IBACTP® — International Board of AI, Cybersecurity & Technology Professionals
CDevSOM®

Certified DevSecOps Manager

CDevSOM® evaluates advanced management judgment across enterprise secure-delivery environments.

Credential
Certified DevSecOps Manager
Certification Designation
CDevSOM®
Certification Level
Advanced / Management
Certification Body
International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)
Program Category
DevSecOps Strategy, Secure Software Governance, Cloud-Native Delivery & Technology Leadership
Delivery Format
Instructor-Led, Virtual Instructor-Led, Self-Paced, or Blended Learning
Recommended Training Duration
50–60 Hours
Certification Examination
Proctored, advanced competency-based management examination
Alternative Assessment Pathway
Enterprise DevSecOps Management Capstone for eligible candidates in approved instructor-led pathways
Credential Renewal Cycle
3 Years
Program code on a dark screen
DevSecOps
CDevSOM® Certified DevSecOps Manager badge

Lead Secure Delivery and Platform Engineering.

Advanced Manager Level For devsecops leaders, managers and decision-makers
Vendor-Neutral Skills and knowledge that apply across platforms and tools
Global Recognition Recognized internationally across industries and regions
Digital Credential Shareable, verifiable credential and certificate
Certification Overview

What You Will Learn

Develop the management knowledge and judgment to lead secure software delivery and platform engineering.

View Full Syllabus
1

Develop Enterprise DevSecOps Strategy and Governance

Assess maturity, define strategic priorities, establish responsibilities, develop roadmaps, and align DevSecO…

2

Govern Secure SDLC and Application Security

Establish secure-development requirements, threat-modeling expectations, testing strategies, remediation stan…

3

Govern CI/CD Pipelines and Secure Automation

Evaluate pipeline architecture, identity, secrets, security gates, artifact integrity, automation, approvals…

4

Govern Cloud-Native and Platform Security

Oversee cloud, IaC, containers, Kubernetes, APIs, microservices, runtime environments, and platform-engineeri…

5

Govern Software Supply-Chain Risk

Manage dependency security, SBOM strategy, package risk, provenance, artifact integrity, third-party componen…

6

Manage DevSecOps Investment, Vendors, and Performance

Prioritize security tooling, evaluate providers, establish KPIs/KRIs, measure maturity, assess developer impa…

7

Govern AI-Enabled DevSecOps and Emerging Risks

Evaluate AI-assisted development, generated code, automated remediation, intelligent testing, agentic develop…

8

Lead Workforce, Culture, Executive Communication, and Transformation

Build capabilities, manage organizational change, strengthen collaboration, communicate software risk, and le…

Certified DevSecOps Manager
LeadGovernDeliverRepeat
Designed for you

Built for DevSecOps Leaders

For professionals who lead, govern and scale secure software delivery, CDevSOM® helps you advance your leadership.

  • DevSecOps Manager
  • DevOps Manager
  • Application Security Manager
  • Secure Software Development Manager
  • Software Engineering Manager
  • Cloud Security Manager
  • Platform Engineering Manager
  • Engineering Manager
  • Product Security Manager
  • CI/CD Platform Manager
CDevSOM® Body of Knowledge

Eight Modules. Real-World Impact.

Explore Detailed Syllabus
01

Enterprise DevSecOps Strategy and Governance

DevSecOps Maturity and Current-State Assessment · Business Alignment and Enterprise DevSecOps Strategy · Governance, Roles, Accountability, and Decision Rights

02

Secure SDLC and Application Security Governance

Secure Development Policies and Standards · Threat Modeling and Secure Architecture Governance · SAST, DAST, SCA, and Testing Strategy

03

CI/CD Pipeline, Automation, and Release Governance

Enterprise CI/CD Architecture and Pipeline Governance · Identity, Secrets, Access, and Privilege Management · Security Gates, Policy Enforcement, and Automated Testing

04

Cloud-Native, IaC, Container, and API Governance

Cloud Security and Shared-Responsibility Governance · Infrastructure as Code, Policy as Code, and Configuration Assurance · Container, Registry, and Kubernetes Security Governance

05

Software Supply Chain and Third-Party Risk

Open-Source and Third-Party Software Governance · SBOM Strategy and Software Component Transparency · Package Repositories, Trusted Sources, and Dependency Controls

06

Investment, Metrics, Vendors, and DevSecOps Performance

DevSecOps Business Cases and Investment Prioritization · Security Tooling Strategy and Platform Rationalization · Vendor, Contract, and Service-Provider Governance

07

AI-Enabled DevSecOps and Emerging Software Risk

AI-Assisted Development and Engineering Productivity · AI-Generated Code Security and Validation · AI-Enabled Testing, Triage, and Remediation

08

Workforce, Culture, Executive Communication, and Transformation

DevSecOps Workforce Strategy and Organizational Design · Skills, Training, Security Champions, and Capability Development · Developer-Security Collaboration and Culture

Learning outcomes

From Development to a More Secure Tomorrow

Lead security across the entire software delivery lifecycle.

  1. PlanDesign with security in mind
  2. CodeWrite and review secure code
  3. BuildAutomate with security controls
  4. TestValidate and assess risks
  5. DeployRelease with confidence
  6. MonitorDetect and respond to threats
  7. ImproveLearn and strengthen
Assessment pathways

Two Pathways. One Recognized Credential.

Choose the pathway that suits your learning journey.

CDevSOM® Certification Examination

  • 100 questions
  • Advanced multiple-choice and scenario-based management questions
  • 90 minutes
  • Closed book
  • Secure online proctoring or approved testing center

Enterprise DevSecOps Management Capstone

  • Eligible candidates in approved instructor-led pathways may complete the Enterprise DevSecOps Management Capstone.

See the Four Ways to Enroll

Why CDevSOM®?

Advance Your Career. Strengthen Your Impact.

Assess

Evaluate current maturity, software risk, capabilities, tooling, processes, and workforce.

Strategize

Define target capabilities, priorities, operating models, and roadmaps.

Govern

Establish standards, accountability, decision rights, exceptions, and assurance.

Prioritize

Direct attention toward the applications, vulnerabilities, supply-chain risks, and capabilities that matter m…

Automate

Scale appropriate controls through secure and governed automation.

Assure

Determine whether controls, pipelines, artifacts, platforms, and delivery practices are operating effectively.

Career opportunitiesDevSecOps ManagerDevOps ManagerApplication Security ManagerProduct Security ManagerSoftware Security ManagerPlatform Engineering Manager
Your credential

Shareable. Verifiable. Professional.

Earn a digital credential and certificate to showcase your achievement.

  • Official IBACTP® Certificate
  • Digital Badge (Shareable)
  • Verifiable Credential
  • Showcase on LinkedIn and professional profiles
CDevSOM® digital badge
CDevSOM®Certified DevSecOps Manager
About the credential

Become a DevSecOps professional the market trusts.

Certification Designation: CDevSOM®

Certification Level: Advanced / Management

Certification Body: International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)

Program Category: DevSecOps Strategy, Secure Software Governance, Cloud-Native Delivery & Technology Leadership

Delivery Format: Instructor-Led, Virtual Instructor-Led, Self-Paced, or Blended Learning

Program code on a dark screen

Advanced Manager level — Three-year certification cycle with continuing professional education

Recommended Training Duration: 50–60 Hours

Certification Examination: Proctored, advanced competency-based management examination

Alternative Assessment Pathway: Enterprise DevSecOps Management Capstone for eligible candidates in approved instructor-led pathways

Credential Renewal Cycle: 3 Years

Program code on a dark screen
CDevSOM®

Full Syllabus and Program Details

Open any topic to read the complete program information.

Who Should Earn CDevSOM®?
CDevSOM®

Who Should Earn CDevSOM®?

CDevSOM® is designed for professionals such as:

  • DevSecOps Manager
  • DevOps Manager
  • Application Security Manager
  • Secure Software Development Manager
  • Software Engineering Manager
  • Cloud Security Manager
  • Platform Engineering Manager
  • Engineering Manager
  • Product Security Manager
  • CI/CD Platform Manager
  • Security Engineering Manager
  • Technology Risk Manager
  • Software Security Program Manager
  • Cloud Engineering Manager
  • Director of DevSecOps
  • Director of Application Security
  • Director of Software Engineering
  • Director of Platform Engineering
  • Technology Transformation Leader
  • Senior Technology Consultant
  • Professionals preparing for CTO, CISO, or senior engineering leadership
CDevSOM® Body of Knowledge — Eight Modules
Curriculum

CDevSOM® Body of Knowledge — Eight Modules

CDevSOM® Course Learning Outcomes
Learning outcomes

CDevSOM® Course Learning Outcomes

Upon successful completion, participants will be able to:

1. Develop Enterprise DevSecOps Strategy and Governance

Assess maturity, define strategic priorities, establish responsibilities, develop roadmaps, and align DevSecOps with organizational objectives.

2. Govern Secure SDLC and Application Security

Establish secure-development requirements, threat-modeling expectations, testing strategies, remediation standards, and risk-acceptance processes.

3. Govern CI/CD Pipelines and Secure Automation

Evaluate pipeline architecture, identity, secrets, security gates, artifact integrity, automation, approvals, and deployment controls.

4. Govern Cloud-Native and Platform Security

Oversee cloud, IaC, containers, Kubernetes, APIs, microservices, runtime environments, and platform-engineering security.

5. Govern Software Supply-Chain Risk

Manage dependency security, SBOM strategy, package risk, provenance, artifact integrity, third-party components, and supply-chain controls.

6. Manage DevSecOps Investment, Vendors, and Performance

Prioritize security tooling, evaluate providers, establish KPIs/KRIs, measure maturity, assess developer impact, and evaluate program effectiveness.

7. Govern AI-Enabled DevSecOps and Emerging Risks

Evaluate AI-assisted development, generated code, automated remediation, intelligent testing, agentic development, and emerging risk.

8. Lead Workforce, Culture, Executive Communication, and Transformation

Build capabilities, manage organizational change, strengthen collaboration, communicate software risk, and lead DevSecOps transformation.

CDevSOM® Certification Testing Outcomes — Skills & Competencies Tested
What is assessed

CDevSOM® Certification Testing Outcomes — Skills & Competencies Tested

CDevSOM® evaluates advanced management judgment across enterprise secure-delivery environments.

CDevSOM®–IBACTP® DevSecOps Management Competency Model
CDevSOM®

CDevSOM®–IBACTP® DevSecOps Management Competency Model

1. Enterprise DevSecOps Strategy and Governance

Assess maturity, define enterprise DevSecOps strategy, establish governance, operating models, responsibilities, roadmaps, and transformation priorities.

2. Secure SDLC and Application Security Governance

Govern secure-development standards, threat modeling, code security, testing requirements, vulnerabilities, exceptions, and software-security assurance.

3. CI/CD, Automation, and Pipeline Governance

Govern pipeline architecture, identities, secrets, testing, approvals, release controls, artifact integrity, automation, and deployment risk.

4. Cloud-Native, Infrastructure, Container, and API Governance

Govern cloud, IaC, containers, Kubernetes, APIs, microservices, platform engineering, runtime security, and distributed systems.

5. Software Supply Chain and Third-Party Risk

Govern dependencies, open-source software, SBOMs, package repositories, artifact provenance, signing, third-party software, and supply-chain risk.

6. DevSecOps Investment, Metrics, Vendors, and Performance

Prioritize technology investments, manage vendors, establish KPIs/KRIs, assess developer experience, evaluate risk reduction, and measure program maturity.

7. AI-Enabled DevSecOps and Emerging Software Risk

Govern AI-assisted coding, generated code, security automation, intelligent testing, agentic development, model risk, and emerging delivery technologies.

8. Workforce, Culture, Executive Communication, and Transformation

Build DevSecOps capabilities, strengthen security culture, align development and security teams, communicate software risk, and lead transformation.

CDevSOM® Management Progression

Assess → Strategize → Govern → Prioritize → Automate → Assure → Measure → Lead → Transform

What Is CDevSOM®?
What it validates

What Is CDevSOM®?

The Certified DevSecOps Manager (CDevSOM®) validates advanced management competency in governing secure software delivery across enterprise development, cloud, application-security, automation, and software-supply-chain environments.

CDevSOM® prepares managers to move from:

Applying DevSecOps Controls

to:

Programme Facts
CDevSOM®

Recommended Prerequisites and Eligibility

Recommended Prerequisites and Eligibility

CDevSOM® is positioned at the advanced management level.

Recommended progression:

Standards and International Framework Alignment — CDevSOM®
DevSecOps

Standards and International Framework Alignment — CDevSOM®

The CDevSOM® Body of Knowledge incorporates relevant principles and practices associated with:

  • ISO/IEC 27001
  • ISO/IEC 27002
  • ISO/IEC 27005
  • ISO/IEC 27017
  • ISO/IEC 27034 concepts
  • ISO/IEC 27701
  • ISO 31000
  • ISO/IEC 42001
  • ISO/IEC 23894
  • NIST Cybersecurity Framework
  • NIST Secure Software Development Framework
  • NIST NICE Workforce Framework
  • NIST AI Risk Management Framework
  • Relevant NIST software-supply-chain, application-security, cloud, identity, and cybersecurity guidance
  • CISA Secure by Design principles and relevant software-security guidance
  • OWASP application-security practices
  • OWASP API-security practices
  • Recognized DevSecOps, secure-development, cloud-native, software-supply-chain, and application-security practices

CDevSOM® Framework Application Progression

Understand → Interpret → Assess → Prioritize → Govern → Assure → Measure → Improve

Alignment does not constitute formal accreditation, recognition, approval, endorsement, sponsorship, or affiliation.

Accreditation and Credentialing Quality Alignment
DevSecOps

Accreditation and Credentialing Quality Alignment

The CDevSOP® and CDevSOM® certification frameworks may incorporate professional credentialing principles associated with:

ISO/IEC 17024 • ANAB • NCCA • I.C.E. • International Personnel-Certification and Conformity-Assessment Practices

The credentialing framework encompasses:

Job Task Analysis • Defined Competencies • Eligibility Standards • Validated Body of Knowledge • Examination Blueprint • SME Participation • Psychometric Principles • Examination Security • Identity Verification • Impartial Decisions • Appeals and Complaints • Professional Ethics • Continuing Education • Recertification • Credential Verification • Periodic Review • Continuous Improvement

Credentialing Quality Lifecycle

Define → Validate → Assess → Certify → Maintain → Verify → Review → Improve

Alignment does not constitute accreditation, recognition, approval, or endorsement. Formal external status should be represented only after officially awarded by the applicable independent organization.

Global and Vendor-Neutral Design
DevSecOps

Global and Vendor-Neutral Design

Both CDevSOP® and CDevSOM® are designed around transferable DevSecOps competencies rather than dependence on one:

Programming Language • CI/CD Platform • Cloud Provider • Application-Security Product • Container Platform • Source-Control Vendor • Infrastructure Automation Tool • AI Provider

This allows the certifications to remain applicable across different:

  • Software-development environments
  • Cloud platforms
  • Programming ecosystems
  • Industries
  • Technology stacks
  • Organizational delivery models
CDevSOM® Leadership Progression
CDevSOM®

CDevSOM® Leadership Progression

The certification develops competency across the complete management lifecycle:

Assess → Strategize → Govern → Prioritize → Automate → Assure → Measure → Communicate → Transform

Assess

Evaluate current maturity, software risk, capabilities, tooling, processes, and workforce.

Strategize

Define target capabilities, priorities, operating models, and roadmaps.

Govern

Establish standards, accountability, decision rights, exceptions, and assurance.

Prioritize

Direct attention toward the applications, vulnerabilities, supply-chain risks, and capabilities that matter most.

Automate

Scale appropriate controls through secure and governed automation.

Assure

Determine whether controls, pipelines, artifacts, platforms, and delivery practices are operating effectively.

Measure

Use meaningful KPIs and KRIs to evaluate security, delivery, risk, and maturity.

Communicate

Translate software risk and program performance into executive decisions.

Transform

Improve platforms, processes, teams, culture, and organizational capability.

Integrated CDevSOP® → CDevSOM® Certification Pathway
CDevSOM®
  • Integrated CDevSOP®
  • CDevSOM® Certification Pathway
  • Professional Level
  • Advanced / Management Level

CDevSOP® — Certified DevSecOps Professional

Primary emphasis:

Plan • Code • Build • Test • Secure • Deploy • Monitor • Improve

CDevSOM® — Certified DevSecOps Manager

Primary emphasis:

Assess • Strategize • Govern • Prioritize • Automate • Assure • Measure • Lead • Transform

The progression moves professionals from integrating security into development and deployment workflows to governing secure software delivery, software risk, automation, platforms, investments, people, and enterprise transformation.

CDevSOP® vs. CDevSOM® Pathway Comparison
CDevSOM®

CDevSOP® vs. CDevSOM® Pathway Comparison

AreaCDevSOP® — ProfessionalCDevSOM® — Advanced Manager
Primary Focus Secure software delivery Enterprise DevSecOps leadership
Secure SDLC Apply Govern
Threat Modeling Perform/support Establish standards
Secure Coding Apply principles Govern program
Source Control Secure repositories Govern enterprise controls
CI/CD Build and secure pipelines Govern pipeline architecture
SAST/DAST/SCA Use and interpret Define strategy and assurance
Cloud Secure workloads Govern cloud-native risk
IaC Implement securely Establish governance
Containers Scan and secure Govern platform risk
APIs Test and secure Govern enterprise requirements
Supply Chain Identify and remediate Govern enterprise risk
SBOM Generate/interpret Establish strategy
Vulnerabilities Identify and prioritize Govern risk acceptance
Automation Implement Strategize and govern
Metrics Operational measures KPIs, KRIs, maturity
AI Apply and validate Govern and invest
Vendors Work with platforms Govern tools/providers
Workforce Professional contribution Build capabilities
Communication Technical reporting Executive communication
Transformation Support adoption Lead enterprise transformation
Objective Deliver Secure Software Govern Secure Software Delivery
IBACTP® DevSecOps Career Pathway
CDevSOM®

IBACTP® DevSecOps Career Pathway

  • CDevSOP® — Professional Level
  • CDevSOM® — Advanced / Management Level

Plan → Code → Build → Test → Secure → Deploy → Monitor → Improve

Build Secure Software. Automate Security. Deliver with Confidence.

Assess → Strategize → Govern → Prioritize → Assure → Measure → Lead → Transform

Govern Secure Delivery. Reduce Software Risk. Lead DevSecOps Transformation.

IBACTP® IT Governance Certification Pathway
CDevSOM®

IBACTP® IT Governance Certification Pathway

  • Certified IT Governance Professional (CITGP®) & Certified IT Governance Manager (CITGM®)

Align Technology. Strengthen Accountability. Govern Risk. Create Enterprise Value.

Information technology is no longer simply an operational support function. Technology influences strategy, financial performance, cybersecurity, data, artificial intelligence, customer experience, regulatory exposure, operational resilience, and organizational transformation.

Organizations therefore need professionals who understand not only how technology is managed, but also how technology decisions should be governed, monitored, challenged, measured, and aligned with enterprise objectives.

The International Board of AI, Cybersecurity & Technology Professionals (IBACTP®) IT Governance Certification Pathway is designed around two progressive levels:

CITGP® — Professional Level

Understand • Assess • Apply • Monitor • Measure • Report • Improve

CITGM® — Advanced / Management Level

Evaluate • Direct • Govern • Prioritize • Assure • Measure • Lead • Transform

Together, the certifications create a structured progression from applying IT-governance principles and supporting governance processes to designing, directing, measuring, and transforming enterprise governance of information and technology.

Certification Overview
CDevSOM®

Certification Overview

Govern Secure Delivery. Scale Automation. Manage Software Risk. Lead DevSecOps Transformation.

The Certified DevSecOps Manager (CDevSOM®) is an advanced, vendor-neutral management certification designed to validate the strategic, governance, risk, investment, performance, and leadership competencies required to manage secure software delivery across modern enterprise environments.

CDevSOM® is designed for experienced professionals responsible for ensuring that software development and delivery capabilities are not only fast and automated but also secure, resilient, measurable, governed, scalable, and aligned with business priorities.

The certification moves beyond the implementation of individual DevSecOps tools and controls.

It prepares managers to govern the complete enterprise delivery ecosystem, including:

CDevSOM® recognizes that modern software delivery sits at the intersection of:

  • Secure software development
  • Application security
  • CI/CD pipelines
  • Cloud-native environments
  • Infrastructure as Code
  • Containers and orchestration
  • APIs and microservices
  • Software supply chains
  • Open-source dependencies
  • Secrets and identities
  • Vulnerability management
  • Security automation
  • Observability
  • Platform engineering
  • AI-assisted software development
  • Developer experience
  • Risk acceptance
  • Workforce capability
  • Vendor management
  • Executive reporting

Business Strategy + Software Engineering + Cybersecurity + Cloud + Automation + Risk + Governance + People

The certification therefore integrates:

DevSecOps Strategy + Secure SDLC Governance + Application Security + Pipeline Governance + Cloud-Native Security + Software Supply Chain + Risk + Automation + Metrics + Vendors + AI Governance + Workforce + Executive Communication

CDevSOM® develops managers who can determine not only whether security controls exist, but whether the entire secure-delivery capability is producing measurable reductions in software risk without creating unnecessary barriers to innovation and delivery.

CDevSOM® Leadership Objective

Why CDevSOM®?
CDevSOM®

Why CDevSOM®?

Software Delivery Is Now an Enterprise Risk and Business Capability

Modern organizations increasingly operate through software.

Applications enable:

For many organizations, software is no longer merely a technology asset.

It is part of the business model itself.

A weakness in software delivery can therefore produce consequences far beyond the development team.

A vulnerable application may expose customer data.

A compromised build pipeline may distribute malicious software.

An insecure API may expose critical business functions.

A vulnerable third-party dependency may affect hundreds of applications simultaneously.

A leaked pipeline credential may provide privileged access to production systems.

An insecure cloud deployment may expose sensitive information.

An unreliable release process may interrupt critical business operations.

Software risk can therefore become:

  • Customer interactions
  • Employee productivity
  • Digital commerce
  • Payments
  • Banking
  • Healthcare
  • Supply-chain operations
  • Manufacturing
  • Communications
  • Data analytics
  • Artificial intelligence
  • Cloud services
  • Digital products
  • Business operations
  • Revenue generation

Cybersecurity Risk • Operational Risk • Financial Risk • Regulatory Risk • Privacy Risk • Customer Risk • Supply-Chain Risk • Reputational Risk

CDevSOM® prepares managers to govern software delivery within this broader enterprise context.

DevSecOps Managers Must Balance Speed and Control
CDevSOM®

DevSecOps Managers Must Balance Speed and Control

Software organizations are under constant pressure to deliver:

These priorities can sometimes conflict.

Excessive security friction may slow development and encourage teams to bypass controls.

Insufficient security may increase enterprise risk.

Poorly implemented automation may scale mistakes.

Manual processes may become bottlenecks.

The DevSecOps manager must therefore create the right balance between:

Delivery Speed + Security + Reliability + Governance + Developer Experience + Business Value

The goal is not simply to add more controls.

It is to build a delivery system where appropriate controls are integrated, automated, risk-based, measurable, and usable.

  • More features
  • Faster releases
  • Better user experiences
  • Greater reliability
  • Lower cost
  • Stronger security
From Security Tools to Secure-Delivery Governance
CDevSOM®

From Security Tools to Secure-Delivery Governance

A professional may ask:

“Did the pipeline scan the code?”

The manager must ask:

“Is our security-testing strategy actually reducing material software risk?”

A professional may ask:

“Did the dependency scanner detect vulnerabilities?”

The manager must ask:

“Which vulnerabilities create meaningful exposure, which require immediate remediation, and who can accept the remaining risk?”

A professional may ask:

“Did the container scan pass?”

The manager must ask:

“Do our container-security standards cover images, registries, runtime behavior, privileges, and production environments consistently?”

A professional may ask:

“Can we automate this deployment?”

The manager must ask:

“Can we automate it safely, validate the result, preserve control, recover from failure, and demonstrate that the automation improves both delivery and risk?”

This transition defines CDevSOM®.

From Individual Findings to Enterprise Software Risk
CDevSOM®

From Individual Findings to Enterprise Software Risk

Technical teams may generate thousands of security findings.

Not all findings have equal significance.

A manager must consider factors such as:

The management objective is to move from:

  • Severity
  • Exploitability
  • Reachability
  • Internet exposure
  • Asset criticality
  • Application sensitivity
  • Data classification
  • Business function
  • Threat activity
  • Existing controls
  • Compensating controls
  • Remediation complexity
  • Release impact

Finding Count

to:

Risk-Based Software Security Prioritization
CDevSOM®

Risk-Based Software Security Prioritization

A mature program should help answer:

  • Which applications create the greatest risk?
  • Which vulnerabilities deserve priority?
  • Which risks should block a release?
  • Which risks can be accepted temporarily?
  • Who has authority to approve exceptions?
  • How long can exceptions remain open?
  • How should residual risk be tracked?
Security Must Become Part of Delivery Governance
CDevSOM®

Security Must Become Part of Delivery Governance

A strong DevSecOps program requires more than security scanners.

It requires governance.

Organizations must establish:

CDevSOM® develops managers capable of building and governing these structures.

  • Secure-development standards
  • Security requirements
  • Pipeline requirements
  • Testing requirements
  • Minimum control baselines
  • Release criteria
  • Risk thresholds
  • Exception processes
  • Remediation expectations
  • Ownership
  • Accountability
  • Escalation
  • Metrics
  • Assurance
DevSecOps Is a Shared Enterprise Responsibility
CDevSOM®

DevSecOps Is a Shared Enterprise Responsibility

Secure software delivery requires collaboration among:

Software Engineering

Build and maintain applications.

Application Security

Define and support software-security practices.

Cybersecurity

Manage broader enterprise security risk.

DevOps and Platform Engineering

Build and operate delivery platforms.

Cloud Engineering

Provide cloud infrastructure and services.

Operations and Reliability Teams

Operate production services and manage availability.

Product Management

Prioritize features, security, and business outcomes.

Risk and Compliance

Interpret enterprise obligations and risk tolerances.

Executive Leadership

Provide resources, direction, accountability, and risk oversight.

The DevSecOps manager must align these groups around common objectives.

Secure Software Delivery Must Be Measurable
CDevSOM®

Secure Software Delivery Must Be Measurable

Organizations often measure activity rather than effectiveness.

Examples of activity measures include:

These measures can be useful, but they do not necessarily answer whether software risk is improving.

CDevSOM® emphasizes measures such as:

The progression is:

Security Activity → Control Performance → Risk Reduction → Business Outcome

  • Number of scans
  • Number of pipeline executions
  • Number of security findings
  • Number of applications tested
  • Security-test coverage
  • Time to remediate critical vulnerabilities
  • Vulnerability recurrence
  • Release-blocking findings
  • Exception age
  • Secrets-exposure trends
  • Dependency risk
  • Pipeline-control coverage
  • Signed-artifact coverage
  • SBOM coverage
  • Production vulnerability trends
  • Developer remediation performance
  • Security-control effectiveness
  • Mean time to resolve software-security issues
DevSecOps Must Protect the Software Supply Chain
CDevSOM®

DevSecOps Must Protect the Software Supply Chain

Modern organizations do not build software entirely from internal source code.

Applications increasingly depend on:

Managers must therefore govern the complete software supply chain.

Questions include:

The management progression becomes:

  • Open-source packages
  • Third-party libraries
  • Public repositories
  • Package managers
  • Build tools
  • CI/CD platforms
  • Container images
  • External APIs
  • Cloud services
  • SaaS platforms
  • Development tools
  • Code-generation tools
  • Which package repositories are approved?
  • Are dependencies continuously monitored?
  • Are SBOMs generated and maintained?
  • Are artifacts signed?
  • Can build provenance be verified?
  • Are external components trusted?
  • Can vulnerable components be identified quickly?
  • Are development tools themselves secured?
  • Are software suppliers evaluated?
  • Are pipeline dependencies monitored?
  • Know the Components → Trust the Source → Verify the Build → Protect the Artifact → Monitor the Risk
Cloud-Native Delivery Requires New Governance
CDevSOM®

Cloud-Native Delivery Requires New Governance

Cloud-native development introduces new technologies and operating models.

A single application may involve:

Cloud Services + Containers + Kubernetes + APIs + Microservices + Infrastructure as Code + Serverless + Managed Databases + Identity Services

Managers must govern this complexity.

CDevSOM® addresses questions such as:

  • Are cloud-security responsibilities understood?
  • Are Infrastructure as Code templates reviewed?
  • Are container images sourced from trusted registries?
  • Are workloads excessively privileged?
  • Are APIs inventoried and secured?
  • Are service identities controlled?
  • Are secrets centrally managed?
  • Are production environments monitored?
  • Are cloud-native controls applied consistently?
Automation Must Be Governed as a Control System
CDevSOM®

Automation Must Be Governed as a Control System

Automation is one of the greatest strengths of DevSecOps.

It can also become one of its greatest risks.

A misconfigured automated process can deploy a weakness to hundreds of environments faster than a human administrator ever could.

Managers must therefore evaluate automation based on:

Authority

What can the automation do?

Scope

How many systems can it affect?

Validation

How is output verified?

Recovery

Can changes be rolled back?

Auditability

Can the organization determine what occurred?

Segregation

Are approvals and privileges appropriate?

Security

Are credentials and secrets protected?

CDevSOM® Automation Principle

Automate at Scale → Validate Continuously → Maintain Governance → Preserve Recovery

Developer Experience Matters
CDevSOM®

Developer Experience Matters

Security programs can fail when controls make normal development excessively difficult.

If security tools produce:

developers may lose trust in the system.

CDevSOM® therefore recognizes developer experience as part of security effectiveness.

Managers must ask:

Strong DevSecOps governance should make the secure path the easiest reasonable path.

  • Too many false positives
  • Poor explanations
  • Slow scans
  • Duplicate findings
  • Unclear remediation guidance
  • Excessive manual approvals
  • Are findings actionable?
  • Are results delivered quickly?
  • Are tools integrated with developer workflows?
  • Are duplicate findings reduced?
  • Do developers understand what to fix?
  • Are security standards practical?
  • Are security champions available?
  • Is remediation support accessible?
Governing Secure Software Delivery at Enterprise Scale
CDevSOM®

Governing Secure Software Delivery at Enterprise Scale

The certification focuses on strategy, governance, accountability, risk, performance, investment, workforce, and transformation.

CDevSOM® Prepares Managers to Answer Critical Enterprise Questions
CDevSOM®

CDevSOM® Prepares Managers to Answer Critical Enterprise Questions

01 / 04

Strategy

  • Is DevSecOps aligned with business strategy?
  • What maturity level should the organization achieve?
  • Which capabilities should be standardized?
  • Which development environments require different approaches?
  • What should the DevSecOps roadmap include?
02 / 04

Governance

  • Are roles and responsibilities clear?
  • Who owns application-security risk?
  • Who approves exceptions?
  • Which security controls are mandatory?
  • Which controls can be risk-based?
  • What evidence must teams retain?
  • How should policy violations be handled?
03 / 04

Secure Development

  • Are secure-development standards consistently applied?
  • Is threat modeling required for high-risk applications?
  • Are security requirements incorporated into design?
  • Are developers receiving appropriate secure-coding guidance?
  • Are security champions effective?
04 / 04

Security Testing

  • Which applications require SAST?
  • Where is DAST appropriate?
  • When should SCA run?
  • Which security tests should block a release?
  • How should false positives be handled?
  • Are test results actionable?
  • Are security gates appropriately calibrated?

Swipe or scroll sideways to see each part →

CI/CD Pipeline Governance
CDevSOM®

CI/CD Pipeline Governance

Pipelines are highly privileged systems.

They may possess access to:

CDevSOM® prepares managers to govern:

The question is not merely:

  • Source code
  • Secrets
  • Cloud environments
  • Registries
  • Artifacts
  • Deployment systems
  • Production environments
  • Pipeline identities
  • Service accounts
  • Secrets
  • Permissions
  • Branch controls
  • Build environments
  • Security testing
  • Approval processes
  • Artifacts
  • Signing
  • Deployment
  • Rollback
  • Audit trails

“Does the pipeline work?”

It is:

“Can we trust the pipeline to produce and deploy secure software?”

Application Vulnerability Governance
CDevSOM®

Application Vulnerability Governance

CDevSOM® prepares managers to establish structured approaches for:

Managers must create a model that distinguishes:

Technical Severity from Enterprise Risk.

  • Severity
  • Exploitability
  • Reachability
  • Business criticality
  • Exposure
  • Remediation deadlines
  • Exceptions
  • Compensating controls
  • Risk acceptance
  • Escalation
SBOM Governance
CDevSOM®

SBOM Governance

Software Bills of Materials can provide visibility into application components.

CDevSOM® managers may need to establish:

The objective is not merely to generate SBOM files.

It is to use component transparency to improve software-risk decisions.

  • Which applications require SBOMs
  • When SBOMs are generated
  • How they are updated
  • Where they are stored
  • How vulnerabilities are correlated
  • Who can access them
  • How supplier SBOMs are evaluated
  • How SBOM information supports incident response
Artifact Trust and Provenance
CDevSOM®

Artifact Trust and Provenance

Secure software delivery requires confidence that an artifact is the software the organization intended to build.

Managers must consider:

The trust progression becomes:

Trusted Source → Trusted Build → Trusted Artifact → Trusted Deployment

  • Signing
  • Hashing
  • Build provenance
  • Trusted repositories
  • Artifact registries
  • Build environments
  • Access controls
  • Release approvals
  • Tamper detection
  • Deployment validation
Vulnerability and Exception Governance
CDevSOM®

Vulnerability and Exception Governance

Not every vulnerability can be remediated immediately.

Managers therefore need consistent processes for:

An exception should never simply mean:

“We decided not to fix it.”

It should mean:

  • Risk assessment
  • Remediation timelines
  • Business justification
  • Compensating controls
  • Exception approval
  • Expiration
  • Revalidation
  • Escalation
  • Closure
  • “We understand the risk, have documented the decision, established compensating controls where appropriate, assigned accountability, and defined when the decision must be reviewed.”
Cloud-Native and Platform Governance
CDevSOM®

Cloud-Native and Platform Governance

CDevSOM® prepares leaders to govern:

The goal is to enable teams to innovate within defined and secure guardrails.

  • Public cloud
  • Private cloud
  • Hybrid cloud
  • Containers
  • Kubernetes
  • APIs
  • Microservices
  • Serverless
  • Infrastructure as Code
  • Platform engineering
  • Developer platforms
Build, Buy, or Platform Decisions
CDevSOM®

Build, Buy, or Platform Decisions

Managers must evaluate whether capabilities should be:

Relevant factors include:

  • Built internally
  • Purchased
  • Delivered through SaaS
  • Integrated into development platforms
  • Provided through cloud services
  • Outsourced
  • Consolidated
  • Capability + Security + Integration + Cost + Developer Experience + Scalability + Vendor Risk + Value
DevSecOps Tooling Strategy
CDevSOM®

DevSecOps Tooling Strategy

More tools do not automatically create stronger security.

Excessive tooling can produce:

CDevSOM® prepares managers to rationalize tooling around capability requirements.

The progression is:

Need → Capability → Tool → Integration → Governance → Measurement → Value

  • Duplicate findings
  • Integration problems
  • Licensing cost
  • Developer friction
  • Operational overhead
  • Inconsistent policies
  • Fragmented data
AI-Generated Code Changes Software Risk
CDevSOM®

AI-Generated Code Changes Software Risk

Generative AI can accelerate software development, but it can also introduce risk.

AI-generated code may contain:

Managers must therefore establish expectations for:

  • Security weaknesses
  • Outdated patterns
  • Invented APIs
  • Unsafe dependencies
  • Licensing concerns
  • Sensitive information
  • Poor error handling
  • Incorrect access controls
  • Human review
  • Secure coding
  • Testing
  • Data handling
  • Approved AI tools
  • Code ownership
  • Intellectual-property considerations
  • Security validation
  • Accountability

CDevSOM® AI Development Principle

Accelerate Development → Validate the Code → Protect the Data → Maintain Human Accountability

Agentic Development and Emerging Risk
CDevSOM®

Agentic Development and Emerging Risk

AI systems are increasingly capable of performing multi-step development activities.

Such systems may:

This creates new governance questions:

CDevSOM® prepares managers to evaluate these emerging risks responsibly.

  • Generate code
  • Modify repositories
  • Execute tests
  • Create infrastructure
  • Open pull requests
  • Deploy software
  • Remediate findings
  • What authority should AI agents have?
  • Which repositories can they access?
  • Can they deploy to production?
  • What approvals are required?
  • How are actions logged?
  • How are secrets protected?
  • Who is accountable for changes?
  • What happens when an automated decision is wrong?
DevSecOps Workforce Leadership
CDevSOM®

DevSecOps Workforce Leadership

Technology does not create a successful DevSecOps program by itself.

Organizations need people with capabilities spanning:

Managers must determine:

  • Software engineering
  • Application security
  • Cloud
  • Infrastructure
  • CI/CD
  • Containers
  • Automation
  • Cybersecurity
  • Risk
  • Platform engineering
  • Which skills are required?
  • Which skills are missing?
  • Which roles should be centralized?
  • Which responsibilities belong within product teams?
  • Should security champions be established?
  • Which capabilities should be outsourced?
  • How should teams be trained?
  • How should knowledge be shared?
Security Champions
CDevSOM®

Security Champions

Security champions can help distribute security knowledge across development teams.

Effective programs may support:

CDevSOM® prepares managers to govern security-champion programs as part of broader workforce strategy.

  • Local security expertise
  • Developer education
  • Threat-modeling assistance
  • Secure-design guidance
  • Faster remediation
  • Collaboration with application security
  • Security awareness
Executive Communication
CDevSOM®

Executive Communication

Executives generally do not need detailed lists of static-analysis findings.

They need to understand:

The DevSecOps manager must translate:

Technical Findings → Software Risk → Business Impact → Management Options → Executive Decision

  • Are our critical applications secure?
  • Is software risk increasing or decreasing?
  • Are high-risk vulnerabilities being remediated?
  • Can we trust our software supply chain?
  • Are security controls delaying delivery unnecessarily?
  • Are investments producing measurable improvement?
  • What risks require leadership decisions?
  • Are AI-assisted development tools introducing new exposure?
CDevSOM® Management Decision Framework
CDevSOM®

CDevSOM® Management Decision Framework

CDevSOM® develops managers capable of evaluating secure software delivery through several interconnected perspectives.

Strategy

Does DevSecOps support organizational objectives?

Security

Are software risks identified and reduced effectively?

Delivery

Can teams release software safely and efficiently?

Governance

Are accountability, standards, and decisions clear?

Automation

Are controls scalable and repeatable?

Developer Experience

Are security practices usable within normal workflows?

Resilience

Can the organization respond and recover when delivery systems fail?

Investment

Are tools and platforms creating sufficient value?

Workforce

Does the organization have the right capabilities?

Measurement

Can leadership demonstrate that DevSecOps is improving outcomes?

CDevSOM® Management Value Proposition
CDevSOM®

CDevSOM® Management Value Proposition

CDevSOM® integrates:

DevSecOps Strategy + Secure SDLC Governance + Application Security + CI/CD + Cloud-Native Governance + Software Supply Chain + Automation + Risk + Metrics + AI + Workforce + Executive Leadership

Its central management objective is:

Align Secure Delivery → Govern Software Risk → Scale Trusted Automation → Assure the Supply Chain → Measure Outcomes → Lead Transformation → Protect Enterprise Value

CDevSOP® → CDevSOM® Professional Progression
CDevSOM®
  • CDevSOP®
  • CDevSOM® Professional Progression

CDevSOP® — Professional Level

Plan • Build • Test • Secure • Deploy • Monitor • Remediate • Improve

Primary objective:

Deliver Secure Software Effectively

CDevSOM® — Advanced / Management Level

Assess • Strategize • Govern • Prioritize • Assure • Measure • Lead • Transform

Primary objective:

Govern Secure Software Delivery at Enterprise Scale

The progression represents a shift from:

Applying DevSecOps Controls → Governing Enterprise DevSecOps Capability

CDevSOM® Professional Identity
CDevSOM®

CDevSOM® Professional Identity

A CDevSOM® manager should be capable of asking:

That is the advanced leadership capability CDevSOM® is designed to develop and validate.

CDevSOM® — Govern Secure Delivery. Reduce Software Risk. Scale Trusted Automation. Lead DevSecOps Transformation.

  • Are we reducing meaningful software risk?
  • Are secure-development requirements consistent?
  • Can we trust our pipelines?
  • Can we trust our artifacts?
  • Are dependencies and suppliers appropriately governed?
  • Are security findings prioritized intelligently?
  • Are risk exceptions controlled?
  • Are developers receiving useful security feedback?
  • Are security tools integrated effectively?
  • Are our automation processes safe?
  • Are cloud-native environments appropriately governed?
  • Are APIs adequately protected?
  • Do we have software-component visibility?
  • Is developer experience improving?
  • Are our metrics demonstrating real progress?
  • Are our investments producing value?
  • Are AI-assisted development practices appropriately governed?
  • Does executive leadership understand our software risk?
CDevSOP® → CDevSOM®
CDevSOM®

CDevSOP® → CDevSOM®

Equivalent qualifying experience in:

may satisfy applicable IBACTP® eligibility requirements.

Candidates should possess sufficient technical understanding to evaluate secure-development practices, question pipeline designs, interpret security findings, and challenge recommendations appropriately.

  • DevSecOps
  • DevOps
  • Software engineering
  • Application security
  • Cloud engineering
  • Platform engineering
  • Security engineering
  • Product security
  • Software architecture
  • Technology risk
  • IT management
  • Engineering management
Tools, Technologies, and Enterprise DevSecOps Environments
CDevSOM®

Tools, Technologies, and Enterprise DevSecOps Environments

CDevSOM® is vendor-neutral, but managers are expected to understand technology categories such as:

Source Control

GitHub • GitLab • Bitbucket • Enterprise Repository Platforms

CI/CD

Jenkins • GitHub Actions • GitLab CI/CD • Azure DevOps • CircleCI • Equivalent Platforms

Security Testing

SAST • DAST • SCA • IAST Concepts • Secrets Scanning • API Security Testing

Cloud and Infrastructure

AWS • Azure • Google Cloud • Private Cloud • Terraform/OpenTofu • Ansible

Containers

Docker • Kubernetes • Registries • Container Security • Runtime Protection

Software Supply Chain

SBOM • Signing • Provenance • Artifact Repositories • Package Registries

Observability

Prometheus • Grafana • OpenTelemetry • SIEM • Application Monitoring

AI and Automation

AI Coding Assistants • Intelligent Testing • Automated Remediation • Security Copilots • Agentic Workflows

Managers focus on:

Selection → Integration → Governance → Automation → Risk → Performance → Developer Experience → Value

Flexible CDevSOM® Certification Assessment
CDevSOM®

Flexible CDevSOM® Certification Assessment

Option 1 — CDevSOM® Certification Examination

Recommended structure:

Assessment emphasis:

Strategy • Governance • Secure SDLC • Pipeline Decisions • Software Risk • Supply Chain • Automation • Metrics • AI • Leadership

  • 100 questions
  • Advanced multiple-choice and scenario-based management questions
  • 90 minutes
  • Closed book
  • Secure online proctoring or approved testing center
  • Recommended passing score: 70%

Option 2 — Enterprise DevSecOps Management Capstone

Eligible candidates in approved instructor-led pathways may complete the Enterprise DevSecOps Management Capstone.

The Capstone may integrate:

Maturity Assessment → Strategy → Secure SDLC Governance → Pipeline Architecture → Supply-Chain Risk → Metrics → Executive Recommendation

Certification Value Proposition
CDevSOM®

Certification Value Proposition

  • CDevSOP® Professional Objective

CDevSOP® Integrates

Secure Development + CI/CD + Application Security + Cloud + IaC + Containers + APIs + Supply Chain + Monitoring + Automation + AI

Build Securely → Test Continuously → Deploy Safely → Monitor Effectively → Remediate Rapidly → Improve Continuously
CDevSOM®
  • Build Securely
  • Test Continuously
  • Deploy Safely
  • Monitor Effectively
  • Remediate Rapidly
  • Improve Continuously
  • CDevSOM® Leadership Objective

CDevSOM® Integrates

DevSecOps Strategy + Governance + AppSec + Pipeline Governance + Cloud-Native Risk + Supply Chain + Investment + Metrics + AI + Workforce + Executive Leadership

Certified DevSecOps Manager (CDevSOM®)
CDevSOM®

Certified DevSecOps Manager (CDevSOM®)

Govern Secure Delivery. Manage Software Risk. Lead DevSecOps Transformation.

The employment outlook for DevSecOps managers is supported by growth in technology management, software engineering, cybersecurity, cloud computing, application security, and enterprise automation.

There is no separate BLS occupational classification for “DevSecOps Manager.” Positions with CDevSOM®-aligned responsibilities may be classified under titles such as:

The most relevant official management benchmark is Computer and Information Systems Managers.

  • DevSecOps Manager
  • DevOps Manager
  • Application Security Manager
  • Software Engineering Manager
  • Security Engineering Manager
  • Cloud Security Manager
  • Platform Engineering Manager
  • Product Security Manager
  • Engineering Manager
  • Director of DevSecOps
  • Director of Application Security
  • Director of Platform Engineering
  • Director of Software Engineering
Programme Facts
CDevSOM®

U.S. Management Employment Outlook · 667,100 Computer and Information Systems Manager positions in 2024 · 768,700 by 2034 · 101,600 additional management positions · 15% from 2024 to 2034 · 55,600 openings per year

U.S. Management Employment Outlook

BLS reports approximately:

667,100 Computer and Information Systems Manager positions in 2024

and projects employment to reach approximately:

768,700 by 2034

This represents approximately:

101,600 additional management positions

and projected growth of:

15% from 2024 to 2034

(Bureau of Labor Statistics)

That growth is approximately five times the projected overall U.S. occupational growth rate.

BLS projects approximately:

55,600 openings per year

for computer and information systems managers over the decade. (Bureau of Labor Statistics)

Why Technology-Management Demand Is Growing
CDevSOM®

Why Technology-Management Demand Is Growing

BLS attributes expected management growth partly to the increasing complexity and importance of technology throughout the economy.

Organizations are expanding investments in areas including:

and require managers who can plan and oversee implementation. (Bureau of Labor Statistics)

This aligns closely with CDevSOM® because DevSecOps managers increasingly oversee combinations of:

Software Engineering + Security + Cloud + Automation + Risk + Governance

  • Cloud computing
  • Cybersecurity
  • Digital platforms
  • Artificial intelligence
Management Demand Is Reinforced by Cybersecurity Skills Shortages
CDevSOM®

Management Demand Is Reinforced by Cybersecurity Skills Shortages

ISC2's 2025 research indicates that organizations are increasingly struggling not simply to hire more cybersecurity personnel, but to obtain the specific skills required to secure rapidly changing technology environments.

Almost 59% of respondents reported critical or significant cybersecurity skills needs, while 95% reported at least one skills need. (ISC2)

This increases the importance of leaders who can:

These are central CDevSOM® management competencies.

  • Build internal capability
  • Develop staff
  • Select technologies
  • Prioritize security investments
  • Automate controls
  • Manage external providers
  • Govern software risk
  • Develop sustainable operating models
CDevSOM® Salary Outlook
CDevSOM®

CDevSOM® Salary Outlook

Official Technology-Management Benchmark

According to BLS, the median annual wage for Computer and Information Systems Managers was:

$171,200 in May 2024
CDevSOM®

$171,200 in May 2024

(Bureau of Labor Statistics)

More recent BLS wage data for May 2025 reported:

  • Approximately 670,570 employed computer and information systems managers
  • Mean hourly wage of approximately $92.39
  • Mean annual wage of approximately:
Programme Facts
CDevSOM®

$192,160 · DevSecOps Management Job-Posting Benchmarks · $139,600–$278,300 · $122,900–$216,660

$192,160

(Bureau of Labor Statistics)

These figures provide an official benchmark for senior technology-management roles aligned with CDevSOM® responsibilities.

DevSecOps Management Job-Posting Benchmarks

Recent employer postings demonstrate the compensation potential for DevSecOps-specific leadership.

A Lockheed Martin DevSecOps First Line Manager posting in 2026 listed annual compensation of approximately:

$139,600–$278,300

with a stated range of approximately $139,600–$246,100 for specified states and markets. (Indeed)

A separate Lockheed Martin DevSecOps Engineering Manager role listed approximately:

$122,900–$216,660

per year. (Indeed)

A Deloitte Cloud Security Architect – DevSecOps Manager posting listed approximately:

$144,200–$265,600
CDevSOM®

$144,200–$265,600

per year. (Indeed)

These figures are examples of individual current postings rather than nationwide averages, but they demonstrate the premium that may be associated with senior DevSecOps, cloud-security, engineering-management, and architecture responsibilities.

Broader DevOps Management Compensation
CDevSOM®

Broader DevOps Management Compensation

For broader comparison, Glassdoor's 2026 DevOps Manager data showed recent reported compensation ranges such as approximately:

Glassdoor also reported that the Information Technology industry was its highest-paying industry category for DevOps Managers, with median total pay around $268,750. (Glassdoor)

Because this is self-reported market compensation rather than official government wage data, it should be treated as supplementary rather than definitive.

  • $148,000–$172,000 in Denver for a professional with 15+ years of experience
  • $164,000–$190,000 in Herndon, Virginia
  • $147,000–$171,000 in Eagan, Minnesota
Geography Can Significantly Affect Technology-Management Pay
CDevSOM®

Geography Can Significantly Affect Technology-Management Pay

BLS 2025 regional wage data illustrate significant location-related differences.

For Computer and Information Systems Managers, mean annual wages included approximately:

(Bureau of Labor Statistics)

This demonstrates why DevSecOps management compensation can vary substantially by geographic market.

U.S. Metropolitan AreaMean Annual Wage
San Francisco–Oakland–Fremont $249,040
New York–Newark–Jersey City $224,990
Chicago–Naperville–Elgin $184,810
Geography Also Affects Technical DevSecOps-Related Roles
CDevSOM®

Geography Also Affects Technical DevSecOps-Related Roles

BLS May 2025 data for the San Jose technology market illustrate the compensation potential of advanced technical roles:

(Bureau of Labor Statistics)

In Raleigh-Cary, where technology employment is also concentrated, BLS reported mean annual wages of approximately:

(Bureau of Labor Statistics)

These differences highlight the influence of location, industry concentration, experience, and specialization.

  • Software Developers: approximately $221,710 mean annual wage
  • Information Security Analysts: approximately $196,700
  • Computer Network Architects: approximately $192,650
  • Computer occupations, all other: approximately $195,680
  • Software Developers: $136,640
  • Information Security Analysts: $132,540
  • Computer Network Architects: $123,850
  • Computer Systems Analysts: $114,280
Factors That Influence DevSecOps Compensation
CDevSOM®

Factors That Influence DevSecOps Compensation

Actual compensation for both CDevSOP®- and CDevSOM®-aligned roles may vary based on:

Experience

Senior engineering and management responsibilities generally command higher compensation.

Technical Depth

Expertise in cloud, Kubernetes, application security, Infrastructure as Code, CI/CD, or software-supply-chain security may increase market value.

Management Scope

Managing larger teams, critical platforms, global delivery functions, or enterprise application-security programs may increase compensation.

Geographic Location

Major technology and financial centers frequently offer higher nominal salaries.

Industry

Financial services, technology, aerospace, defense, consulting, healthcare, and regulated industries may compensate specialized skills differently.

Security Clearance

Certain government and defense roles may attach substantial value to active security clearances and specialized technical experience.

Cloud Expertise

Multi-cloud and cloud-security capabilities remain in strong demand.

Software Security Expertise

Application security, secure architecture, threat modeling, and supply-chain security can differentiate DevSecOps professionals.

AI Competency

AI-assisted development and secure adoption of generative AI are becoming important differentiators.

Potential Careers for CDevSOM® Professionals
CDevSOM®

Potential Careers for CDevSOM® Professionals

CDevSOM® competencies may support progression toward roles such as:

  • DevSecOps Manager
  • DevOps Manager
  • Application Security Manager
  • Product Security Manager
  • Software Security Manager
  • Platform Engineering Manager
  • Cloud Security Manager
  • Security Engineering Manager
  • Software Engineering Manager
  • Site Reliability Engineering Manager
  • Cloud Engineering Manager
  • Secure Software Development Manager
  • Software Supply-Chain Security Manager
  • Technology Risk Manager
  • Director of DevSecOps
  • Director of Application Security
  • Director of Product Security
  • Director of Platform Engineering
  • Director of Software Engineering
  • Head of DevSecOps
  • Head of Application Security
CDevSOM® Employment Outlook Summary
CDevSOM®

CDevSOM® Employment Outlook Summary

15%

Projected growth for Computer and Information Systems Managers, 2024–2034. (Bureau of Labor Statistics)

101,600

Projected additional U.S. computer and information systems management jobs by 2034. (Bureau of Labor Statistics)

55,600

Average projected annual management openings over the decade. (Bureau of Labor Statistics)

$192,160

May 2025 mean annual wage for U.S. Computer and Information Systems Managers. (Bureau of Labor Statistics)

$249,040

May 2025 mean annual wage for Computer and Information Systems Managers in the San Francisco metropolitan area. (Bureau of Labor Statistics)

$144,200–$265,600

Recent posted salary range for a Cloud Security Architect–DevSecOps Manager position. (Indeed)

59%

Cybersecurity professionals reporting critical or significant skills needs in ISC2's 2025 global study. (ISC2)

95%

Respondents reporting at least one cybersecurity skills need. (ISC2)

CDevSOP® → CDevSOM® Career and Earnings Progression
CDevSOM®

CDevSOP® → CDevSOM® Career and Earnings Progression

Career DimensionCDevSOP® — ProfessionalCDevSOM® — Manager
Primary Career Focus Secure engineering and delivery Enterprise secure-delivery leadership
Closest BLS Benchmark Software Developer / Information Security Analyst Computer & Information Systems Manager
Projected BLS Growth 15.8% software development / 28.5% information security 15% management
Relevant Annual Openings 115,200 software developers; 16,000 security analysts 55,600 managers
BLS Wage Benchmark $133,080 software developer median; $124,910 security analyst median $171,200 management median
2025 BLS Mean Benchmark $148,100 software developers $192,160 technology managers
Current DevSecOps Market Example $137,495 average DevSecOps Engineer estimate $144,200–$265,600 recent manager posting
Career Direction Build, secure, automate Strategize, govern, measure, lead
Website Marketing Callout
CDevSOM®

Website Marketing Callout

A Career Positioned Where High-Growth Technology Disciplines Converge

DevSecOps professionals operate where some of today's most important technology capabilities meet:

Software + Cybersecurity + Cloud + Automation + AI
CDevSOM®

Software + Cybersecurity + Cloud + Automation + AI

Official U.S. projections show strong growth for software developers, information-security professionals, and technology managers, while global cybersecurity workforce research continues to identify significant shortages in skills directly relevant to DevSecOps—including cloud security, application security, AI, security engineering, and risk assessment. (Bureau of Labor Statistics)

  • CDevSOP®
  • Build the Skills Organizations Need to Deliver Software Securely.
  • CDevSOM®
  • Develop the Leadership Capability to Govern Secure Software Delivery at Enterprise Scale.
CDevSOP® → CDevSOM®
CDevSOM®
  • CDevSOP®
  • CDevSOM®

Build Securely. Advance Strategically. Lead Secure Digital Delivery.

Employment projections and BLS wage figures are U.S. occupational statistics. DevSecOps-specific salary figures are third-party market estimates or examples from individual job postings and should not be interpreted as guaranteed compensation. Salaries vary by experience, geography, employer, industry, responsibilities, education, certifications, and other factors.

CDevSOP® → CDevSOM®
CDevSOM®
  • CDevSOP®
  • CDevSOM®
  • From Secure Software Delivery Competency to Enterprise DevSecOps Leadership.
The examination

Exam & Certification Details

Everything you need to plan your sitting.

CDevSOM-200

Exam code for the Advanced Manager-level DevSecOps credential.

100 questions (maximum)

Multiple choice, completed in 120 minutes.

700 out of 1000

Passing score. Delivered in English.

Recommended experience

A minimum of five years of experience, including two years in a supervisory, lead or management role.

Where you sit it

IBACTP® approved testing centers and online proctored delivery

Staying certified

Three-year certification cycle with continuing professional education

Choose your route

Four ways to enroll. One credential.

Every route leads to the same CDevSOM® examination and the same designation.

Option 1

Self-Paced Learning

Self-study
$400 USD
  • Exam fee only
  • Complimentary course materials provided
Option 2

Virtual Instructor-Led Training

4 days
$1,200 USD
  • 4 days, 2 hours daily online
  • Includes all course materials + Exam
Select a Date and Purchase
Option 3

Bootcamps & Intensives

10 days
$1,800 USD
  • 10 days, 2 hours daily
  • Includes all course materials + Exam
Select a Date and Purchase
Option 4

Corporate Training

Your schedule
Fees negotiable
  • Certify a whole team on a schedule that suits your organization
  • Fees depend on the team's size / number
Request a Team Quote
Progression

Your Certification Pathway

Start as a Professional. Advance as a Leader.

Questions

Frequently Asked Questions — CDevSOP® & CDevSOM®

What is CDevSOP®?

CDevSOP® is a vendor-neutral professional DevSecOps certification focused on secure software development, CI/CD, application security, cloud, Infrastructure as Code, containers, APIs, software supply chains, automation, monitoring, and AI-assisted DevSecOps.

What is CDevSOM®?

CDevSOM® is an advanced DevSecOps management certification focused on strategy, secure SDLC governance, application-security leadership, pipeline governance, cloud-native risk, software supply-chain security, investment, metrics, AI, workforce leadership, and transformation.

How are CDevSOP® and CDevSOM® different?

CDevSOP® focuses primarily on implementing and operating secure software-delivery practices. CDevSOM® focuses on strategizing, governing, funding, measuring, and transforming enterprise DevSecOps capabilities.

Do I need CDevSOP® before CDevSOM®?

CDevSOP® is the recommended professional pathway. Equivalent qualifying experience in DevSecOps, DevOps, application security, cloud, software engineering, platform engineering, or management may satisfy applicable IBACTP® eligibility requirements.

Are the certifications vendor-neutral?

Yes. Both emphasize transferable competencies rather than one CI/CD platform, cloud provider, programming language, or security product.

Does CDevSOP® cover secure coding?

Yes. Secure coding, code review, repositories, secrets, source-control security, SAST, and developer security feedback are core areas.

Does CDevSOP® cover CI/CD?

Yes. Pipeline design, automated testing, security gates, secrets, artifacts, permissions, release controls, and secure deployment are central competencies.

Do the certifications cover cloud and Infrastructure as Code?

Yes. CDevSOP® focuses on practical secure implementation. CDevSOM® focuses on enterprise governance, standardization, risk, automation, investment, and assurance.

Do they cover containers and Kubernetes?

Yes. Container images, registries, orchestration, Kubernetes concepts, runtime security, and cloud-native risk are included.

Do they cover software supply-chain security?

Yes. Dependencies, package repositories, SCA, SBOMs, artifact integrity, signing, provenance, and third-party software risk are major areas.

Does CDevSOM® cover metrics?

Yes. Managers evaluate vulnerability trends, remediation performance, pipeline coverage, control effectiveness, developer experience, release risk, software supply chain exposure, maturity, and other KPIs/KRIs.

Do they cover AI?

Yes. CDevSOP® addresses AI-assisted coding, testing, vulnerability analysis, and automation. CDevSOM® addresses governance, AI-generated code risk, agentic development, reliability, human oversight, investment, and emerging risk.

How are candidates assessed?

Candidates may complete the applicable certification examination or, where eligible, complete the corresponding professional or management Capstone through an approved instructor-led pathway.

How long are the certifications valid?

The recommended credential cycle is three years, subject to applicable IBACTP® continuing professional education, ethics, certification-maintenance, and recertification policies.

28+ Certifications
14 Technology Disciplines
Global Recognition
Industry Validated
Your Career Our Mission