Head of Application Security

Opens analogdevices.wd1.myworkdayjobs.com in a new tab

What You'll Do

  • Lead the strategy, build-out, and operation of ADI’s application security, AI security, and product security capabilities, including: Application Security (DevSecOps) : Establish and mature secure software development lifecycle (secure-SDLC) policy, standards, reference architectures, and tooling (SAST, SCA, DAST, secret scanning); harden the software supply chain – source repositories, Continuous Integration / Continuous Delivery/Deployment (CI/CD) pipelines, build systems, credentials, and dependencies – and drive software bill of materials (SBOM) generation and trusted-publishing at scale.
  • AI Security : Define and operate a risk-managed AI security and governance program aligned to recognized frameworks (e.g., NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, MITRE ATLAS), beginning with generative AI and LLM controls, and operations, and extending to secure agentic AI use cases including non-human / agent identity, action guardrails, and human-in-the-loop controls.
  • Product Security : Grow a company-wide, risk-managed product security practice anchored to a secure product development lifecycle standard (e.g., IEC 62443-4-1) and embedded into the New Product Introduction (NPI) process; own and mature ADI’s Product Security Incident Response Team (PSIRT) capability, coordinated vulnerability disclosure, CVE/CVSS practice, and SBOM/HBOM strategy for shipped firmware and hardware.
  • Serve as a trusted strategic advisor to the CISO, executive leadership, and the Board of Directors – translating complex application, AI, and product security exposure into clear, quantified business, customer, and financial impact, and shaping the narrative around key security decisions, priorities, and tradeoffs.
  • Build, lead, and develop a high-performing, multidisciplinary team; make deliberate build / borrow / buy decisions and cultivate a broad network of security champions embedded across engineering and the business units.
  • Champion a security-by-design, paved-road culture in which the secure path is the fast path – earning adoption from engineering and improving velocity while reducing risk, with measurable coverage, adoption, and risk-burndown reporting.
  • Align application, AI, and product security to the regulatory and customer requirements that govern ADI’s markets – including automotive (ISO/SAE 21434, ISO 26262), aerospace and defense (ITAR/EAR, CMMC), healthcare (IEC 62304, FDA cybersecurity guidance), and industrial (IEC 62443) – and support customer-facing trust, audits, and attestations.
  • Integrate application, AI, and product security risk into ADI’s enterprise risk model, establish and chair cross-functional governance with a clear risk-acceptance and exception process, and report posture, key risk indicators, and program progress to executive and Board-level audiences.
  • Lead response to significant application, AI, or product security incidents, including decision-making, regulatory engagement, external communications, and post-incident learning.
  • Operate with a high degree of autonomy in a fast-paced, evolving environment; identify opportunities to improve how ADI secures its software, AI, and products, and establish scalable standards and best practices.
  • Lead and scale a high-performing multidisciplinary organization across application, AI, and product security, establishing the structure, priorities, and accountability needed to deliver impactful enterprise security outcomes for ADI Build a strong talent bench by attracting, developing, and retaining top security talent, strengthening leadership capability, and fostering a collaborative culture of agility, ownership, and continuous improvement Serves as a credible, trusted partner to internal stakeholders and engineering teams, ensuring security standards enable delivery, strengthen product trust, and support ADI’s innovation and growth priorities Required Qualifications Bachelor’s degree required, preferably in Engineering, Computer Science, Cybersecurity, or a related technical field (or equivalent experience). 15+ years of progressive cybersecurity experience, including significant experience in a senior security leadership role (e.g., Deputy CISO, CISO, or a Senior Director/Executive Director leading application, product, or AI security) in a large-scale, complex environment. 15+ years of sponsoring and managing complex programs and projects.
  • A breathe of program delivery across application delivery, product and cybersecurity is preferred.
  • Proven experience building, leading, and scaling security functions across large, global engineering organizations, with a track record of building high-performing teams and sustaining engagement through organizational change.
  • Deep expertise establishing secure-SDLC / DevSecOps programs and embedding automated security testing (SAST/SCA/DAST/secret scanning) into CI/CD pipelines, with hands-on understanding of software supply-chain security, threat modeling, and secure code / design review.
  • Working knowledge of AI/GenAI security and governance frameworks and controls – including model risk, data leakage, prompt-injection defense, and AI incident response – and familiarity with the emerging risks of agentic AI.
  • Experience with product security, PSIRT / coordinated vulnerability disclosure, and SBOM / software-supply-chain transparency, and the ability to interpret and map requirements from security and safety frameworks relevant to ADI’s markets (e.g., IEC 62443, ISO/SAE 21434, ISO 26262, IEC 62304, NIST CSF, CMMC, ITAR/EAR).
  • Demonstrated ability to translate highly complex technical risk into clear, quantified, business-focused terms (e.g., FAIR or equivalent) and communicate to both technical and non-technical audiences, including executives and the Board.
  • Strong executive presence and stakeholder-management skills, with experience working directly with senior leadership and influencing across organizational boundaries.
  • Demonstrated ability to operate with significant autonomy, navigate ambiguity, and balance strategic thinking with hands-on execution in a dynamic, fast-paced environment.
  • Ideal Qualifications Advanced degree and relevant certifications (e.g., CISSP, CISM).
  • Experience in the semiconductor, electronics, or advanced-hardware industry, or in another regulated, IP-intensive, or critical-infrastructure-adjacent environment (e.g., aerospace/defense, automotive, medical devices, or life sciences).
  • Experience operating in export-controlled and regulated environments (e.g., ITAR/EAR, CMMC).
  • Experience standing up a new security capability or function from the ground up, including establishing governance, standards, and scalable operating models across a large organization.
  • Experience supporting Board-level communications, enterprise risk reviews, or executive decision forums on cybersecurity posture and strategy.
  • For positions requiring access to technical data, Analog Devices, Inc. may have to obtain export licensing approval from the U.S.
  • Department of Commerce - Bureau of Industry and Security and/or the U.S.
  • Department of State - Directorate of Defense Trade Controls.
  • As such, applicants for this position – except US Citizens, US Permanent Residents, and protected individuals as defined by 8 U.S.C. 1324b(a)(3) –

Sourced directly from Analog Devices’s career page

Your application goes straight to Analog Devices.

Analog Devices logo

Analog Devices

US, MA, Wilmington

Specialisation
Open roles at Analog Devices
985 positions
Job ID
/job/US-MA-Wilmington/Head-of-Application-Security_R265247

Get matched to roles like this

Upload your resume once. We’ll notify you when matching roles open up.

Join talent pool — free

Similar Other roles