





Strong brand and metro location increase applicants, but niche DevSecOps governance skills limit qualified candidates.
High — specialized cybersecurity, SSDLC governance, and policy-as-code expertise limits cross-industry transferability.
High — explicit 6+ years plus specific DevSecOps, policy-as-code, CI/CD tooling and governance requirements.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead and improve Secure Software Development Lifecycle (SSDLC) governance and assurance activities including maintaining security requirements, controls, and policies.
Operate and enhance Secure Release Framework by translating security requirements into automated, testable policies integrated with CI/CD pipelines to ensure secure release governance.
Utilize AI tooling and ServiceNow for control automation, risk tracking, reporting, and strengthening security posture across software development processes.
6+ years of experience in cybersecurity, application security, software security, IT risk, or security governance.
Experience with software development lifecycle, Agile methodologies, and continuous integration/continuous deployment (CI/CD) concepts.
Bachelor's degree in computer science, engineering, technical or security discipline, or a security certification such as CompTIA Security+, ISC2 Certified in Cybersecurity, or Associate of ISC2.
Experience with security testing methods (SAST, DAST, software composition analysis), security automation, and AI tooling for governance and documentation.
Experienced in implementing and automating security controls in CI/CD pipelines with policy-as-code tools (e.g., Open Policy Agent/Rego).
Proficient in using governance, risk, and compliance platforms such as ServiceNow, GitHub, Azure DevOps, and security tools like Snyk.
Familiar with secure development frameworks (NIST SSDF, OWASP SAMM/ASVS, Microsoft SDL) and emerging topics like software supply chain security and AI-assisted security governance.