workstreams. \nDeliver high-quality technical analysis, documentation, automation, and recommendations with limited supervision. \nBuild reusable security engineering assets and share knowledge across development and security teams. \nManage workstream priorities, risks, dependencies, deliverables, and stakeholder expectations. \nExercise sound judgment when evaluating vulnerabilities, exceptions, compensating controls, and business risk. \nMentor developers and security practitioners through technical guidance, workshops, code reviews, and knowledge sharing. \nMaintain current knowledge of application security threats, cloud technologies, development practices, and security tooling. \nPromote a practical, collaborative, and outcomes-focused security culture. \nWhat Success Looks Like\nDuring the first six to twelve months, you will be expected to:\nEstablish consistent secure SDLC control requirements across priority development and engineering organizations. \nIncrease adoption of SAST, DAST, SCA, secrets detection, container, and IaC scanning within approved CI/CD pipelines. \nImprove remediation timeliness for critical and high-severity application security findings. \nReduce false positives and improve the actionability of automated security findings. \nComplete prioritized application security assessments and threat models for critical business and enterprise applications. \nImprove coverage of cloud, container, API, and software supply chain security controls. \nDeliver reusable automation, integrations, standards, and developer guidance. \nEstablish reliable AppSec metrics, dashboards, exception processes, and reporting. \nStrengthen collaboration between security, development, cloud, infrastructure, engineering, and product teams. \nSalary Range\nThe pay range below is for Bay Area California only. Actual salary may vary based on a number of factors including job location, job-related knowledge, skills, experiences, trainings, etc. We also offer incentive opportunities that reward employees based on individual and company performance.\n$149,100 - $215,925 USD\nWe use artificial intelligence to screen, assess, or select applicants for the position. Applicants must be eligible for any required U.S. export authorizations.\nQualifications:\nMinimum Qualifications\nBachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, Information Systems, or a related technical discipline; equivalent experience may be considered. \n6+ years of professional experience in AppSec, DevSecOps, secure SDLC, cloud security, cybersecurity engineering, software security, or a related discipline. \nHands-on experience with secure SDLC, application security, secure-by-design, or DevSecOps activities. \nExperience with CI/CD or modern software engineering environments. \nExperience with at least three of the following: SAST, DAST, SCA, secrets scanning, IaC scanning, container security, API security, threat modeling, or vulnerability management. \nExperience translating cybersecurity policies, standards, or control requirements into technical controls, engineering requirements, security procedures, or SDLC workflows. \nExperience with at least one cloud or cloud-native environment, including Microsoft Azure, AWS, Kubernetes, or container-based application environments. \nExperience using engineering, security workflow, or automation platforms such as Azure DevOps, GitHub, GitLab, Jenkins, Jira, or ServiceNow. \nAbility to conduct or support application security assessments and communicate findings to technical and nontechnical stakeholders. \nStrong written and verbal communication skills, attention to detail, and ability to manage multiple priorities. \nAbility to work independently and collaborate effectively across geographically distributed teams. \nPreferred Qualifications\nExperience supporting complex global, high-technology, regulated, or intellectual-property-intensive organizations. \nExperience securing enterprise applications, developer platforms, cloud services, source code repositories, business-critical systems, product lifecycle platforms, or intellectual property systems. \nExperience with Checkmarx, Fortify, Veracode, Semgrep, GitHub Advanced Security, CodeQL, SonarQube, Snyk, Mend, Black Duck, or comparable tools. \nExperience with Burp Suite, OWASP ZAP, Invicti, or comparable DAST and API security tools. \nExperience securing containers, Kubernetes, serverless applications, APIs, and infrastructure-as-code. \nExperience with Azure DevOps, GitHub Actions, GitLab CI/CD, Jenkins, Bitbucket, Argo CD, or comparable platforms. \nFamiliarity with OWASP Top 10, OWASP ASVS, OWASP SAMM, NIST SSDF, BSIMM, SLSA, CIS Controls, or similar frameworks. \nExperience with SBOM, software provenance, artifact integrity, code signing, PKI, HSM, or dependency governance. \nExperience developing application security dashboards, key risk indicators, key performance indicators, and executive reporting. \nExperience with AI-enabled cybersecurity, secure AI development, or AI-assisted security automation. \nTechnical Skills and Technologies\nApplication Security: Thre...","description_format":"text","description_chars":14306,"description_truncated":true,"requirements":{"experience_years_min":6,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["DevSecOps","Processors, MCUs & AI Chips","Application Security"],"lifecycle":[{"event":"open","at":"2026-10-06T07:20:43Z"}],"visa":[{"country":"US","licensed_sponsor":true,"evidence":"H-1B filings in 12 months: 71","filings_12m":71,"filings_prev_12m":39,"green_card_filings_12m":0,"median_offered_wage_usd":157500,"route":null,"cap_exempt":false,"checked_at":"2026-10-03T21:08:04+00:00","sources":["US Department of Labor: LCA disclosure data (H-1B, H-1B1, E-3)"],"filings_for_role_12m":8}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":5,"expected_fill_days":71,"reasons":["conf:5","velocity","win:early","comp:brand"],"computed_at":"2026-10-10T05:45:15Z"},"pay":{"stated_usd_annual":215925,"is_top_pay":true},"html_url":"https://alion.io/job/altera-devsecops-and-aiautomation-engineer","json_url":"https://alion.io/job/altera-devsecops-and-aiautomation-engineer.json","meta":{"generated_at":"2026-10-11T00:50:02Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1105,"day_limit":5000,"remaining_today":3895,"minute_limit":60,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":5328},"rest":"https://alion.io/mcp/rest/get_company?id=5328"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Faltera-devsecops-and-aiautomation-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Faltera-devsecops-and-aiautomation-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Faltera-devsecops-and-aiautomation-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/altera-devsecops-and-aiautomation-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Faltera-devsecops-and-aiautomation-engineer"}]}