Security Engineer Manager, SVP – Application & Product Security
Blackstone · New York, NY · Yesterday
Information Technology$175k–$250k/yrFull-time
Responsibilities
- Lead and manage Blackstone's Application Security team, providing technical leadership, mentoring, career development, and performance management.
- Own the Application Security program roadmap, strategy, and execution across software, cloud-native, and AI-enabled platforms.
- Oversee Security Design Reviews (SDRs), Technical Security Reviews (TSRs), Source Code Reviews (SCRs), Vulnerability Disclosure, penetration testing activities, and vulnerability remediation programs.
- Partner with engineering organizations to embed security controls and secure-by-design principles throughout the software development lifecycle.
- Drive adoption of secure development practices including static analysis, software composition analysis (SCA), SAST, secret scanning, CI/CD security controls, and policy enforcement.
- Lead software supply chain security initiatives, including dependency management, artifact security, and build pipeline protections.
- Establish security standards, reference architectures, and guardrails for cloud-native applications, AI-enabled systems, APIs, and platform services.
- Support security architecture reviews for AWS, Kubernetes, containers, Infrastructure-as-Code, and modern developer platforms.
- Drive vulnerability reduction programs and risk remediation efforts across application portfolios.
- Partner with Security Operations, Infrastructure Security, IAM, and Incident Response teams during investigations involving application or software security risks.
- Evaluate emerging security technologies and lead vendor assessments, proof-of-concepts, and strategic security tooling decisions.
- Develop metrics, reporting, and KPIs that demonstrate risk reduction and program effectiveness.
- Present findings, risks, and strategic recommendations to technology leadership, audit stakeholders, and senior management.
- Stay current on emerging threats, secure development practices, AI security risks, and regulatory requirements.
Qualifications
- 8+ years of experience in application security, product security, software engineering, or security engineering.
- 3+ years of experience managing security engineers or leading security engineering teams.
- Deep understanding of application security principles, secure software development lifecycles, threat modeling, vulnerability management, and secure architecture design.
- Experience conducting security design reviews, code reviews, penetration testing, and security assessments for modern software platforms.
- Experience securing cloud-native architectures, preferably AWS.
- Experience with CI/CD pipelines, developer platforms, Infrastructure-as-Code, and modern software delivery practices.
- Experience with application security tooling including SAST, SCA, DAST, secrets scanning, and developer security platforms.
- Strong communication skills with the experience influencing engineering and business stakeholders.
- Experience securing AI/ML platforms, LLM-enabled applications, or data-driven systems.
- Experience with Kubernetes, containers, APIs, and microservice architectures.
- Experience leading software supply chain security initiatives.
- A minimum of Bachelor’s degree (or foreign equivalent) in Computer Science, Cybersecurity, Engineering, or a related field.