freehire launches on Product Hunt on 26 August.

Follow →

Head of Application Security

Summary

Leads application, AI, and product security for a semiconductor company, embedding security into software development, AI governance, and product lifecycle processes to protect critical systems in automotive, aerospace, healthcare, and industrial markets.

About Analog Devices

Analog Devices, Inc. (NASDAQ: ADI) is a global semiconductor leader that bridges the physical and digital worlds to enable breakthroughs at the Intelligent Edge. ADI combines analog, digital, AI, and software technologies into solutions that combat climate change, reliably connect humans and the world, and help drive advancements in automation and robotics, mobility, healthcare, energy and data centers. With revenue of more than $11 billion in FY25, ADI ensures today's innovators stay Ahead of What's Possible. Learn more at and on LinkedIn and X.

Head of Application Security

The leader of Application, AI and Product Security is a senior leadership role responsible for protecting the software, artificial intelligence, and products at the heart of ADI’s business. Reporting to the Chief Information Security Officer (CISO), this leader ensures that everything ADI builds and ships is secure by design – worthy of the trust of our automotive, aerospace and defense, healthcare, and industrial customers, and resilient against the most capable threat actors. As ADI accelerates at the Intelligent Edge, embedding software, AI, and connectivity into the components the world depends on, this role makes security a competitive advantage.

This role is a “build-and-scale” mandate spanning three connected disciplines. This leader will stand up and mature a developer-first application security (DevSecOps) capability across ADI’s software development lifecycle; establish a risk-managed AI security and governance program covering generative AI, large language models, and emerging agentic AI use cases; and grow a company-wide product security practice – building on ADI’s existing product security incident response and coordinated vulnerability disclosure capabilities – for the products ADI designs, manufactures, and ships. Working across IT, LRO, and the business (Software & Digital Platforms, Engineering Enablement, Global Operations & Technology), the role connects these threads into a single, risk-managed security strategy that drives alignment, informs executive and Board decision-making, and strengthens the resilience and trustworthiness of ADI’s technology.

Sequencing matters in this role. The immediate priority is application security embedded into ADI’s DevOps / CI-CD environment; the near-term priority is a risk-managed AI security program, beginning with generative AI and LLM governance and controls before extending to agentic AI; and the third priority is maturing a full-scope, company-wide product security practice. The leader will establish a disciplined discovery and stakeholder-alignment period before scaling execution across all three.

Key Responsibilities:

Lead the strategy, build-out, and operation of ADI’s application security, AI security, and product security capabilities, including:

  • Application Security (DevSecOps): Establish and mature secure software development lifecycle (secure-SDLC) policy, standards, reference architectures, and tooling (SAST, SCA, DAST, secret scanning); harden the software supply chain – source repositories, Continuous Integration / Continuous Delivery/Deployment (CI/CD) pipelines, build systems, credentials, and dependencies – and drive software bill of materials (SBOM) generation and trusted-publishing at scale.
  • AI Security: Define and operate a risk-managed AI security and governance program aligned to recognized frameworks (e.g., NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, MITRE ATLAS), beginning with generative AI and LLM controls, and operations, and extending to secure agentic AI use cases including non-human / agent identity, action guardrails, and human-in-the-loop controls.
  • Product Security: Grow a company-wide, risk-managed product security practice anchored to a secure product development lifecycle standard (e.g., IEC 62443-4-1) and embedded into the New Product Introduction (NPI) process; own and mature ADI’s Product Security Incident Response Team (PSIRT) capability, coordinated vulnerability disclosure, CVE/CVSS practice, and SBOM/HBOM strategy for shipped firmware and hardware.

Serve as a trusted strategic advisor to the CISO, executive leadership, and the Board of Directors – translating complex application, AI, and product security exposure into clear, quantified business, customer, and financial impact, and shaping the narrative around key security decisions, priorities, and tradeoffs.

Build, lead, and develop a high-performing, multidisciplinary team; make deliberate build / borrow / buy decisions and cultivate a broad network of security champions embedded across engineering and the business units.

Champion a security-by-design, paved-road culture in which the secure path is the fast path – earning adoption from engineering and improving velocity while reducing risk, with measurable coverage, adoption, and risk-burndown reporting.

Align application, AI, and product security to the regulatory and customer requirements that govern ADI’s markets – including automotive (ISO/SAE 21434, ISO 26262), aerospace and defense (ITAR/EAR, CMMC), healthcare (IEC 62304, FDA cybersecurity guidance), and industrial (IEC 62443) – and support customer-facing trust, audits, and attestations.

Integrate application, AI, and product security risk into ADI’s enterprise risk model, establish and chair cross-functional governance with a clear risk-acceptance and exception process, and report posture, key risk indicators, and program progress to executive and Board-level audiences.

Lead response to significant application, AI, or product security incidents, including decision-making, regulatory engagement, external communications, and post-incident learning.

Operate with a high degree of autonomy in a fast-paced, evolving environment; identify opportunities to improve how ADI secures its software, AI, and products, and establish scalable standards and best practices.

Lead and scale a high-performing multidisciplinary organization across application, AI, and product security, establishing the structure, priorities, and accountability needed to deliver impactful enterprise security outcomes for ADI

Build a strong talent bench by attracting, developing, and retaining top security talent, strengthening leadership capability, and fostering a collaborative culture of agility, ownership, and continuous improvement

Serves as a credible, trusted partner to internal stakeholders and engineering teams, ensuring security standards enable delivery, strengthen product trust, and support ADI’s innovation and growth priorities

Required Qualifications

  • Bachelor’s degree required, preferably in Engineering, Computer Science, Cybersecurity, or a related technical field (or equivalent experience).
  • 15+ years of progressive cybersecurity experience, including significant experience in a senior security leadership role (e.g., Deputy CISO, CISO, or a Senior Director/Executive Director leading application, product, or AI security) in a large-scale, complex environment.
  • 15+ years of sponsoring and managing complex programs and projects. A breathe of program delivery across application delivery, product and cybersecurity is preferred.
  • Proven experience building, leading, and scaling security functions across large, global engineering organizations, with a track record of building high-performing teams and sustaining engagement through organizational change.
  • Deep expertise establishing secure-SDLC / DevSecOps programs and embedding automated security testing (SAST/SCA/DAST/secret scanning) into CI/CD pipelines, with hands-on understanding of software supply-chain security, threat modeling, and secure code / design review.
  • Working knowledge of AI/GenAI security and governance frameworks and controls – including model risk, data leakage, prompt-injection defense, and AI incident response – and familiarity with the emerging risks of agentic AI.
  • Experience with product security, PSIRT / coordinated vulnerability disclosure, and SBOM / software-supply-chain transparency, and the ability to interpret and map requirements from security and safety frameworks relevant to ADI’s markets (e.g., IEC 62443, ISO/SAE 21434, ISO 26262, IEC 62304, NIST CSF, CMMC, ITAR/EAR).
  • Demonstrated ability to translate highly complex technical risk into clear, quantified, business-focused terms (e.g., FAIR or equivalent) and communicate to both technical and non-technical audiences, including executives and the Board.
  • Strong executive presence and stakeholder-management skills, with experience working directly with senior leadership and influencing across organizational boundaries.
  • Demonstrated ability to operate with significant autonomy, navigate ambiguity, and balance strategic thinking with hands-on execution in a dynamic, fast-paced environment.

Ideal Qualifications

  • Advanced degree and relevant certifications (e.g., CISSP, CISM).
  • Experience in the semiconductor, electronics, or advanced-hardware industry, or in another regulated, IP-intensive, or critical-infrastructure-adjacent environment (e.g., aerospace/defense, automotive, medical devices, or life sciences).
  • Experience operating in export-controlled and regulated environments (e.g., ITAR/EAR, CMMC).
  • Experience standing up a new security capability or function from the ground up, including establishing governance, standards, and scalable operating models across a large organization.
  • Experience supporting Board-level communications, enterprise risk reviews, or executive decision forums on cybersecurity posture and strategy.

For positions requiring access to technical data, Analog Devices, Inc. may have to obtain export licensing approval from the U.S. Department of Commerce - Bureau of Industry and Security and/or the U.S. Department of State - Directorate of Defense Trade Controls. As such, applicants for this position – except US Citizens, US Permanent Residents, and protected individuals as defined by 8 U.S.C. 1324b(a)(3) – may have to go through an export licensing review process.

Analog Devices is an equal opportunity employer. We foster a culture where everyone has an opportunity to succeed regardless of their race, color, religion, age, ancestry, national origin, social or ethnic origin, sex, sexual orientation, gender, gender identity, gender expression, marital status, pregnancy, parental status, disability, medical condition, genetic information, military or veteran status, union membership, and political affiliation, or any other legally protected group.

EEO is the Law: Notice of Applicant Rights Under the Law.

Job Req Type: ExperiencedRequired Travel: Yes, 10% of the timeShift Type: 1st Shift/DaysThe expected wage range for a new hire into this position is $219,200 to $301,400.
  • Actual wage offered may vary depending on work location, experience, education, training, external market data, internal pay equity, or other bona fide factors.

  • This position qualifies for a discretionary performance-based bonus which is based on personal and company factors.

  • This position includes medical, vision and dental coverage, 401k, paid vacation, holidays, and sick time, and other benefits.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available