Lead AppSec Engineer
Core
Lead Security Engineer supporting Gartner's AppSec function by executing vulnerability assessments, threat modeling, and risk prioritization to secure applications and infrastructure.
Role type
Lead Application Security Engineer (DevSecOps)
Builds
Secure application lifecycles, automated security tool integrations, and risk mitigation strategies for Gartner's internal platforms and client-facing solutions.
Domain
Enterprise IT Security, Cloud Security, Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Vulnerability scanning, Application Security Testing (AST), Threat modeling, Cloud security (AWS/Azure/GCP), Infrastructure as Code (IaC), Policy as Code (PaC), Security automation, Risk assessment, CI/CD security integration
Preferred skills
Penetration testing, Web application assessment, Scripting/Programming (Java, Python, PowerShell, Bash), SOC2/ISO/NIST frameworks
Technologies
AWS, Azure, GCP, IaC tools, PaC tools, AST platforms, Vulnerability scanners, CI/CD pipelines
Responsibilities
Execute daily vulnerability assessments and triage security risks; Mentor engineers on threat modeling; Coordinate orchestration and automation of security technologies; Define metrics (KRIs) to measure security control effectiveness; Partner with stakeholders to remediate security issues in applications and infrastructure.
Seniority
Senior, hands-on IC with leadership responsibilities