Department Manager - Application Security
Core
Lead end-to-end Application Security program, defining secure SDLC policies and managing the toolchain to enforce them across CI/CD pipelines.
Role type
Senior Application Security Manager (Leadership)
Builds
Secure software delivery pipelines and hardened application architectures
Domain
Application Security / Software Development Lifecycle
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Application Security (AppSec), Secure SDLC, SAST/SCA/DAST/Secrets scanning, CI/CD integration, Threat modeling, Code review, Team leadership, Vulnerability management
Preferred skills
Container security scanning, IaC security, AI/LLM security, Software development background, CSSLP/GWEB/CASE certification, Retail/E-commerce security
Technologies
Checkmarx, SonarQube, Qualys WAS, Spectral, OWASP ZAP, GitHub Actions, Azure DevOps, Jenkins, Trivy, Prisma Cloud, Aqua, Checkov, tfsec
Responsibilities
Own and evolve Secure SDLC framework; Manage and optimize AppSec toolchain; Drive CI/CD pipeline security integration; Lead threat modeling and secure design reviews; Consult on vulnerability remediation; Define security quality gates; Report security posture metrics; Evaluate emerging AppSec technologies; Coordinate with Offensive Security team
Seniority
Senior, hands-on IC with management responsibilities