FICO
Sr DevSecOps Engineer - IAM Engineer
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About FICO
FICO, or Fair Isaac Corporation, is an American data analytics company founded in 1956. It specializes in predictive analytics, credit scoring, risk management, fraud detection, and decision management software. Headquartered in Bozeman, Montana, FICO operates in over 90-100 countries and serves more than 10,000 clients across various industries, including financial services, healthcare, retail, and telecommunications. The company is known for pioneering the first credit scoring system and introducing the widely recognized FICO Score, which has become a standard measure of consumer credit risk in the U.S. FICO offers a range of products, including fraud detection solutions, customer communication services, and loan origination automation tools. Its analytics software leverages big data and mathematical algorithms to help businesses improve decision-making, enhance profitability, and strengthen customer relationships.
Security at FICO
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- FICO's AppSec philosophy is guided by a "security by design"principle and a proactive, risk-based approach.
- They adopt a DevSecOps model, integrating strict security controls throughout all phases of a Secure Software Development Lifecycle (SSDL).
Security Team
- FICO's AppSec team roles are found within Cybersecurity/Identity teams and Product Security/DevSecOps positions.
- Public job postings indicate roles like Identity Security Architect and SecDevOps Engineer.
- Explicit organizational reporting lines or specific named public-facing AppSec leaders were not found.
Key Initiatives
- FICO's AppSec initiatives include a Secure Software Development Lifecycle (SSDL), penetration testing, and automated testing tools.
- They integrate security into CI/CD pipelines.
- Public details about a Security Champions program, formal SLAs for triage/MTTR, or named AppSec runbooks were not found.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.