About the Role
Lead the strategy, development, and execution of the Application Security program, maturing capabilities across the software development lifecycle to ensure secure-by-design principles are embedded while enabling rapid product delivery. Partner with Engineering, Product Management, Architecture, DevOps, Cloud Engineering, and Security Operations to integrate security throughout software development.
Responsibilities
- Develop and execute the enterprise Application Security strategy aligned with business and technology objectives.
- Build and mature a scalable Application Security program supporting modern software development practices.
- Define the long-term roadmap for secure software development across cloud, web, mobile, APIs, and emerging technologies.
- Establish secure-by-design principles and integrate them throughout the Software Development Life Cycle (SDLC).
- Lead the implementation and continuous improvement of a Secure Software Development Lifecycle (SSDLC).
- Develop standards and security requirements for application development.
- Partner with engineering teams to integrate security early within CI/CD pipelines.
- Promote developer-friendly security practices that minimize friction while improving software security.
- Oversee enterprise application security testing, including SAST, DAST, SCA, IAST, API Security Testing, Container Security, IaC Security, secure code reviews, and penetration testing coordination.
- Partner with DevOps teams to embed automated security controls into CI/CD pipelines.
- Improve automation of security testing and vulnerability management.
- Reduce developer burden through integrated tooling and streamlined workflows.
- Measure security effectiveness while enabling engineering velocity.
- Establish application vulnerability management standards and service level objectives.
- Prioritize remediation activities based on exploitability and business risk.
- Develop executive reporting for application security risk.
- Track remediation effectiveness across engineering organizations.
- Provide application security guidance for cloud-native applications, microservices, APIs, containers, Kubernetes, serverless architectures, AI/ML applications, and third-party integrations.
- Build trusted relationships with engineering leadership.
- Champion security as an engineering quality function.
- Develop security champions programs across engineering organizations.
- Lead, mentor, and develop a high-performing Application Security team.
- Establish performance metrics and operational objectives.
- Manage vendor relationships and application security technologies.
- Support hiring and organizational growth as the program matures.
- Mentor developers on secure coding practices and emerging threats.
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related field required.
- Advanced degree preferred.
- 10+ years of progressive experience in Application Security, Software Security, Product Security, Secure Engineering, or related cybersecurity disciplines.
- 5+ years leading Application Security teams.
- Demonstrated success building, transforming, or significantly maturing Application Security programs within enterprise organizations.
- Experience partnering closely with software engineering organizations in Agile and DevSecOps environments.
- Strong understanding of SSDLC, OWASP Top 10, secure coding principles, threat modeling, modern authentication protocols, API security, cloud-native application security, container security, CI/CD security, DevSecOps, software supply chain security, AI-assisted software development governance and secure use, and application vulnerability management.
- Possesses at least one of the following certifications (or comparable alternative): CISSP, CSSLP, GIAC Secure Software Programmer (GSSP), GIAC Cloud Security Automation (GCSA).
Skills
- Application Security
- Software Security
- Product Security
- Secure Engineering
- Cybersecurity
- Secure Software Development Lifecycle (SSDLC)
- OWASP Top 10
- Secure coding principles
- Threat modeling
- Modern authentication protocols
- API security
- Cloud-native application security
- Container security
- CI/CD security
- DevSecOps
- Software supply chain security
- AI-assisted software development governance
- Application vulnerability management
- SAST
- DAST
- SCA
- IAST
- API Security Testing
- Container Security
- Infrastructure-as-Code (IaC) Security
- Secure code reviews
- Penetration testing coordination
- DevOps
- Agile
Location
- HYBRID
Work Type
- HYBRID
Experience Level
- Director
- 10+ years of progressive experience in Application Security, Software Security, Product Security, Secure Engineering, or related cybersecurity disciplines
- 5+ years leading Application Security teams
Education Level
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related field
- Advanced degree preferred
Salary/Compensations
- $200,000 - $215,000 USD per year
- Total on target compensation includes a base salary plus a variable target incentive that aligns with individual and company performance.
Benefits
- Short-term incentives
- Multiple health insurance options
- Accident and life insurance
- Access to best-in-class development platforms
- Parental Leave
- Family First Programs
- Medical, Dental, and Life Insurance
- Tuition Repayment Assistance Program
About the Company
- We are passionate about honoring our employee's identity and fostering a feeling of belonging. Our commitment is to provide an inclusive culture that celebrates the unique backgrounds and perspectives of our global teams while reflecting the communities we serve.
Equal Opportunity
- We do not discriminate based on race, color, national origin, religion, political affiliation, sex (including pregnancy), sexual orientation, gender identity, age, disability, marital status, or veteran status.
- The company will provide accommodation to applicants, including those with disabilities, during the recruitment process, following applicable laws.
