Director, Application Security
Core
Shape strategy and execution of application security and security architecture across a large technology organization, embedding security into developer workflows and CI/CD pipelines.
Role type
Senior security leadership (Director)
Builds
Security capabilities, tooling, and developer-first security culture
Domain
Technology, Application Security, Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Strategic leadership, multi-team management, workforce planning, budget management, executive communication, secure software development lifecycle integration, multi-cloud security, Zero Trust architecture, detection engineering, risk quantification, team recruitment and development, scripting/programming proficiency
Preferred skills
High-growth consumer tech or fintech experience, AWS expertise, infrastructure-as-code security, Kubernetes and container security, modern detection engineering tools
Technologies
Terraform, CloudFormation, Kubernetes, SIEM, SOAR, DLP, EDR, EPM, CSPM, CWPP, SAST, DAST
Responsibilities
Lead and develop a multi-manager security organization; Define and execute a 2–3-year strategic roadmap; Own workforce planning and organizational design; Build and retain highly technical security teams; Manage operational budgets and security tooling portfolios; Represent application security at executive levels; Lead Application Security program partnering with engineering; Develop security enablement programs; Ensure broad application security coverage; Establish product security practices; Build risk-based vulnerability management program; Partner with Security Architecture on enterprise patterns; Advance Zero Trust principles; Provide proactive security guidance during design reviews; Monitor emerging threats and technology developments
Seniority
Director, hands-on IC with management