Veracode for Security Leads
Managing your application security program across the portfolio
The Security Lead role in Veracode gives you broad visibility across your application portfolio. You can view findings for all applications, manage security policies, and access all Analytics data for your teams.
Note on mitigation approvals: Approving mitigation proposals requires the separate Mitigation Approver role, which must be explicitly assigned by an Administrator and is not included with any other role automatically. If your workflow includes reviewing and approving mitigations, ask your Veracode Administrator to add the Mitigation Approver role to your account.
Your Core Responsibilities
Review findings across the portfolio
The Results page in the Veracode Platform gives you access to all scanned applications. Use the Triage Flaws page to filter and prioritize findings.
- Docs: Triage Flaws
Review mitigation proposals
If you have the Mitigation Approver role, you can approve or reject mitigation proposals from development teams. Accepted mitigations count as resolved for policy purposes without a code fix.
Note on the Mitigation Approver role: The Mitigation Approver role must be explicitly assigned by an Administrator and is not included with any other role automatically — including Security Lead. Ask your Administrator if you need this added to your account.
Manage security policies
Security policies define the rules your applications are assessed against. You can configure which vulnerability types must be fixed, within what timeframe, and what severity triggers policy failure.
- Docs: About Security Policies
- Docs: Create a Security Policy
Using Veracode Analytics
Analytics is your primary tool for program-level visibility. Pre-built dashboards include:
- Security Program Overview — Portfolio-wide policy compliance and findings trends
- Findings Status and History — Open, closed, and mitigated findings over time
- SCA Findings — Open-source vulnerability risk across your portfolio
Analytics access: The Security Lead role provides read access to Analytics for all applications. To create or edit custom dashboards, the Analytics Creator role must also be explicitly assigned by an Administrator — it is not included automatically with any other role.
- Docs: Veracode Analytics
- Docs: Explore Your Data
Prioritization Framework
Not every finding demands immediate action. A practical approach:
Fix First: Very High and High severity in business-critical, internet-facing applications.
Fix Next: Medium severity in critical applications; Very High / High in lower-criticality applications.
Fix Later / Mitigate: Low and Very Low severity findings; findings where compensating controls exist.
Reporting to Leadership
Use the following to demonstrate program progress:
- Customizable Report (PDF) — Select which sections to include. docs.veracode.com/r/c_results_reports
- Analytics Dashboards — Share views of policy compliance trends over time.
- Reporting REST API — Pull data for custom executive reports. docs.veracode.com/r/Reporting_REST_API
Useful Resources
Learning Paths
Go deeper with these step-by-step learning paths on Veracode Docs:
← Back to the Getting Started Guide | ← Back to the Onboarding Hub
.png)