Director, App Security
About the role
We are looking for a hands-on Director, Application Security Engineering to strengthen our cybersecurity posture and partner directly with teams building software across web, mobile, data, and AI-enabled workflows. This role will embed security into delivery practices, improve how we prevent and remediate risk, and communicate clearly with both technical and non-technical stakeholders.
Responsibilities
Own and evolve application security practices across the SSDLC, emphasizing scalable, developer-aligned, shift-left controls
Operate and improve SAST, SCA, secret scanning, code scanning, repository protections, and related controls across repositories and CI/CD pipelines
Develop secure development enablement for citizen developers, vibe coding, and AI-assisted development, including practical guidance for tooling, code assurance, identity, observability, and enterprise standards
Review application and code-level vulnerabilities, validate findings, reduce noise, and drive risk-based remediation plans
Conduct threat modeling and security design reviews for new systems, major changes, integrations, APIs, and high-risk workflows
Advises teams on secure coding, authentication and authorization, session management, secrets handling, logging, encryption, dependency hygiene, and data protection
Improve security guardrails for build pipelines, containers, APIs, third-party components, and deployment practices across modern and legacy environments
Mature risk-based vulnerability management across intake, validation, prioritization, remediation guidance, exception handling, and reporting
Support secure adoption of AI-assisted development and agentic systems by assessing trust boundaries, data exposure paths, prompt and tool-invocation risks, and misuse scenarios
Develop pragmatic standards, playbooks, reference architectures, documentation, and office-hour support that improve consistency without slowing teams down unnecessarily
Track recurring weaknesses, recommend structural fixes, and help leadership understand where engineering investment will reduce risk most effectively
Requirements
5+ years of hands-on experience in application security, product security, DevSecOps, and security engineering or a closely related software security role
Proven experience working directly with engineering teams in fast-moving delivery environments
Hands-on experience configuring, tuning, and operationalizing SAST, SCA, and related tooling such as SonarQube, Dependabot, GitHub, GitHub Advanced Security, or comparable platforms
Practical experience with SSDLC and shift-left practices, including automated code review support, threat modeling, security design review, and vulnerability management
Strong understanding of application and API security, including common software weaknesses, authN/authZ, secrets handling, dependency risk, injection, deserialization, and data protection
Hands-on familiarity with cloud and modern software delivery patterns, including containers, IaC, and Git-based workflows
Strong judgment in vulnerability triage, balancing severity, exploitability, business impact, and engineering realities
Experience integrating reliable, scalable, and minimally disruptive security controls into CI/CD pipelines and developer workflows
Preferred Skills and Experience
Experience securing AI agents, LLM-enabled applications, copilots, or agentic workflows in production or near-production environments
Experience with DAST, API security testing, penetration testing coordination, red-team support, or adversarial testing of application and AI systems
Familiarity with cloud security across AWS and/or GCP and the application-layer implications of cloud-native architectures
Experience in regulated, audit-sensitive, or event-critical environments where evidence, controls, and operational rigor matter
Experience building metrics, dashboards, or reporting that show AppSec posture and remediation progress
Experience mentoring engineers and influencing secure engineering culture without direct people management responsibility
What Good Looks Like in This Role
Engineering teams get faster, clearer, and more actionable security guidance as well as assistance with implementation and mechanics for a "teach a person to fish" approach
Security tooling produces more trustworthy signals and leads to better adoption, not just more alerts
Teams catch and remediate issues earlier in design and development rather than late in release cycles
Application and agent-security risks are surfaced in practical terms with concrete mitigation paths
Standards, playbooks, and tooling make secure delivery easier and more consistent
Security becomes more embedded in day-to-day engineering execution and technical operations, and less dependent on last-minute security scrambles and efforts
Pay
The hiring rate is $142,500 - $190,000 annually, based on a number of factors including location.
Schedule
This is a hybrid role (3 days/week in-office).
Benefits
The company strives to provide locally competitive rewards packages, which include base rate along with, as applicable, short- and long-term incentives, growth and developmental opportunities, and robust benefits, such as health care, retirement, vacation and other paid time off, and additional offerings.
Equal Opportunity Employer
TKO is an Equal Opportunity Employer and complies with all applicable federal, state, and local laws regarding non-discrimination in employment. TKO makes employment decisions based on merit and qualifications, without considering an employee’s or applicant’s race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, marital status, veteran status, or any other basis prohibited under federal, state or local laws governing non-discrimination in employment in every location in which the Company has facilities.