Develop Enterprise DevSecOps Strategy and Governance
Assess maturity, define strategic priorities, establish responsibilities, develop roadmaps, and align DevSecO…
CDevSOM® evaluates advanced management judgment across enterprise secure-delivery environments.
Lead Secure Delivery and Platform Engineering.
Develop the management knowledge and judgment to lead secure software delivery and platform engineering.
Assess maturity, define strategic priorities, establish responsibilities, develop roadmaps, and align DevSecO…
Establish secure-development requirements, threat-modeling expectations, testing strategies, remediation stan…
Evaluate pipeline architecture, identity, secrets, security gates, artifact integrity, automation, approvals…
Oversee cloud, IaC, containers, Kubernetes, APIs, microservices, runtime environments, and platform-engineeri…
Manage dependency security, SBOM strategy, package risk, provenance, artifact integrity, third-party componen…
Prioritize security tooling, evaluate providers, establish KPIs/KRIs, measure maturity, assess developer impa…
Evaluate AI-assisted development, generated code, automated remediation, intelligent testing, agentic develop…
Build capabilities, manage organizational change, strengthen collaboration, communicate software risk, and le…
For professionals who lead, govern and scale secure software delivery, CDevSOM® helps you advance your leadership.
DevSecOps Maturity and Current-State Assessment · Business Alignment and Enterprise DevSecOps Strategy · Governance, Roles, Accountability, and Decision Rights
Secure Development Policies and Standards · Threat Modeling and Secure Architecture Governance · SAST, DAST, SCA, and Testing Strategy
Enterprise CI/CD Architecture and Pipeline Governance · Identity, Secrets, Access, and Privilege Management · Security Gates, Policy Enforcement, and Automated Testing
Cloud Security and Shared-Responsibility Governance · Infrastructure as Code, Policy as Code, and Configuration Assurance · Container, Registry, and Kubernetes Security Governance
Open-Source and Third-Party Software Governance · SBOM Strategy and Software Component Transparency · Package Repositories, Trusted Sources, and Dependency Controls
DevSecOps Business Cases and Investment Prioritization · Security Tooling Strategy and Platform Rationalization · Vendor, Contract, and Service-Provider Governance
AI-Assisted Development and Engineering Productivity · AI-Generated Code Security and Validation · AI-Enabled Testing, Triage, and Remediation
DevSecOps Workforce Strategy and Organizational Design · Skills, Training, Security Champions, and Capability Development · Developer-Security Collaboration and Culture
Lead security across the entire software delivery lifecycle.
Choose the pathway that suits your learning journey.
Evaluate current maturity, software risk, capabilities, tooling, processes, and workforce.
Define target capabilities, priorities, operating models, and roadmaps.
Establish standards, accountability, decision rights, exceptions, and assurance.
Direct attention toward the applications, vulnerabilities, supply-chain risks, and capabilities that matter m…
Scale appropriate controls through secure and governed automation.
Determine whether controls, pipelines, artifacts, platforms, and delivery practices are operating effectively.
Earn a digital credential and certificate to showcase your achievement.
Certification Designation: CDevSOM®
Certification Level: Advanced / Management
Certification Body: International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)
Program Category: DevSecOps Strategy, Secure Software Governance, Cloud-Native Delivery & Technology Leadership
Delivery Format: Instructor-Led, Virtual Instructor-Led, Self-Paced, or Blended Learning
Advanced Manager level — Three-year certification cycle with continuing professional education
Recommended Training Duration: 50–60 Hours
Certification Examination: Proctored, advanced competency-based management examination
Alternative Assessment Pathway: Enterprise DevSecOps Management Capstone for eligible candidates in approved instructor-led pathways
Credential Renewal Cycle: 3 Years
Open any topic to read the complete program information.
CDevSOM® is designed for professionals such as:
1.1 DevSecOps Maturity and Current-State Assessment
1.2 Business Alignment and Enterprise DevSecOps Strategy
1.3 Governance, Roles, Accountability, and Decision Rights
1.4 Operating Models, Platform Teams, and Security Integration
1.5 Strategic Roadmaps and Transformation Planning
2.1 Secure Development Policies and Standards
2.2 Threat Modeling and Secure Architecture Governance
2.3 SAST, DAST, SCA, and Testing Strategy
2.4 Vulnerability Prioritization, Exceptions, and Risk Acceptance
2.5 Application Security Assurance and Continuous Improvement
3.1 Enterprise CI/CD Architecture and Pipeline Governance
3.2 Identity, Secrets, Access, and Privilege Management
3.3 Security Gates, Policy Enforcement, and Automated Testing
3.4 Artifact Integrity, Signing, Provenance, and Release Controls
3.5 Deployment Governance, Rollback, and Change Assurance
4.1 Cloud Security and Shared-Responsibility Governance
4.2 Infrastructure as Code, Policy as Code, and Configuration Assurance
4.3 Container, Registry, and Kubernetes Security Governance
4.4 API, Microservices, Service Identity, and Runtime Risk
4.5 Platform Engineering, Cloud-Native Architecture, and Resilience
5.1 Open-Source and Third-Party Software Governance
5.2 SBOM Strategy and Software Component Transparency
5.3 Package Repositories, Trusted Sources, and Dependency Controls
5.4 Artifact Provenance, Signing, and Integrity Assurance
5.5 Supply-Chain Risk Monitoring, Incident Response, and Improvement
6.1 DevSecOps Business Cases and Investment Prioritization
6.2 Security Tooling Strategy and Platform Rationalization
6.3 Vendor, Contract, and Service-Provider Governance
6.4 KPIs, KRIs, Maturity, and Software-Risk Metrics
6.5 Developer Experience, Performance, and Continuous Improvement
7.1 AI-Assisted Development and Engineering Productivity
7.2 AI-Generated Code Security and Validation
7.3 AI-Enabled Testing, Triage, and Remediation
7.4 Agentic Development, Automation, and Emerging Delivery Models
7.5 AI Governance, Reliability, Human Oversight, and Risk
8.1 DevSecOps Workforce Strategy and Organizational Design
8.2 Skills, Training, Security Champions, and Capability Development
8.3 Developer-Security Collaboration and Culture
8.4 Executive Reporting, Software Risk, and Business Communication
8.5 Change Leadership, Adoption, and Enterprise Transformation
Upon successful completion, participants will be able to:
Assess maturity, define strategic priorities, establish responsibilities, develop roadmaps, and align DevSecOps with organizational objectives.
Establish secure-development requirements, threat-modeling expectations, testing strategies, remediation standards, and risk-acceptance processes.
Evaluate pipeline architecture, identity, secrets, security gates, artifact integrity, automation, approvals, and deployment controls.
Oversee cloud, IaC, containers, Kubernetes, APIs, microservices, runtime environments, and platform-engineering security.
Manage dependency security, SBOM strategy, package risk, provenance, artifact integrity, third-party components, and supply-chain controls.
Prioritize security tooling, evaluate providers, establish KPIs/KRIs, measure maturity, assess developer impact, and evaluate program effectiveness.
Evaluate AI-assisted development, generated code, automated remediation, intelligent testing, agentic development, and emerging risk.
Build capabilities, manage organizational change, strengthen collaboration, communicate software risk, and lead DevSecOps transformation.
CDevSOM® evaluates advanced management judgment across enterprise secure-delivery environments.
Assess DevSecOps maturity, establish priorities, define operating models, and align software security with enterprise objectives.
Evaluate secure SDLC practices, testing strategies, vulnerabilities, exceptions, and risk-based release decisions.
Evaluate CI/CD architecture, security gates, identities, secrets, artifacts, approvals, automation, and deployment risk.
Assess cloud, IaC, container, API, Kubernetes, runtime, and platform-engineering risks.
Evaluate dependencies, SBOMs, package sources, artifact integrity, provenance, third-party components, and supply-chain exposure.
Evaluate security tools, vendors, business cases, developer friction, KPIs, KRIs, maturity, and risk-reduction outcomes.
Evaluate AI-generated code, intelligent automation, agentic development, reliability, human oversight, and emerging threats.
Evaluate workforce models, stakeholder priorities, transformation choices, executive communication, and risk decisions.
Assess → Strategize → Govern → Prioritize → Decide → Automate → Assure → Measure → Transform
1. Enterprise DevSecOps Strategy and Governance
Assess maturity, define enterprise DevSecOps strategy, establish governance, operating models, responsibilities, roadmaps, and transformation priorities.
2. Secure SDLC and Application Security Governance
Govern secure-development standards, threat modeling, code security, testing requirements, vulnerabilities, exceptions, and software-security assurance.
3. CI/CD, Automation, and Pipeline Governance
Govern pipeline architecture, identities, secrets, testing, approvals, release controls, artifact integrity, automation, and deployment risk.
4. Cloud-Native, Infrastructure, Container, and API Governance
Govern cloud, IaC, containers, Kubernetes, APIs, microservices, platform engineering, runtime security, and distributed systems.
5. Software Supply Chain and Third-Party Risk
Govern dependencies, open-source software, SBOMs, package repositories, artifact provenance, signing, third-party software, and supply-chain risk.
6. DevSecOps Investment, Metrics, Vendors, and Performance
Prioritize technology investments, manage vendors, establish KPIs/KRIs, assess developer experience, evaluate risk reduction, and measure program maturity.
7. AI-Enabled DevSecOps and Emerging Software Risk
Govern AI-assisted coding, generated code, security automation, intelligent testing, agentic development, model risk, and emerging delivery technologies.
8. Workforce, Culture, Executive Communication, and Transformation
Build DevSecOps capabilities, strengthen security culture, align development and security teams, communicate software risk, and lead transformation.
Assess → Strategize → Govern → Prioritize → Automate → Assure → Measure → Lead → Transform
The Certified DevSecOps Manager (CDevSOM®) validates advanced management competency in governing secure software delivery across enterprise development, cloud, application-security, automation, and software-supply-chain environments.
CDevSOM® prepares managers to move from:
to:
CDevSOM® is positioned at the advanced management level.
Recommended progression:
The CDevSOM® Body of Knowledge incorporates relevant principles and practices associated with:
Understand → Interpret → Assess → Prioritize → Govern → Assure → Measure → Improve
Alignment does not constitute formal accreditation, recognition, approval, endorsement, sponsorship, or affiliation.
The CDevSOP® and CDevSOM® certification frameworks may incorporate professional credentialing principles associated with:
The credentialing framework encompasses:
Job Task Analysis • Defined Competencies • Eligibility Standards • Validated Body of Knowledge • Examination Blueprint • SME Participation • Psychometric Principles • Examination Security • Identity Verification • Impartial Decisions • Appeals and Complaints • Professional Ethics • Continuing Education • Recertification • Credential Verification • Periodic Review • Continuous Improvement
Define → Validate → Assess → Certify → Maintain → Verify → Review → Improve
Alignment does not constitute accreditation, recognition, approval, or endorsement. Formal external status should be represented only after officially awarded by the applicable independent organization.
Both CDevSOP® and CDevSOM® are designed around transferable DevSecOps competencies rather than dependence on one:
Programming Language • CI/CD Platform • Cloud Provider • Application-Security Product • Container Platform • Source-Control Vendor • Infrastructure Automation Tool • AI Provider
This allows the certifications to remain applicable across different:
The certification develops competency across the complete management lifecycle:
Assess → Strategize → Govern → Prioritize → Automate → Assure → Measure → Communicate → Transform
Evaluate current maturity, software risk, capabilities, tooling, processes, and workforce.
Define target capabilities, priorities, operating models, and roadmaps.
Establish standards, accountability, decision rights, exceptions, and assurance.
Direct attention toward the applications, vulnerabilities, supply-chain risks, and capabilities that matter most.
Scale appropriate controls through secure and governed automation.
Determine whether controls, pipelines, artifacts, platforms, and delivery practices are operating effectively.
Use meaningful KPIs and KRIs to evaluate security, delivery, risk, and maturity.
Translate software risk and program performance into executive decisions.
Improve platforms, processes, teams, culture, and organizational capability.
Primary emphasis:
Plan • Code • Build • Test • Secure • Deploy • Monitor • Improve
↓
Primary emphasis:
Assess • Strategize • Govern • Prioritize • Automate • Assure • Measure • Lead • Transform
The progression moves professionals from integrating security into development and deployment workflows to governing secure software delivery, software risk, automation, platforms, investments, people, and enterprise transformation.
| Area | CDevSOP® — Professional | CDevSOM® — Advanced Manager |
|---|---|---|
| Primary Focus | Secure software delivery | Enterprise DevSecOps leadership |
| Secure SDLC | Apply | Govern |
| Threat Modeling | Perform/support | Establish standards |
| Secure Coding | Apply principles | Govern program |
| Source Control | Secure repositories | Govern enterprise controls |
| CI/CD | Build and secure pipelines | Govern pipeline architecture |
| SAST/DAST/SCA | Use and interpret | Define strategy and assurance |
| Cloud | Secure workloads | Govern cloud-native risk |
| IaC | Implement securely | Establish governance |
| Containers | Scan and secure | Govern platform risk |
| APIs | Test and secure | Govern enterprise requirements |
| Supply Chain | Identify and remediate | Govern enterprise risk |
| SBOM | Generate/interpret | Establish strategy |
| Vulnerabilities | Identify and prioritize | Govern risk acceptance |
| Automation | Implement | Strategize and govern |
| Metrics | Operational measures | KPIs, KRIs, maturity |
| AI | Apply and validate | Govern and invest |
| Vendors | Work with platforms | Govern tools/providers |
| Workforce | Professional contribution | Build capabilities |
| Communication | Technical reporting | Executive communication |
| Transformation | Support adoption | Lead enterprise transformation |
| Objective | Deliver Secure Software | Govern Secure Software Delivery |
Build Secure Software. Automate Security. Deliver with Confidence.
↓
Govern Secure Delivery. Reduce Software Risk. Lead DevSecOps Transformation.
Information technology is no longer simply an operational support function. Technology influences strategy, financial performance, cybersecurity, data, artificial intelligence, customer experience, regulatory exposure, operational resilience, and organizational transformation.
Organizations therefore need professionals who understand not only how technology is managed, but also how technology decisions should be governed, monitored, challenged, measured, and aligned with enterprise objectives.
The International Board of AI, Cybersecurity & Technology Professionals (IBACTP®) IT Governance Certification Pathway is designed around two progressive levels:
Understand • Assess • Apply • Monitor • Measure • Report • Improve
↓
Evaluate • Direct • Govern • Prioritize • Assure • Measure • Lead • Transform
Together, the certifications create a structured progression from applying IT-governance principles and supporting governance processes to designing, directing, measuring, and transforming enterprise governance of information and technology.
The Certified DevSecOps Manager (CDevSOM®) is an advanced, vendor-neutral management certification designed to validate the strategic, governance, risk, investment, performance, and leadership competencies required to manage secure software delivery across modern enterprise environments.
CDevSOM® is designed for experienced professionals responsible for ensuring that software development and delivery capabilities are not only fast and automated but also secure, resilient, measurable, governed, scalable, and aligned with business priorities.
The certification moves beyond the implementation of individual DevSecOps tools and controls.
It prepares managers to govern the complete enterprise delivery ecosystem, including:
CDevSOM® recognizes that modern software delivery sits at the intersection of:
The certification therefore integrates:
DevSecOps Strategy + Secure SDLC Governance + Application Security + Pipeline Governance + Cloud-Native Security + Software Supply Chain + Risk + Automation + Metrics + Vendors + AI Governance + Workforce + Executive Communication
CDevSOM® develops managers who can determine not only whether security controls exist, but whether the entire secure-delivery capability is producing measurable reductions in software risk without creating unnecessary barriers to innovation and delivery.
CDevSOM® Leadership Objective
Modern organizations increasingly operate through software.
Applications enable:
For many organizations, software is no longer merely a technology asset.
It is part of the business model itself.
A weakness in software delivery can therefore produce consequences far beyond the development team.
A vulnerable application may expose customer data.
A compromised build pipeline may distribute malicious software.
An insecure API may expose critical business functions.
A vulnerable third-party dependency may affect hundreds of applications simultaneously.
A leaked pipeline credential may provide privileged access to production systems.
An insecure cloud deployment may expose sensitive information.
An unreliable release process may interrupt critical business operations.
Software risk can therefore become:
CDevSOM® prepares managers to govern software delivery within this broader enterprise context.
Software organizations are under constant pressure to deliver:
These priorities can sometimes conflict.
Excessive security friction may slow development and encourage teams to bypass controls.
Insufficient security may increase enterprise risk.
Poorly implemented automation may scale mistakes.
Manual processes may become bottlenecks.
The DevSecOps manager must therefore create the right balance between:
Delivery Speed + Security + Reliability + Governance + Developer Experience + Business Value
The goal is not simply to add more controls.
It is to build a delivery system where appropriate controls are integrated, automated, risk-based, measurable, and usable.
A professional may ask:
The manager must ask:
A professional may ask:
The manager must ask:
A professional may ask:
The manager must ask:
A professional may ask:
The manager must ask:
This transition defines CDevSOM®.
Technical teams may generate thousands of security findings.
Not all findings have equal significance.
A manager must consider factors such as:
The management objective is to move from:
to:
A mature program should help answer:
A strong DevSecOps program requires more than security scanners.
It requires governance.
Organizations must establish:
CDevSOM® develops managers capable of building and governing these structures.
Secure software delivery requires collaboration among:
Build and maintain applications.
Define and support software-security practices.
Manage broader enterprise security risk.
Build and operate delivery platforms.
Provide cloud infrastructure and services.
Operate production services and manage availability.
Prioritize features, security, and business outcomes.
Interpret enterprise obligations and risk tolerances.
Provide resources, direction, accountability, and risk oversight.
The DevSecOps manager must align these groups around common objectives.
Organizations often measure activity rather than effectiveness.
Examples of activity measures include:
These measures can be useful, but they do not necessarily answer whether software risk is improving.
CDevSOM® emphasizes measures such as:
The progression is:
Security Activity → Control Performance → Risk Reduction → Business Outcome
Modern organizations do not build software entirely from internal source code.
Applications increasingly depend on:
Managers must therefore govern the complete software supply chain.
Questions include:
The management progression becomes:
Cloud-native development introduces new technologies and operating models.
A single application may involve:
Cloud Services + Containers + Kubernetes + APIs + Microservices + Infrastructure as Code + Serverless + Managed Databases + Identity Services
Managers must govern this complexity.
CDevSOM® addresses questions such as:
Automation is one of the greatest strengths of DevSecOps.
It can also become one of its greatest risks.
A misconfigured automated process can deploy a weakness to hundreds of environments faster than a human administrator ever could.
Managers must therefore evaluate automation based on:
What can the automation do?
How many systems can it affect?
How is output verified?
Can changes be rolled back?
Can the organization determine what occurred?
Are approvals and privileges appropriate?
Are credentials and secrets protected?
Automate at Scale → Validate Continuously → Maintain Governance → Preserve Recovery
Security programs can fail when controls make normal development excessively difficult.
If security tools produce:
developers may lose trust in the system.
CDevSOM® therefore recognizes developer experience as part of security effectiveness.
Managers must ask:
Strong DevSecOps governance should make the secure path the easiest reasonable path.
The certification focuses on strategy, governance, accountability, risk, performance, investment, workforce, and transformation.
Pipelines are highly privileged systems.
They may possess access to:
CDevSOM® prepares managers to govern:
The question is not merely:
It is:
“Can we trust the pipeline to produce and deploy secure software?”
CDevSOM® prepares managers to establish structured approaches for:
Managers must create a model that distinguishes:
Technical Severity from Enterprise Risk.
Software Bills of Materials can provide visibility into application components.
CDevSOM® managers may need to establish:
The objective is not merely to generate SBOM files.
It is to use component transparency to improve software-risk decisions.
Secure software delivery requires confidence that an artifact is the software the organization intended to build.
Managers must consider:
The trust progression becomes:
Trusted Source → Trusted Build → Trusted Artifact → Trusted Deployment
Not every vulnerability can be remediated immediately.
Managers therefore need consistent processes for:
An exception should never simply mean:
“We decided not to fix it.”
It should mean:
CDevSOM® prepares leaders to govern:
The goal is to enable teams to innovate within defined and secure guardrails.
Managers must evaluate whether capabilities should be:
Relevant factors include:
More tools do not automatically create stronger security.
Excessive tooling can produce:
CDevSOM® prepares managers to rationalize tooling around capability requirements.
The progression is:
Need → Capability → Tool → Integration → Governance → Measurement → Value
Generative AI can accelerate software development, but it can also introduce risk.
AI-generated code may contain:
Managers must therefore establish expectations for:
Accelerate Development → Validate the Code → Protect the Data → Maintain Human Accountability
AI systems are increasingly capable of performing multi-step development activities.
Such systems may:
This creates new governance questions:
CDevSOM® prepares managers to evaluate these emerging risks responsibly.
Technology does not create a successful DevSecOps program by itself.
Organizations need people with capabilities spanning:
Managers must determine:
Security champions can help distribute security knowledge across development teams.
Effective programs may support:
CDevSOM® prepares managers to govern security-champion programs as part of broader workforce strategy.
Executives generally do not need detailed lists of static-analysis findings.
They need to understand:
The DevSecOps manager must translate:
Technical Findings → Software Risk → Business Impact → Management Options → Executive Decision
CDevSOM® develops managers capable of evaluating secure software delivery through several interconnected perspectives.
Does DevSecOps support organizational objectives?
Are software risks identified and reduced effectively?
Can teams release software safely and efficiently?
Are accountability, standards, and decisions clear?
Are controls scalable and repeatable?
Are security practices usable within normal workflows?
Can the organization respond and recover when delivery systems fail?
Are tools and platforms creating sufficient value?
Does the organization have the right capabilities?
Can leadership demonstrate that DevSecOps is improving outcomes?
CDevSOM® integrates:
Its central management objective is:
Align Secure Delivery → Govern Software Risk → Scale Trusted Automation → Assure the Supply Chain → Measure Outcomes → Lead Transformation → Protect Enterprise Value
Plan • Build • Test • Secure • Deploy • Monitor • Remediate • Improve
Primary objective:
↓
Assess • Strategize • Govern • Prioritize • Assure • Measure • Lead • Transform
Primary objective:
The progression represents a shift from:
Applying DevSecOps Controls → Governing Enterprise DevSecOps Capability
A CDevSOM® manager should be capable of asking:
That is the advanced leadership capability CDevSOM® is designed to develop and validate.
CDevSOM® — Govern Secure Delivery. Reduce Software Risk. Scale Trusted Automation. Lead DevSecOps Transformation.
Equivalent qualifying experience in:
may satisfy applicable IBACTP® eligibility requirements.
Candidates should possess sufficient technical understanding to evaluate secure-development practices, question pipeline designs, interpret security findings, and challenge recommendations appropriately.
CDevSOM® is vendor-neutral, but managers are expected to understand technology categories such as:
Source Control
GitHub • GitLab • Bitbucket • Enterprise Repository Platforms
CI/CD
Jenkins • GitHub Actions • GitLab CI/CD • Azure DevOps • CircleCI • Equivalent Platforms
Security Testing
SAST • DAST • SCA • IAST Concepts • Secrets Scanning • API Security Testing
Cloud and Infrastructure
AWS • Azure • Google Cloud • Private Cloud • Terraform/OpenTofu • Ansible
Containers
Docker • Kubernetes • Registries • Container Security • Runtime Protection
Software Supply Chain
SBOM • Signing • Provenance • Artifact Repositories • Package Registries
Observability
Prometheus • Grafana • OpenTelemetry • SIEM • Application Monitoring
AI and Automation
AI Coding Assistants • Intelligent Testing • Automated Remediation • Security Copilots • Agentic Workflows
Managers focus on:
Selection → Integration → Governance → Automation → Risk → Performance → Developer Experience → Value
Recommended structure:
Assessment emphasis:
Strategy • Governance • Secure SDLC • Pipeline Decisions • Software Risk • Supply Chain • Automation • Metrics • AI • Leadership
Eligible candidates in approved instructor-led pathways may complete the Enterprise DevSecOps Management Capstone.
The Capstone may integrate:
Maturity Assessment → Strategy → Secure SDLC Governance → Pipeline Architecture → Supply-Chain Risk → Metrics → Executive Recommendation
Secure Development + CI/CD + Application Security + Cloud + IaC + Containers + APIs + Supply Chain + Monitoring + Automation + AI
DevSecOps Strategy + Governance + AppSec + Pipeline Governance + Cloud-Native Risk + Supply Chain + Investment + Metrics + AI + Workforce + Executive Leadership
The employment outlook for DevSecOps managers is supported by growth in technology management, software engineering, cybersecurity, cloud computing, application security, and enterprise automation.
There is no separate BLS occupational classification for “DevSecOps Manager.” Positions with CDevSOM®-aligned responsibilities may be classified under titles such as:
The most relevant official management benchmark is Computer and Information Systems Managers.
BLS reports approximately:
and projects employment to reach approximately:
This represents approximately:
and projected growth of:
(Bureau of Labor Statistics)
That growth is approximately five times the projected overall U.S. occupational growth rate.
BLS projects approximately:
for computer and information systems managers over the decade. (Bureau of Labor Statistics)
BLS attributes expected management growth partly to the increasing complexity and importance of technology throughout the economy.
Organizations are expanding investments in areas including:
and require managers who can plan and oversee implementation. (Bureau of Labor Statistics)
This aligns closely with CDevSOM® because DevSecOps managers increasingly oversee combinations of:
Software Engineering + Security + Cloud + Automation + Risk + Governance
ISC2's 2025 research indicates that organizations are increasingly struggling not simply to hire more cybersecurity personnel, but to obtain the specific skills required to secure rapidly changing technology environments.
Almost 59% of respondents reported critical or significant cybersecurity skills needs, while 95% reported at least one skills need. (ISC2)
This increases the importance of leaders who can:
These are central CDevSOM® management competencies.
According to BLS, the median annual wage for Computer and Information Systems Managers was:
(Bureau of Labor Statistics)
More recent BLS wage data for May 2025 reported:
(Bureau of Labor Statistics)
These figures provide an official benchmark for senior technology-management roles aligned with CDevSOM® responsibilities.
Recent employer postings demonstrate the compensation potential for DevSecOps-specific leadership.
A Lockheed Martin DevSecOps First Line Manager posting in 2026 listed annual compensation of approximately:
with a stated range of approximately $139,600–$246,100 for specified states and markets. (Indeed)
A separate Lockheed Martin DevSecOps Engineering Manager role listed approximately:
per year. (Indeed)
A Deloitte Cloud Security Architect – DevSecOps Manager posting listed approximately:
per year. (Indeed)
These figures are examples of individual current postings rather than nationwide averages, but they demonstrate the premium that may be associated with senior DevSecOps, cloud-security, engineering-management, and architecture responsibilities.
For broader comparison, Glassdoor's 2026 DevOps Manager data showed recent reported compensation ranges such as approximately:
Glassdoor also reported that the Information Technology industry was its highest-paying industry category for DevOps Managers, with median total pay around $268,750. (Glassdoor)
Because this is self-reported market compensation rather than official government wage data, it should be treated as supplementary rather than definitive.
BLS 2025 regional wage data illustrate significant location-related differences.
For Computer and Information Systems Managers, mean annual wages included approximately:
(Bureau of Labor Statistics)
This demonstrates why DevSecOps management compensation can vary substantially by geographic market.
| U.S. Metropolitan Area | Mean Annual Wage |
|---|---|
| San Francisco–Oakland–Fremont | $249,040 |
| New York–Newark–Jersey City | $224,990 |
| Chicago–Naperville–Elgin | $184,810 |
BLS May 2025 data for the San Jose technology market illustrate the compensation potential of advanced technical roles:
(Bureau of Labor Statistics)
In Raleigh-Cary, where technology employment is also concentrated, BLS reported mean annual wages of approximately:
(Bureau of Labor Statistics)
These differences highlight the influence of location, industry concentration, experience, and specialization.
Actual compensation for both CDevSOP®- and CDevSOM®-aligned roles may vary based on:
Senior engineering and management responsibilities generally command higher compensation.
Expertise in cloud, Kubernetes, application security, Infrastructure as Code, CI/CD, or software-supply-chain security may increase market value.
Managing larger teams, critical platforms, global delivery functions, or enterprise application-security programs may increase compensation.
Major technology and financial centers frequently offer higher nominal salaries.
Financial services, technology, aerospace, defense, consulting, healthcare, and regulated industries may compensate specialized skills differently.
Certain government and defense roles may attach substantial value to active security clearances and specialized technical experience.
Multi-cloud and cloud-security capabilities remain in strong demand.
Application security, secure architecture, threat modeling, and supply-chain security can differentiate DevSecOps professionals.
AI-assisted development and secure adoption of generative AI are becoming important differentiators.
CDevSOM® competencies may support progression toward roles such as:
Projected growth for Computer and Information Systems Managers, 2024–2034. (Bureau of Labor Statistics)
Projected additional U.S. computer and information systems management jobs by 2034. (Bureau of Labor Statistics)
Average projected annual management openings over the decade. (Bureau of Labor Statistics)
May 2025 mean annual wage for U.S. Computer and Information Systems Managers. (Bureau of Labor Statistics)
May 2025 mean annual wage for Computer and Information Systems Managers in the San Francisco metropolitan area. (Bureau of Labor Statistics)
Recent posted salary range for a Cloud Security Architect–DevSecOps Manager position. (Indeed)
Cybersecurity professionals reporting critical or significant skills needs in ISC2's 2025 global study. (ISC2)
Respondents reporting at least one cybersecurity skills need. (ISC2)
| Career Dimension | CDevSOP® — Professional | CDevSOM® — Manager |
|---|---|---|
| Primary Career Focus | Secure engineering and delivery | Enterprise secure-delivery leadership |
| Closest BLS Benchmark | Software Developer / Information Security Analyst | Computer & Information Systems Manager |
| Projected BLS Growth | 15.8% software development / 28.5% information security | 15% management |
| Relevant Annual Openings | 115,200 software developers; 16,000 security analysts | 55,600 managers |
| BLS Wage Benchmark | $133,080 software developer median; $124,910 security analyst median | $171,200 management median |
| 2025 BLS Mean Benchmark | $148,100 software developers | $192,160 technology managers |
| Current DevSecOps Market Example | $137,495 average DevSecOps Engineer estimate | $144,200–$265,600 recent manager posting |
| Career Direction | Build, secure, automate | Strategize, govern, measure, lead |
DevSecOps professionals operate where some of today's most important technology capabilities meet:
Official U.S. projections show strong growth for software developers, information-security professionals, and technology managers, while global cybersecurity workforce research continues to identify significant shortages in skills directly relevant to DevSecOps—including cloud security, application security, AI, security engineering, and risk assessment. (Bureau of Labor Statistics)
Employment projections and BLS wage figures are U.S. occupational statistics. DevSecOps-specific salary figures are third-party market estimates or examples from individual job postings and should not be interpreted as guaranteed compensation. Salaries vary by experience, geography, employer, industry, responsibilities, education, certifications, and other factors.
Everything you need to plan your sitting.
Exam code for the Advanced Manager-level DevSecOps credential.
Multiple choice, completed in 120 minutes.
Passing score. Delivered in English.
A minimum of five years of experience, including two years in a supervisory, lead or management role.
IBACTP® approved testing centers and online proctored delivery
Three-year certification cycle with continuing professional education
Every route leads to the same CDevSOM® examination and the same designation.
Start as a Professional. Advance as a Leader.
Exam fee only, with complimentary course materials provided — $400 USD.
4 days, 2 hours daily online. All course materials + Exam — $1,200 USD.
10 days, 2 hours daily. All course materials + Exam — $1,800 USD.
Certify a whole team on a schedule that suits your organization. Fees negotiable.
Apply, choose your preparation route and book your examination with an approved provider.
CDevSOP® is a vendor-neutral professional DevSecOps certification focused on secure software development, CI/CD, application security, cloud, Infrastructure as Code, containers, APIs, software supply chains, automation, monitoring, and AI-assisted DevSecOps.
CDevSOM® is an advanced DevSecOps management certification focused on strategy, secure SDLC governance, application-security leadership, pipeline governance, cloud-native risk, software supply-chain security, investment, metrics, AI, workforce leadership, and transformation.
CDevSOP® focuses primarily on implementing and operating secure software-delivery practices. CDevSOM® focuses on strategizing, governing, funding, measuring, and transforming enterprise DevSecOps capabilities.
CDevSOP® is the recommended professional pathway. Equivalent qualifying experience in DevSecOps, DevOps, application security, cloud, software engineering, platform engineering, or management may satisfy applicable IBACTP® eligibility requirements.
Yes. Both emphasize transferable competencies rather than one CI/CD platform, cloud provider, programming language, or security product.
Yes. Secure coding, code review, repositories, secrets, source-control security, SAST, and developer security feedback are core areas.
Yes. Pipeline design, automated testing, security gates, secrets, artifacts, permissions, release controls, and secure deployment are central competencies.
Yes. CDevSOP® focuses on practical secure implementation. CDevSOM® focuses on enterprise governance, standardization, risk, automation, investment, and assurance.
Yes. Container images, registries, orchestration, Kubernetes concepts, runtime security, and cloud-native risk are included.
Yes. Dependencies, package repositories, SCA, SBOMs, artifact integrity, signing, provenance, and third-party software risk are major areas.
Yes. Managers evaluate vulnerability trends, remediation performance, pipeline coverage, control effectiveness, developer experience, release risk, software supply chain exposure, maturity, and other KPIs/KRIs.
Yes. CDevSOP® addresses AI-assisted coding, testing, vulnerability analysis, and automation. CDevSOM® addresses governance, AI-generated code risk, agentic development, reliability, human oversight, investment, and emerging risk.
Candidates may complete the applicable certification examination or, where eligible, complete the corresponding professional or management Capstone through an approved instructor-led pathway.
The recommended credential cycle is three years, subject to applicable IBACTP® continuing professional education, ethics, certification-maintenance, and recertification policies.