Lead, Application Security
Core
Lead the maturation of enterprise application security and vulnerability management programs, embedding security controls into CI/CD pipelines and securing cloud-native environments.
Role type
Senior IC Application Security Lead (DevSecOps & Attack Surface Management)
Builds
Secure-by-design application security capabilities, automated security controls, and risk governance processes for Prudential's digital ecosystem.
Domain
Financial Services / Application Security / DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Application security program leadership, vulnerability management, DevSecOps integration, SAST/SCA/DAST/ASPM tooling, software composition analysis (SCA), SBOMs, supply chain risk, exploit validation, security frameworks (OWASP, NIST, PCI DSS), policy-as-code, automation engineering.
Preferred skills
Python/PowerShell/Bash scripting, web application penetration testing, threat actor knowledge, Agentic AI in security, advanced security certifications (OSCP, GPEN, etc.), cloud certifications (AWS, Azure, GCP).
Technologies
SAST, SCA, DAST, ASPM, CI/CD pipelines, Python, PowerShell, Bash, AWS, Azure, GCP, MITRE ATT&CK, CVE, CVSS, EPSS, CWE.
Responsibilities
Lead design and execution of application security assessment and risk governance processes; drive integration of security controls into CI/CD pipelines; evaluate and vet new security technologies; develop proof-of-concept exploits to validate remediation; mentor junior team members; define requirements for workflow orchestration and automation; ensure risk metrics align with executive and regulatory needs.
Seniority
Senior, hands-on IC with strategic leadership