Director, App Security
About the role
We are looking for a hands-on Director, Application Security Engineering to strengthen our cybersecurity posture and partner directly with teams building software across web, mobile, data, and AI-enabled workflows. This role will embed security into delivery practices, improve how we prevent and remediate risk, and communicate clearly with both technical and non-technical stakeholders.
Responsibilities
- Own and evolve application security practices across the SSDLC, emphasizing scalable, developer-aligned, shift-left controls
- Operate and improve SAST, SCA, secret scanning, code scanning, repository protections, and related controls across repositories and CI/CD pipelines
- Develop secure development enablement for citizen developers, vibe coding, and AI-assisted development, including practical guidance for tooling, code assurance, identity, observability, and enterprise standards
- Review application and code-level vulnerabilities, validate findings, reduce noise, and drive risk-based remediation plans
- Conduct threat modeling and security design reviews for new systems, major changes, integrations, APIs, and high-risk workflows
- Advises teams on secure coding, authentication and authorization, session management, secrets handling, logging, encryption, dependency hygiene, and data protection
- Improve security guardrails for build pipelines, containers, APIs, third-party components, and deployment practices across modern and legacy environments
- Mature risk-based vulnerability management across intake, validation, prioritization, remediation guidance, exception handling, and reporting
- Support secure adoption of AI-assisted development and agentic systems by assessing trust boundaries, data exposure paths, prompt and tool-invocation risks, and misuse scenarios
- Develop pragmatic standards, playbooks, reference architectures, documentation, and office-hour support that improve consistency without slowing teams down unnecessarily
- Track recurring weaknesses, recommend structural fixes, and help leadership understand where engineering investment will reduce risk most effectively
Requirements
- 5+ years of hands-on experience in application security, product security, DevSecOps, and security engineering or a closely related software security role
- Proven experience working directly with engineering teams in fast-moving delivery environments
- Hands-on experience configuring, tuning, and operationalizing SAST, SCA, and related tooling such as SonarQube, Dependabot, GitHub, GitHub Advanced Security, or comparable platforms
- Ability to interpret and reason about code, identify meaningful risk, and provide specific, implementable remediation guidance to engineers
- Strong understanding of application and API security, including common software weaknesses, authN/authZ, secrets handling, dependency risk, injection, deserialization, and data protection
- Experience integrating reliable, scalable, and minimally disruptive security controls into CI/CD pipelines and developer workflows
- Hands-on familiarity with cloud and modern software delivery patterns, including containers, IaC, and Git-based workflows
- Strong judgment in vulnerability triage, balancing severity, exploitability, business impact, and engineering realities
- Broad DevSecOps mindset across code, pipelines, dependencies, platforms, deployment, and operations
- Experience using AI tools responsibly to improve engineering and security outcomes
Preferred Skills and Experience
- Experience securing AI agents, LLM-enabled applications, copilots, or agentic workflows in production or near-production environments
- Experience with DAST, API security testing, penetration testing coordination, red-team support, or adversarial testing of application and AI systems
- Experience with policy-as-code, IaC scanning, container/image security, software supply-chain security, SBOMs, provenance, attestation, and secrets management
- Familiarity with cloud security across AWS and/or GCP and the application-layer implications of cloud-native architectures
- Experience in regulated, audit-sensitive, or event-critical environments where evidence, controls, and operational rigor matter
- Experience building metrics, dashboards, or reporting that show AppSec posture and remediation progress
- Experience mentoring engineers and influencing secure engineering culture without direct people management responsibility
What Good Looks Like in This Role
- Engineering teams get faster, clearer, and more actionable security guidance as well as assistance with implementation and mechanics for a "teach a person to fish" approach
- Security tooling produces more trustworthy signals and leads to better adoption, not just more alerts
- Teams catch and remediate issues earlier in design and development rather than late in release cycles
- Application and agent-security risks are surfaced in practical terms with concrete mitigation paths
- Standards, playbooks, and tooling make secure delivery easier and more consistent
- Security becomes more embedded in day-to-day engineering execution and technical operations, and less dependent on last-minute security scrambles and efforts
Pay
The hiring rate for this role is $142,500 - $190,000 annually, based on a number of factors including location and may vary depending on job-related qualifications, knowledge, skills and experience. The company strives to provide locally competitive rewards packages, which include base rate along with, as applicable, short- and long-term incentives, growth and developmental opportunities, and robust benefits such as health care, retirement, vacation and other paid time off, and additional offerings.