Lead Application Security Engineer
Core
Define and drive the firm's application security strategy, embedding security throughout the software lifecycle for a global alternative investment manager.
Role type
Director of Application Security (Strategy & Program Leadership)
Builds
Scalable application security program, secure SDLC processes, and security tooling integration for engineering teams.
Domain
Financial Services / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application threat modeling, Secure SDLC implementation, SAST/SCA/DAST tooling, CI/CD pipeline security, Application architecture review, Governance frameworks
Preferred skills
Penetration testing methodologies, Cloud environment security, OWASP/NIST/ISO 27001 frameworks, Burp Suite, Snyk, GitHub
Technologies
Snyk, GitHub, Burp Suite, CI/CD pipelines
Responsibilities
Lead threat modeling for new and existing applications, Guide teams in secure design principles, Define and implement secure SDLC processes, Integrate and maintain security tooling, Build and sustain a security champion program, Establish governance frameworks for compliance
Seniority
Director, Strategy & Program Leadership