Application Security Manager
Core
Lead application security services including red team simulations, vulnerability assessments, penetration testing, and source code reviews to help clients implement effective cybersecurity programs and protect against threats.
Role type
Senior IC Application Security Manager (Advisory/Consulting)
Builds
Security architecture reviews, risk assessments, and application security programs for clients across web, cloud, mobile, and API environments.
Domain
Cybersecurity & Privacy / Application Security
Deliverable
client delivery
Required skills
Red team operations, vulnerability assessment, penetration testing, source code review, threat modeling, security architecture review, DevSecOps integration, exploit development, reverse engineering, wireless/web/network security testing, MITRE ATT&CK framework, D3FEND matrix, OWASP knowledge, manual web testing, API understanding (SOAP/REST/GraphQL), OS/DB/Network auditing, Unix/Linux/Windows administration, bash/Powershell scripting.
Preferred skills
Project management, team leadership, client stakeholder management, project economics, security tool integration.
Technologies
Nmap, Nessus, Kali, Metasploit, BurpSuite, Netsparker, OWASP CSRF Tester, Fortify, Checkmarx, SonarQube, Synopsys, SQLite, Drozer.
Responsibilities
Manage and deliver cyber-attack simulations (red team), conduct VAPT for web/mobile/API/network/thick-client applications, perform source-code reviews, execute configuration reviews for OS/DB/Firewall/routers, perform gap analysis based on standards (ISO27K1, MAS TRM, HKMA), prepare detailed security reports, provide technical guidance on application security service offerings, manage client stakeholders and project status, analyze and enhance client security posture from design to deployment.
Seniority
Manager, hands-on IC with team management