Full-Time

Senior Corporate Counsel

Veracode

Veracode

201-500 employees

Cloud-based platform for application security scanning

No salary listed

Burlington, MA, USA

In Person

Category
Legal & Compliance (1)

Get referred to Veracode

See people who can refer or advise you

Requirements
  • JD from an accredited law school and admission to practice law.
  • 10+ years of legal experience, with significant in-house counsel experience in a technology or cybersecurity environment.
  • Knowledge of data protection laws and cybersecurity regulations.
  • Ability to manage complex legal matters in a fast-paced, growth-oriented environment.
  • Experience working with government contracts a plus.
  • Strong leadership, communication, and problem-solving skills.
Responsibilities
  • Advise leadership on corporate governance, risk management, and legal strategy.
  • Performing corporate secretarial duties.
  • Ensure compliance with relevant cybersecurity, privacy, and data protection laws (e.g., GDPR, CCPA, HIPAA, NIST).
  • Draft, review, and negotiate complex contracts including customer agreements and support corporate Go-To-Market efforts.
  • Oversee legal aspects of product development to ensure privacy-by-design and secure-by-design principles are embedded.
  • Advise on regulatory compliance efforts and internal policies, including training and enforcement.
  • Advise the Company’s People Success function on domestic and international employment law and the creation of employment contracts and internal policies.
  • Manage legal issues related to IP, employment, litigation, and international expansion.
  • Collaborate with external counsel as necessary and manage the company’s legal budget.
  • Lead incident response from a legal perspective, including breach notifications, communications, and coordination with regulators.
  • Provide legal support for mergers and acquisitions, financing rounds, and other corporate transactions.
  • Support the strategic oversight of the information security program (InfoSec), including security operations, governance, risk, and compliance, and the alignment of organizational goals with risk and compliance requirements.

Placeholder

Company Size

201-500

Company Stage

Acquired

Total Funding

$114.3M

Headquarters

New York City, New York

Founded

2006

Get referred to Veracode

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Record 2025 momentum added over 130 customers in one quarter.
  • Fix for SCA automates safe, ready-to-merge open-source remediation.
  • Package Firewall blocks malicious packages across major ecosystems and package managers.

What critics are saying

  • Microsoft and GitHub bundle comparable tools into broader developer suites.
  • One failed AI-generated fix can damage trust in autonomous remediation.
  • A supply-chain bypass would undermine Package Firewall's core security promise.

What makes Veracode unique

  • Independent cloud AppSec platform spanning code, runtime, and remediation.
  • Trillions of code scans power proprietary AI-assisted vulnerability analysis.
  • Broad suite includes SAST, DAST, SCA, ASPM, and Package Firewall.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Wellness Program

Unlimited Paid Time Off

401(k) Company Match

401(k) Retirement Plan

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

1%

2 year growth

-4%
Corgea
Jul 8th, 2026
Snyk vs Veracode vs Corgea: comparison table.

Snyk vs Veracode vs Corgea: comparison table. | Feature | Snyk | Veracode | Corgea | | Primary focus | Developer-first AppSec across dependencies and code | Enterprise application risk management and AppSec testing | AI-native detection and review-ready remediation | | SAST | Yes, through Snyk Code | Yes, mature SAST with broad language support | Yes, AI-native SAST with contextual detection | | SCA | Yes, core strength | Yes, native SCA with policy workflows | Yes, reachability-aware SCA | | DAST | Add-on / partner workflows | Yes, native DAST and API testing | Works alongside existing DAST findings | | IaC scanning | Yes | Yes | Yes | | Container scanning | Yes | Yes | Yes | | Secrets detection | Limited / platform-dependent | Yes, through platform workflows | Yes | | Auto-fix / remediation | Snyk Agent Fix for supported issues | Veracode Fix for supported Pipeline Scan findings | Review-ready fixes as pull requests | | Governance | Enterprise controls available | Strong policy and compliance workflows | Lighter governance, developer workflow first | | Pricing model | Free and paid tiers, enterprise quote | Custom enterprise quote | Free trial, quote-based plans | | Best fit | Engineering-led rollout | Regulated enterprise portfolios | Faster remediation and lower-noise prioritization | When to choose Snyk. Choose Snyk if you need developer-first AppSec coverage with especially strong SCA, container, and IaC workflows. Snyk is a good fit for engineering-led teams that want security checks in IDEs, pull requests, repositories, CLIs, and CI/CD. When to choose Veracode. Choose Veracode if you need enterprise SAST depth, broad language coverage, governance, policy controls, and a unified AppSec platform that security teams can operate across a large portfolio. Veracode is especially compelling for regulated organizations and complex multi-language environments. When to choose Corgea. Choose Corgea if you want lower-noise prioritization and review-ready fixes without waiting on manual patch translation. Corgea works alongside Snyk, Veracode, or whatever scanners you already use. It can also replace parts of the stack for teams that want an AI-native AppSec platform with SAST, SCA, secrets, IaC, containers, and autonomous pentesting. Frequently asked questions. What is the main difference between Snyk and Veracode? Snyk is a developer-first AppSec platform best known for SCA and smooth developer workflow integrations. Veracode is an enterprise AppSec platform best known for mature SAST, policy management, and centralized compliance reporting. The short version of Snyk vs Veracode is developer-first rollout versus enterprise governance depth. Can I use Snyk and Veracode together? Some organizations use different tools for different business units or application types. If you run both, Corgea can sit on top of scanner output and help normalize remediation by generating pull requests from findings. Which is better for SAST: Snyk or Veracode? Veracode is usually stronger if your main requirement is mature enterprise SAST across a broad set of languages, policies, and governance workflows. Snyk is usually stronger if you want SAST embedded into a broader developer-first platform with fast adoption. Validate on your own repositories. What are the best alternatives to Snyk and Veracode? Common alternatives include Corgea, Semgrep, Checkmarx, GitHub Advanced Security, SonarQube, and Fortify. See the best SAST tools guide, Snyk alternatives, and Veracode alternatives. Does Corgea replace Snyk or Veracode? Corgea can replace parts of a scanner stack for teams that want an AI-native AppSec platform, but it does not have to replace Snyk or Veracode. Corgea complements these tools by ingesting their findings and generating review-ready fixes as pull requests. Ready to turn findings into fixes? Corgea integrates with Snyk, Veracode, and other security tools to generate review-ready fixes. Validate the workflow on your own repositories.

Help Net Security
Mar 18th, 2026
Veracode Fix for SCA automates open-source vulnerability fixes.

Veracode Fix for SCA automates open-source vulnerability fixes. Veracode has unveiled Veracode Fix for Software Composition Analysis (SCA), an AI-powered solution to address software supply chain risk. The enhanced automated remediation engine, the next evolution of Veracode's Fix solution, enables organizations to detect and remediate open-source vulnerabilities easily, before code reaches production. Designed to integrate seamlessly into existing developer workflows, it delivers third-party updates and first-party code refactoring without breaking builds or disrupting development. In 2025, software supply chain breaches accounted for 30% of external attacks. Meanwhile Veracode's 2026 State of Software Security (SoSS) Report revealed 82% of organizations struggle with escalating security debt, largely due to open-source dependencies. Veracode Fix for SCA addresses both challenges directly. Leveraging deep, contextual analysis, the solution delivers pull requests that are safe to merge, enabling autonomous fixing. Unlike traditional SCA solutions that often overwhelm developers with alerts and hinder productivity, Veracode Fix combines logic-driven AI with proprietary vulnerability intelligence, ensuring ready-to-merge fixes while eliminating the risk of AI "hallucinations." "AI is accelerating software development - but it's also enabling an unprecedented explosion of supply chain risks," said Tim Jarrett, Vice President of Product Management. "Visibility into these risks is no longer enough. Organizations need intelligent, automated solutions that not only find vulnerabilities but fix them with precision, giving development teams the confidence to innovate securely." Veracode Fix for SCA transforms the remediation process through several core capabilities: * Contextual analysis: Evaluates the interaction between third-party dependencies and first-party code, preventing breaking changes. * Multi-file, cohesive pull requests: Bundles all configuration files and source code modifications into a focused, easily reviewable update. * Curated AI engine: Grounds automated fixes in a proprietary, human-verified vulnerability database for accurate, trustworthy remediation. * Automated workflows: Delivers ready-to-merge code directly into the developer's Git environment. "By enabling development teams to upgrade to safe open-source libraries automatically while addressing breaking changes with a single, testable update, we move organizations from seeing risk to actively eliminating it, strengthening the security of their software supply chains," Jarrett closed. More about

The Associated Press
Mar 18th, 2026
Veracode launches AI-powered Fix for SCA to combat software supply chain vulnerabilities

Veracode has launched Veracode Fix for Software Composition Analysis, an AI-powered solution addressing software supply chain vulnerabilities. The automated remediation engine detects and fixes open-source vulnerabilities before code reaches production, delivering pull requests directly into developers' Git workflows. The solution combines logic-driven AI with proprietary vulnerability intelligence to provide contextual analysis and multi-file, cohesive pull requests. It evaluates interactions between third-party dependencies and first-party code to prevent breaking changes whilst eliminating AI hallucinations through a human-verified vulnerability database. Veracode's 2026 State of Software Security Report found 82% of organisations struggle with escalating security debt from open-source dependencies, whilst software supply chain breaches accounted for 30% of external attacks in 2025. The company showcased the solution at RSA Conference 2026 in San Francisco.

Veracode
Feb 10th, 2026
Veracode Named a Leader in GigaOm Radar for Software Supply Chain Security

Veracode named a Leader in GigaOm Radar for Software Supply Chain Security. By Karen Buffo Modern software development is a balancing act. You are under constant pressure to innovate faster, ship features daily, and maintain near-perfect uptime. To meet these demands, development teams rely heavily on open-source libraries, APIs, and third-party components. It's efficient, but it introduces a significant challenge: your attack surface is now composed of code you didn't write. Securing this complex web of dependencies - your software supply chain - is no longer optional. It is a critical requirement for enterprise security. Veracode is proud to announce that Veracode, Inc. has been named a Leader in the GigaOm Radar Report for Software Supply Chain Security. This recognition validates its platform-centric approach to application security and underscores its commitment to helping you build software that is secure by design. The rising stakes of Supply Chain Security. Software supply chain attacks have shifted the security paradigm. Attackers are no longer just looking for vulnerabilities in your custom code; they are targeting the pipelines, tools, and open-source components that build your applications. A single compromised library can cascade into a widespread breach, affecting not just your organization but your customers as well. This reality has driven a surge in regulatory focus, such as the executive orders on cybersecurity and the increasing demand for Software Bills of Materials (SBOMs). Organizations need more than just a scanner. You need comprehensive visibility and control over every component that enters your development lifecycle. However, many security tools struggle to keep pace. They often flood developers with false positives, lack context, or sit outside the development workflow, creating friction that slows down innovation. Why Veracode was named a Leader. Its position as a Leader in the GigaOm Radar reflects its philosophy that security must be integral to the development process, not an obstacle to it. Veracode, Inc. believe that to truly secure the supply chain, you need a solution that connects the dots between code, dependencies, and deployment. Here is a closer look at the strengths that distinguish the Veracode Continuous Software Security Platform. 1. A unified platform approach. GigaOm recognizes the value of a comprehensive platform. Point solutions often create data silos, making it difficult for security leaders to get a clear picture of their risk posture. Veracode brings together Static Analysis (SAST), Dynamic Analysis (DAST), Software Composition Analysis (SCA), and Container Security into a single, unified view. This convergence allows you to manage your entire application security program from one dashboard. You get consistent policy enforcement and reporting across all your applications, whether they are legacy monoliths or cloud-native microservices. 2. Seamless integration into the SDLC. Security tools are only effective if developers use them. Veracode, Inc. engineered its platform to fit seamlessly into the tools your teams already use every day. Whether it is integrating directly into IDEs like IntelliJ and VS Code, or automating scans within Jenkins, GitHub, or Azure DevOps pipelines, Veracode meets developers where they are. This "shift left" capability ensures that security checks happen early and often. By catching vulnerabilities during the coding phase - rather than waiting for a pre-production scan - you reduce the cost and time required to fix them. 3. Turning insight into action with AI. Identifying a vulnerability is only half the battle. The real challenge lies in remediation. Developers often spend hours researching how to fix a specific flaw without breaking the build. Veracode is leading the charge in AI-driven remediation. Its solution doesn't just flag a problem; it suggests the fix. By leveraging a vast database of secure code patterns, Veracode, Inc. provide developers with automated pull requests and remediation advice. This dramatically reduces the "fix rate" time, helping teams clear their security debt faster and focus on building new features. 4. Visibility through sboms. You cannot secure what you cannot see. As regulations tighten, the ability to produce and manage an accurate SBOM is essential. Veracode provides deep visibility into your open-source dependencies, including transitive dependencies (the libraries your libraries use). Veracode, Inc. help you identify license risks and security vulnerabilities hidden deep in your dependency tree. With its continuous monitoring, you receive alerts the moment a new vulnerability is discovered in a component you are using, allowing for immediate response. Understanding the GigaOm Radar. The GigaOm Radar Report is one of the most respected technical assessments in the industry. Unlike traditional market quadrants that may focus heavily on market share, the GigaOm Radar evaluates vendors based on technical capabilities, product roadmap, and innovation. It looks at how well a solution meets the needs of modern enterprises today and how well-positioned it is to handle future challenges. In this report, GigaOm analyzes the Software Supply Chain Security (SSCS) landscape. They evaluate vendors on key criteria such as: * SBOM Management: The ability to generate and manage Software Bills of Materials. * Pipeline Security: protecting the integrity of the CI/CD pipeline itself. * Open-Source Security: Identifying and remediating vulnerabilities in third-party libraries. * Policy Enforcement: Automating governance across the development lifecycle. GigaOm classifies vendors into different sectors based on their maturity and focus. Being named a Leader signifies that a vendor demonstrates a strong balance of innovation and platform maturity, offering scalable solutions that deliver high value to the enterprise. Moving forward with confidence. The recognition from GigaOm is not just an award for Veracode, Inc.; it is a signal to the market that the future of application security is integrated, automated, and platform-based. As software supply chains grow more complex, the "trust but verify" model is obsolete. You must verify continuously. You need a partner that evolves as fast as the threat landscape does. Veracode, Inc. is committed to empowering your developers to write secure code and enabling your security teams to manage risk at the speed of business. By reducing false positives, automating remediation, and providing crystal-clear visibility, Veracode, Inc. help you turn security from a bottleneck into a competitive advantage. Take the next step. Don't let supply chain vulnerabilities be your blind spot. Equip your team with the insights and tools validated by industry experts. Read the full GigaOm Radar Report for Software Supply Chain Security to explore the key criteria for evaluating vendors, understand the market landscape, and see why Veracode was named a Leader. Interested in Learning More? Subscribe today to stay informed and get regular updates from Veracode. By Karen Buffo As Chief Marketing Officer at Veracode, Karen Buffo brings more than 18 years of global security expertise, with a proven track record of developing and executing marketing strategies that deliver value to customers, partners, shareholders, and employees alike. Prior to joining Veracode, Karen held leadership positions at MixMode, Anomali, The Symantec Enterprise Division of Broadcom, and Oracle. Throughout her career, she has defined and implemented comprehensive global marketing initiatives that strengthen brands and drive worldwide growth. Karen's multifaceted background in strategy, business enablement, and global marketing provides her with a holistic perspective on companies' distinctive capabilities, opportunities, and growth drivers - resulting in sustainable business value. A recognized industry keynote speaker, mentor, and active contributor to the cybersecurity community, Karen holds a Bachelor's degree in Consumer Science and Business Administration.

Business Wire
Feb 5th, 2026
Veracode closes 2025 with 81% ACV growth amid surging application risk management demand

Veracode, an application risk management company, reported strong growth in 2025, with new Annual Contract Value increasing 81% year-over-year in the fourth quarter. The company added over 130 new customers in the final quarter alone and closed several seven-figure, multi-year contracts. The platform processed 420 trillion lines of code and helped customers fix 131 million flaws throughout the year. Growth was driven by demand for comprehensive security platforms addressing AI-generated code risks and supply chain vulnerabilities. Veracode launched new products including Package Firewall and External Attack Surface Management. The company was recognised as a leader in multiple industry reports, including the Forrester Wave for SAST and Gartner Magic Quadrant for Application Security Testing. Total funding raised to date was not disclosed.