Infrastructure Cyber Defense Leader

Altera Semiconductor
  • San Jose, California
  • Autofill and Review
7 days ago

Job Description

Job Details:

Job Description:

About the Role 

Altera is seeking a technically capable Infrastructure Cyber Defense Leader to lead enterprise infrastructure security strategy, operations, and continuous improvement across network, cloud, on-premises, and hybrid technology environments. 


The role will oversee network security, cloud security, infrastructure protection, vulnerability management, security architecture, cyber resilience, and risk assessment activities. The successful candidate will help protect semiconductor design environments, operations, intellectual property, corporate systems, engineering platforms, and critical business services.

 

This position will work closely with Information Security, Infrastructure, Cloud, Network Engineering, IT Engineering, IT Operations, Compliance, Legal, Internal Audit, and business stakeholders. It is best suited for a hands-on security leader who can translate enterprise risk into practical security controls, measurable outcomes, and resilient technology architectures. 


What You’ll Do 

Infrastructure Defense Strategy and Operations 

  • Lead the strategy, operating model, and day-to-day execution of infrastructure defense capabilities across enterprise, cloud, data center, remote access, and engineering environments. 
  • Establish security standards, operating procedures, control objectives, service-level expectations, and performance metrics for infrastructure security. 
  • Assess infrastructure risks and prioritize remediation based on business criticality, exploitability, exposure, and potential impact to production, engineering, intellectual property, and customer commitments. 
  • Develop and maintain infrastructure security roadmaps aligned to business priorities, technology strategy, threat intelligence, and applicable security frameworks. 
  • Monitor operational performance, control effectiveness, open risks, exceptions, remediation commitments, and unresolved security gaps. 
  • Identify opportunities to improve automation, visibility, control consistency, operational efficiency, and cyber resilience. 

 

Network Security 

  • Oversee enterprise network security capabilities, including firewalls, secure web gateways, intrusion prevention, network segmentation, remote access, DNS security, DDoS protection, and network monitoring. 
  • Partner with Network Engineering to design and implement secure connectivity across corporate, cloud, data center, engineering and third-party environments. 
  • Improve segmentation and access controls for sensitive semiconductor design assets, production systems, engineering networks, and high-value intellectual property. 
  • Review network security configurations, rule sets, architecture changes, and exceptions to ensure alignment with approved standards. 
  • Establish measurable improvements in network visibility, control coverage, policy hygiene, and response readiness. 
  • Support investigation and remediation of network-based threats, misconfigurations, unauthorized access, and control failures. 

 

Cloud Security — Azure and AWS 

  • Lead security architecture, governance, and operational control implementation across Microsoft Azure, Amazon Web Services, and hybrid cloud environments. 
  • Define and enforce cloud security standards for identity, access management, network controls, encryption, logging, monitoring, secrets management, workload protection, and data security. 
  • Oversee security posture management and remediation activities across Azure and AWS accounts, subscriptions, landing zones, and cloud workloads. 
  • Partner with Cloud Engineering and DevOps teams to integrate security into infrastructure-as-code, CI/CD pipelines, container platforms, serverless services, and platform engineering practices. 
  • Improve cloud detection, logging, configuration compliance, vulnerability visibility, and incident response readiness. 
  • Review cloud architecture designs and technology changes for security risks, control gaps, resilience implications, and regulatory requirements. 
  • Support cloud migration and modernization initiatives by embedding secure-by-design principles into solution delivery. 

 

Application Security and DevSecOps  

 

  • Lead and mature application security and DevSecOps capabilities across internally developed applications, APIs, cloud-native services, and engineering platforms.  
  • Establish secure SDLC requirements, application security standards, security review processes, and security control expectations.  
  • Partner with Software Engineering, DevOps, Platform Engineering, and Cloud teams to integrate security into development, testing, CI/CD pipelines, infrastructure-as-code, containers, Kubernetes platforms, and software delivery processes.  
  • Oversee application security testing capabilities including SAST, DAST, SCA, secrets detection, API security testing, container security scanning, and infrastructure-as-code security assessments.  
  • Facilitate threat modeling, secure design reviews, secure coding initiatives, and risk assessments for new applications and major technology changes.  
  • Establish risk-based remediation processes and performance metrics for application security findings and software supply-chain risks.  
  • Coordinate application penetration testing, remediation validation, and secure release readiness activities.  
  • Improve software supply-chain security through dependency governance, SBOM visibility, artifact integrity controls, and code-signing practices. 

 

Infrastructure Security and Cyber Resilience 

  • Protect compute, storage, virtualization, operating systems, databases, endpoints, identity infrastructure, backup platforms, and other foundational technology services. 
  • Assess technology dependencies and identify breaking points that could affect the recoverability and availability of critical business. 
  • Drive initiatives that strengthen infrastructure resilience against ransomware, destructive attacks, identity compromise, cloud disruption, and technology failures. 
  • Partner with IT Operations and Disaster Recovery teams to validate backup protection, recovery controls, restoration procedures, and resilience assumptions. 
  • Support infrastructure hardening, secure configuration management, privileged access controls, endpoint protection, and administrative activity monitoring. 
  • Lead infrastructure security reviews for new platforms, major changes, acquisitions, third-party services, and high-risk technology implementations. 

 

Vulnerability Management 

  • Lead the enterprise vulnerability management program across network devices, servers, endpoints, cloud resources, applications, containers, engineering systems, and assets. 
  • Establish risk-based prioritization, remediation service levels, exception processes, escalation paths, and executive reporting. 
  • Improve asset inventory accuracy, scanning coverage, authenticated scanning, cloud visibility, vulnerability validation, and remediation tracking. 
  • Partner with Infrastructure, Cloud, Application, Engineering, and IT teams to reduce exposure to critical and actively exploited vulnerabilities. 
  • Track remediation performance using measurable indicators such as critical vulnerability aging, remediation timeliness, exposure reduction, asset coverage, and exception closure. 
  • Coordinate vulnerability assessments, penetration testing, configuration reviews, attack-surface assessments, and remediation validation. 
  • Provide risk-based reporting to security leadership, technology owners, audit teams, and executive stakeholders. 

 

Security Architecture and Risk Assessments 

  • Lead security architecture reviews for infrastructure, cloud, network, identity, data center, and technology transformation initiatives. 
  • Translate business and technical requirements into secure, scalable, and resilient architecture patterns. 
  • Conduct risk assessments that identify control gaps, attack paths, dependencies, concentration risks, and potential business impacts. 
  • Review proposed designs, technology changes, exceptions, and compensating controls against enterprise security standards. 
  • Maintain architecture principles, reference designs, control requirements, decision records, and security review documentation. 
  • Facilitate structured discussions with technical teams to evaluate technology landscapes against security, resilience, and recovery requirements. 
  • Provide practical recommendations that balance risk reduction, operational feasibility, performance, availability, and business timelines. 

 

Governance, Reporting, and Continuous Improvement 

  • Establish infrastructure defense governance meetings, action tracking, escalation processes, and cross-functional follow-up. 
  • Prepare dashboards and management reports covering:  
  • Vulnerability exposure and remediation performance 
  • Network and cloud control coverage 
  • Security architecture review status 
  • Open risks, exceptions, and remediation commitments 
  • Cloud security posture and configuration compliance 
  • Critical asset protection 
  • Infrastructure resilience and recovery readiness 
  • Conduct periodic quality reviews of security assessments, architecture decisions, remediation evidence, control performance, and operational outcomes. 
  • Identify and implement improvements to infrastructure defense maturity, automation, data quality, operational efficiency, and stakeholder adoption. 

 

Technical Skills and Technologies 

  • Network Security: Next-generation firewalls, secure web gateways, VPN, ZTNA, IDS/IPS, DDoS protection, DNS security, network access control, segmentation, and network traffic analysis. 
  • Azure Security: Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Entra ID, Azure Policy, Azure Firewall, Azure Key Vault, Azure Monitor, Azure Networking, Azure Security Center capabilities, and Azure landing zones. 
  • AWS Security: AWS Security Hub, GuardDuty, Inspector, IAM, Organizations, Control Tower, CloudTrail, AWS Config, KMS, VPC security, and centralized logging. 
  • Infrastructure Security: Windows and Linux security, endpoint protection, server hardening, virtualization, storage, databases, backup platforms, privileged access, patch management, and configuration management. 
  • Vulnerability Management: Vulnerability scanners, attack-surface management, penetration testing, configuration assessment, remediation tracking, exception management, and risk-based prioritization. 
  • Security Architecture: Zero Trust, secure network architecture, cloud reference architectures, identity-centric security, segmentation, encryption, resiliency, and secure-by-design reviews. 
  • Security Frameworks: NIST CSF, NIST SP 800-53, CIS Controls, ISO/IEC 27001, IEC 62443, SOC 2, and SOX/ITGC. 
  • Application Security: Secure SDLC, threat modeling, secure coding, SAST, DAST, software composition analysis, API security testing, application penetration testing, dependency management, and security review processes. 
  • DevSecOps & Software Supply Chain Security: CI/CD security, infrastructure-as-code security, secrets management, container security, Kubernetes security, software bill of materials (SBOM), artifact integrity, code signing, policy-as-code, and automated security controls. 

 

Leadership and People Management 

  • Lead and develop infrastructure security, network security, cloud security, application security, DevSecOps, vulnerability management, cyber resilience, and security architecture capabilities. 
  • Establish clear objectives, role expectations, operating rhythms, quality standards, and performance measures. 
  • Coach team members through technical assessments, architecture decisions, risk discussions, stakeholder interactions, and career development. 
  • Coordinate internal teams, technology owners, and service providers through clear accountability and escalation processes. 
  • Promote secure-by-design thinking, disciplined documentation, knowledge sharing, automation, and continuous learning. 
  • Foster a culture of operational ownership, timely escalation, practical risk management, and measurable improvement. 

 

Stakeholder Management 

  • Partner with the CISO organization, CIO, IT Infrastructure, Network Engineering, Cloud Engineering, Enterprise Architecture, DevOps, Engineering, Compliance, Legal, Internal Audit, Procurement, and business leadership. 
  • Facilitate architecture reviews, risk assessments, remediation planning, resilience exercises, and executive working sessions. 
  • Communicate infrastructure security risks, control gaps, remediation options, and residual risk in clear business terms. 
  • Build effective relationships with cloud providers, managed security service providers, technology vendors, and strategic suppliers. 
  • Support leadership decisions by providing actionable analysis of risk, cost, feasibility, operational impact, and security outcomes. 

 

What Success Looks Like 

During the first six to twelve months, you will be expected to: 

  • Establish clear governance, performance measures, and operating procedures for infrastructure defense. 
  • Improve visibility and control coverage across network, Azure, AWS, on-premises and engineering environments. 
  • Reduce critical and actively exploited vulnerability exposure through measurable remediation improvements. 
  • Establish consistent security architecture review and risk assessment processes. 
  • Improve cloud security posture, configuration compliance, logging, monitoring, and identity protection. 
  • Strengthen network segmentation, infrastructure hardening, privileged access, and cyber resilience controls. 
  • Improve readiness for ransomware, cloud disruption, infrastructure compromise, and technology recovery scenarios. 
  • Establish reliable infrastructure security dashboards and executive reporting. 
  • Build a collaborative, accountable, and technically strong infrastructure defense capability. 
  • Expand automated application security coverage across source code, open-source dependencies, APIs, containers, infrastructure-as-code, and CI/CD pipelines.  
  • Improve remediation performance for critical application and software supply-chain vulnerabilities through measurable reductions in exposure and remediation timelines. 

Salary Range

The pay range below is for Bay Area California only. Actual salary may vary based on a number of factors including job location, job-related knowledge, skills, experiences, trainings, etc. We also offer incentive opportunities that reward employees based on individual and company performance.  


$187,000 - $270,000 USD 

 

We use artificial intelligence to screen, assess, or select applicants for the position. Applicants must be eligible for any required U.S. export authorizations.


#LI-MD1

Qualifications:

Minimum Qualifications 

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field; equivalent experience may be considered. 
  • 10+ years of experience in infrastructure security, network security, cloud security, security architecture, vulnerability management, cyber resilience, or a related discipline. 
  • Experience leading infrastructure security programs across on-premises, cloud, and hybrid environments. 
  • Hands-on experience with enterprise network security controls, cloud security architecture, infrastructure hardening, vulnerability management, and security risk assessments. 
  • Strong experience securing Microsoft Azure and AWS environments. 
  • Experience designing or reviewing security architectures for networks, cloud platforms, data centers, identity services, applications, and infrastructure technologies. 
  • Experience developing and operating risk-based vulnerability management programs. 
  • Strong understanding of identity and access management, privileged access, network segmentation, encryption, logging, monitoring, endpoint security, and secure configuration management. 
  • Ability to translate technical findings into practical remediation plans and executive-level risk reporting. 
  • Strong written and verbal communication skills, with the ability to engage technical and nontechnical stakeholders. 
  • Strong organizational skills and the ability to manage multiple workstreams, priorities, stakeholders, and deadlines. 
  • Ability to work independently and collaborate effectively across Security, IT, Engineering, Compliance, Legal, Internal Audit, and business teams. 
  • Experience leading or supporting Application Security and DevSecOps programs.  
  • Experience implementing secure SDLC practices and application security testing methodologies.  
  • Experience integrating SAST, DAST, SCA, API security, secrets detection, container security, and infrastructure-as-code security controls into CI/CD pipelines.  
  • Working knowledge of OWASP Top 10, OWASP ASVS, OWASP SAMM, and NIST Secure Software Development Framework (SSDF). 

 

Preferred Qualifications 

  • Experience supporting semiconductor, electronics, industrial, engineering, or other high-technology organizations. 
  • Experience securing semiconductor design environments, networks, engineering systems, intellectual property, or IT/OT-connected environments. 
  • Experience with Azure security services, Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Entra ID, Azure Policy, Azure Firewall, Azure Key Vault, and Azure Monitor. 
  • Experience with AWS security services, including AWS Security Hub, GuardDuty, Inspector, IAM, Organizations, Control Tower, CloudTrail, Config, KMS, and VPC security controls. 
  • Experience with cloud security posture management, cloud workload protection, infrastructure-as-code security, containers, Kubernetes, and DevSecOps practices. 
  • Familiarity with NIST Cybersecurity Framework, NIST SP 800-53, NIST SP 800-82, CIS Controls, ISO/IEC 27001, IEC 62443, SOC 2, and SOX/ITGC. 
  • Experience with IT/OT segmentation, industrial control systems, engineering execution systems, networks, or engineering workstations. 
  • Experience managing third-party infrastructure, cloud providers, managed security services, and technology suppliers. 
  • Experience developing infrastructure security dashboards, key risk indicators, key performance indicators, and executive reporting. 
  • Experience supporting business continuity, disaster recovery, ransomware resilience, or technology recovery exercises. 

Certifications (Continued Preferred Qualifications)

A relevant certification is preferred but not required. Examples include: 

    • Certified Information Systems Security Professional — CISSP 
    • Certified Information Security Manager — CISM 
    • Certified Cloud Security Professional — CCSP 
    • GIAC Cloud Security Automation — GCSA 
    • GIAC Cloud Penetration Tester — GCPN 
    • AWS Certified Security — Specialty 
    • Microsoft Certified: Cybersecurity Architect Expert 
    • Microsoft Certified: Azure Security Engineer Associate 
    • Certified Information Systems Auditor — CISA 
    • Certified Ethical Hacker — CEH 
    • ISA/IEC 62443 Cybersecurity Certification 

(Equivalent hands-on experience may be considered in lieu of certification.)

Job Type:

Regular

Shift:

Shift 1 (United States of America)

Primary Location:

San Jose, California, United States

Additional Locations:

Posting Statement:

All qualified applicants will receive consideration for employment without regard to race, color, religion, religious creed, sex, national origin, ancestry, age, physical or mental disability, medical condition, genetic information, military and veteran status, marital status, pregnancy, gender, gender expression, gender identity, sexual orientation, or any other characteristic protected by local law, regulation, or ordinance.

Numbers & Facts

LocationSan Jose, California

Skills

  • Access Controlunmatched
  • Amazon Web Services (AWS)unmatched
  • Analysis Skillsunmatched
  • Application Programming Interface (API)unmatched
  • Applications Securityunmatched
  • Authenticationunmatched
  • Automationunmatched
  • Bill of Materials (BOM)unmatched
  • Business Servicesunmatched
  • Business Supportunmatched
  • CCSP - Cisco Certified Security Professionalunmatched
  • CEH - Certified Ethical Hackerunmatched
  • CISA - Certified Information Systems Auditorunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Career Developmentunmatched
  • Cloud Applicationsunmatched
  • Cloud Architectureunmatched
  • Cloud Computingunmatched
  • Coachingunmatched
  • Code Reviewsunmatched
  • Communication Skillsunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Computer Workstationsunmatched
  • Configuration Managementunmatched
  • Continuous Deployment/Deliveryunmatched
  • Continuous Improvementunmatched
  • Continuous Integrationunmatched
  • Control Systemsunmatched
  • Cost Analysisunmatched
  • Cross-Functionalunmatched
  • Cryptographyunmatched
  • DNS (Domain Name System)unmatched
  • Data Qualityunmatched
  • Data Recoveryunmatched
  • Database Backupunmatched
  • Denial of Service (DoS)unmatched
  • DevOpsunmatched
  • Disaster Recoveryunmatched
  • Documentation Reviewunmatched
  • Electronicsunmatched
  • Endpoint Securityunmatched
  • Enterprise Architectureunmatched
  • Enterprise Protectionunmatched
  • Establish Prioritiesunmatched
  • Firewallsunmatched
  • GIAC - Global Information Assurance Certificationunmatched
  • GPEN - GIAC Penetration Testerunmatched
  • Hybrid Cloudunmatched
  • ISA Standardsunmatched
  • ISO (International Organization for Standardization)unmatched
  • Identity Data Managementunmatched
  • Incident Responseunmatched
  • Industrial Engineeringunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Intellectual Property (IP)unmatched
  • Internal Auditunmatched
  • International Electro-Technical Commission (IEC)unmatched
  • Internet Securityunmatched
  • Intrusion Detection Systemsunmatched
  • Intrusion Prevention Systemsunmatched
  • Leadershipunmatched
  • Legalunmatched
  • Linux Operating Systemunmatched
  • Loss Preventionunmatched
  • Microsoft Product Familyunmatched
  • Microsoft Windows Azureunmatched
  • Microsoft Windows Operating Systemunmatched
  • Network Access Control (NAC)unmatched
  • Network Architecture/Engineeringunmatched
  • Network Configuration Managementunmatched
  • Network Designunmatched
  • Network Monitoringunmatched
  • Network Operations Centerunmatched
  • Network Programmingunmatched
  • Network Securityunmatched
  • Network Traffic Analysisunmatched
  • Operating Systemsunmatched
  • Operational Controlunmatched
  • Operational Improvementunmatched
  • Operational Strategyunmatched
  • Operations Processesunmatched
  • Operations Security (OPSEC)unmatched
  • Organizational Skillsunmatched
  • Penetration Testingunmatched
  • People Managementunmatched
  • Performance Analysisunmatched
  • Performance Metricsunmatched
  • Presentation/Verbal Skillsunmatched
  • Production Systemsunmatched
  • Property Maintenanceunmatched
  • Protective Servicesunmatched
  • Purchasing/Procurementunmatched
  • Quality Assurance Methodologyunmatched
  • Quality Metricsunmatched
  • Ransomwareunmatched
  • Regulatory Requirementsunmatched
  • Remote Accessunmatched
  • Reporting Dashboardsunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Sarbanes-Oxley Act (SOX)unmatched
  • Secure Codingunmatched
  • Security Analysisunmatched
  • Security Architectureunmatched
  • Security Attacksunmatched
  • Security Infrastructureunmatched
  • Security Monitoringunmatched
  • Security Softwareunmatched
  • Semiconductorsunmatched
  • Software Administrationunmatched
  • Software Developmentunmatched
  • Software Development Lifecycle (SDLC)unmatched
  • Software Engineeringunmatched
  • Software Patchesunmatched
  • Software Testingunmatched
  • Standard Operating Procedures (SOP)unmatched
  • Supply Chainunmatched
  • Systems Engineeringunmatched
  • Team Playerunmatched
  • Technical Analysisunmatched
  • Technical Strategyunmatched
  • Technology Analysisunmatched
  • Test Plan/Scheduleunmatched
  • Threat Modelingunmatched
  • Time Managementunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • VPN (Virtual Private Network)unmatched
  • Validation Testingunmatched
  • Vendor/Supplier Planningunmatched
  • Virtualizationunmatched
  • Vulnerability Scannersunmatched
  • Web Infrastructureunmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder