Director, Application Security (Cybersecurity Defense)
Core
Establishing and leading enterprise application security strategy to embed security into the software development lifecycle (SDLC) and reduce application-layer risk across Pharma, Medical, and Commercial Technology segments.
Role type
Director, Application Security (Cybersecurity Defense)
Builds
Secure application portfolios and APIs across diverse business segments
Domain
Healthcare technology, Application Security, DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security testing methodologies (SAST, DAST, SCA, IAST), Secure development lifecycle (SDLC) practices, Cloud-native architecture, Application and API security, Cybersecurity frameworks (NIST CSF, OWASP, ISO 27001), Executive stakeholder management, Team leadership
Preferred skills
Experience leading application security programs in large complex organizations, M&A security integration, Runtime security controls implementation
Technologies
SAST, DAST, SCA, IAST, WAF, API gateways, CI/CD pipelines, DevSecOps tools
Responsibilities
Lead enterprise application security strategy aligned with risk management objectives; Establish governance frameworks to embed security into SDLC; Collaborate with engineering teams to align security with technology strategies; Serve as advisor to executive leadership on security risks and investments; Drive secure-by-design culture across development teams; Oversee application security testing programs and vulnerability management; Define segment-specific security requirements and approaches; Drive standardization of processes and tooling across segments; Oversee implementation of runtime security controls for applications and APIs; Lead development and integration of application security tooling; Ensure alignment of application security practices with regulatory requirements and compliance standards; Provide application security oversight for audits and regulatory assessments; Define and track KPIs and KRIs related to application security posture; Provide regular reporting to executive leadership on security risks and program effectiveness; Identify opportunities to enhance automation and scalability of security processes; Support M&A activities by assessing and integrating application security controls; Build and lead a high-performing application security organization.
Seniority
Director, strategic leadership with hands-on technical oversight