Director, App Security
Core
Director of Application Security Engineering embedding security into software delivery, managing tooling, and advising teams on secure development for web, mobile, data, and AI workflows.
Role type
Senior IC Director, Application Security Engineering
Builds
Secure SDLC practices, developer-friendly guardrails, and AI security controls for web, mobile, data, and AI-enabled systems
Domain
Sports & Entertainment / Cybersecurity / Application Security
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Application security, DevSecOps, SAST/SCA tooling, threat modeling, vulnerability management, secure coding, API security, CI/CD integration, cloud security, AI security assessment
Preferred skills
AI agent security, DAST, penetration testing coordination, policy-as-code, container security, software supply chain security, cloud security (AWS/GCP), security metrics
Technologies
SonarQube, Dependabot, GitHub, GitHub Advanced Security, AWS, GCP
Responsibilities
Own and evolve application security practices across the SSDLC; Operate and improve SAST, SCA, secret scanning, and code scanning controls; Develop secure development enablement for citizen developers and AI-assisted development; Review application vulnerabilities and drive risk-based remediation; Conduct threat modeling and security design reviews; Advise teams on secure coding, authN/authZ, secrets handling, and data protection; Improve security guardrails for build pipelines and containers; Mature risk-based vulnerability management; Support secure adoption of AI-assisted development and agentic systems; Develop pragmatic standards, playbooks, and documentation; Track recurring weaknesses and recommend structural fixes
Seniority
Director, hands-on IC with strategic influence
