×
Register Here to Apply for Jobs or Post Jobs. X

Director Application Security

Job in Austin, Travis County, Texas, 78716, USA
Listing for: Western Union
Full Time position
Listed on 2026-08-26
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 200000 - 215000 USD Yearly USD 200000.00 215000.00 YEAR
Job Description & How to Apply Below

We are seeking an experienced and visionary Director Application Security to lead the strategy, development, and execution of our Application Security program. Reporting to the Vice President of Security Operations, this leader will be responsible for maturing and optimizing application security capabilities across the software development lifecycle, ensuring secure-by-design principles are embedded into engineering practices while enabling rapid delivery of innovative products.

This individual will partner closely with Engineering, Product Management, Architecture, Dev Ops, Cloud Engineering, and Security Operations to integrate security into every phase of software development.

The successful candidate will have extensive experience building or transforming Application Security programs within complex technology organizations and will possess the ability to influence engineering culture through collaboration rather than gatekeeping.

Role Responsibilities:

Application Security Strategy

Develop and execute the enterprise Application Security strategy aligned with business and technology objectives. Build and mature a scalable Application Security program supporting modern software development practices. Define the long-term roadmap for secure software development across cloud, web, mobile, APIs, and emerging technologies. Establish secure-by-design principles and integrate them throughout the Software Development Life Cycle (SDLC).

Secure Development Lifecycle (SSDLC)

Lead the implementation and continuous improvement of a Secure Software Development Lifecycle (SSDLC). Develop standards and security requirements for application development. Partner with engineering teams to integrate security early within CI/CD pipelines. Promote developer-friendly security practices that minimize friction while improving software security.

Security Testing & Assurance
  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Software Composition Analysis (SCA)
  • Interactive Application Security Testing (IAST)
  • API Security Testing
  • Container Security
  • Infrastructure-as-Code (IaC) Security
  • Secure code reviews
  • Penetration testing coordination
Dev Sec Ops  Enablement

Partner with Dev Ops teams to embed automated security controls into CI/CD pipelines. Improve automation of security testing and vulnerability management. Reduce developer burden through integrated tooling and streamlined workflows. Measure security effectiveness while enabling engineering velocity.

Operationalize Continuous Threat & Exposure Management (CTEM)

Define CTEM scope around critical business services, crown-jewel applications, sensitive data, material APIs, and externally exposed assets. Consolidate exposure signals from application testing, attack-surface management, cloud security, vulnerability management, penetration testing, bug bounty, and threat intelligence. Establish a common exposure taxonomy and risk model that incorporates exploitability, reachability, business criticality, threat activity, and compensating controls. Maintain an evidence-backed view of application exposure rather than relying primarily on scanner severity.

Cloud

& Modern Architecture Security

Provide application security guidance for:
Cloud-native applications Microservices APIs Containers Kubernetes Serverless architectures Artificial Intelligence and Machine Learning applications Third-party integrations

Engineering Partnership

Build trusted relationships with engineering leadership. Champion security as an engineering quality function. Develop security champions programs across engineering organizations.

Leadership

Lead, mentor, and develop a high-performing Application Security team. Establish performance metrics and operational objectives. Manage vendor relationships and application security technologies. Support hiring and organizational growth as the program matures. Mentor developers on secure coding practices and emerging threats.

Role Requirements:
  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related field required.
  • Advanced degree preferred.
  • 10+ years of progressive experience in Application Security, Software Security, Product Security, Secure Engineering, or related cybersecurity disciplines.
  • 5+ years leading Application Security teams.
  • Demonstrated success building, transforming, or significantly maturing Application Security programs within enterprise organizations.
  • Experience partnering closely with software engineering organizations in Agile and Dev Sec Ops  environments.
  • Strong understanding of:
    Secure Software Development Lifecycle (SSDLC) OWASP Top 10 Secure coding principles Threat modeling Modern authentication protocols API security Cloud-native application security Container security CI/CD security Dev Sec Ops  Software supply chain security AI-assisted software development ("vibe coding") governance and secure use Application vulnerability management.
  • Possesses at least one of the following certifications (o4 comparable alternative):…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary