Veracode for Security Leads

Managing your application security program across the portfolio


The Security Lead role in Veracode gives you broad visibility across your application portfolio. You can view findings for all applications, manage security policies, and access all Analytics data for your teams.

Note on mitigation approvals: Approving mitigation proposals requires the separate Mitigation Approver role, which must be explicitly assigned by an Administrator and is not included with any other role automatically. If your workflow includes reviewing and approving mitigations, ask your Veracode Administrator to add the Mitigation Approver role to your account.


Your Core Responsibilities

Review findings across the portfolio

The Results page in the Veracode Platform gives you access to all scanned applications. Use the Triage Flaws page to filter and prioritize findings.


Review mitigation proposals

If you have the Mitigation Approver role, you can approve or reject mitigation proposals from development teams. Accepted mitigations count as resolved for policy purposes without a code fix.

Note on the Mitigation Approver role: The Mitigation Approver role must be explicitly assigned by an Administrator and is not included with any other role automatically — including Security Lead. Ask your Administrator if you need this added to your account.

Manage security policies

Security policies define the rules your applications are assessed against. You can configure which vulnerability types must be fixed, within what timeframe, and what severity triggers policy failure.


Using Veracode Analytics

Analytics is your primary tool for program-level visibility. Pre-built dashboards include:

  • Security Program Overview — Portfolio-wide policy compliance and findings trends
  • Findings Status and History — Open, closed, and mitigated findings over time
  • SCA Findings — Open-source vulnerability risk across your portfolio

Analytics access: The Security Lead role provides read access to Analytics for all applications. To create or edit custom dashboards, the Analytics Creator role must also be explicitly assigned by an Administrator — it is not included automatically with any other role.


Prioritization Framework

Not every finding demands immediate action. A practical approach:

Fix First: Very High and High severity in business-critical, internet-facing applications.

Fix Next: Medium severity in critical applications; Very High / High in lower-criticality applications.

Fix Later / Mitigate: Low and Very Low severity findings; findings where compensating controls exist.


Reporting to Leadership

Use the following to demonstrate program progress:


Useful Resources


Learning Paths

Go deeper with these step-by-step learning paths on Veracode Docs:


← Back to the Getting Started Guide | ← Back to the Onboarding Hub