Perforce Software
Security Engineer
About This Role
About Perforce Software
Perforce Software, Inc. is an American software company founded in 1995, specializing in developer tools for version control, application lifecycle management (ALM), and DevOps. Headquartered in Minneapolis, Minnesota, Perforce has grown into a comprehensive platform through strategic acquisitions, serving over 15,000 customers globally, including Fortune 10 companies. The company offers a wide range of solutions designed to enhance productivity and collaboration in software development. Key products include Helix Core, a robust version control system; Perforce ALM, an integrated suite for managing requirements and testing; and TeamHub, a Git-based repository management tool. Additional offerings encompass agile planning software, automated testing, and open source support services. Perforce's tools are utilized across various industries, including gaming, media, and semiconductors, enabling teams to manage complex projects and workflows effectively.
Security at Perforce Software
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
“Security is built into our products from initial design and integrated throughout the development lifecycle. Security is a team sport. Perforce empowers enterprise tech teams to balance scope, quality, speed, and security. No public evidence found for explicit Security Champions program or specific developer-facing paved road documentation.”
Security Team
Org Structure & Reporting Line: Information not publicly available. Aaron Kiemele serves as CISO. Key Public-Facing Leaders: Aaron Kiemele, Chief Information Security Officer with focus on "Customer Trust | Product Security | Application Security"; Anjali Arora, Chief Technology Officer. Team Size Estimate: Information not publicly available. Active AppSec Job Postings: Currently 0 specific AppSec roles listed. Gaps & Contradictions: No public data on specific number of AppSec engineers or internal reporting hierarchy between AppSec and the CTO/CISO.
Key Initiatives
- Shift Left in Practice: Threat modeling & design reviews for significant architectural changes.
- Vulnerability Management Process - Intake: Triage findings from scanners, pen tests, third-party advisories, and coordinated disclosures.
- Triage/Remediation: Risk-based remediation.
- Secure SDLC Artifacts: Penetration testing across applications and cloud services with remediation tracking to closure.
- Recent Initiatives: Perforce has achieved ISO/IEC 42001:2023 certification.
- Gaps & Contradictions: No public mention of specific remediation SLAs or specific bug bounty platform names.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.
Interested in this role?
Apply on LinkedIn