Director Application Security
Listed on 2026-08-31
-
IT/Tech
Cybersecurity, Security Management & Operations
Mentions AI-assisted ('vibe coding') software development governance — role involves securing and governing vibe coding practices.
About the RoleLead and mature Western Union's enterprise Application Security program, embedding secure-by-design principles across the software development lifecycle and partnering with engineering, product, Dev Ops, and cloud teams to enable secure, rapid delivery of products.
Job Description RoleDirector-level leader responsible for developing and executing an enterprise Application Security strategy, maturing a scalable App Sec program, and integrating security into the SDLC to enable secure-by-design engineering practices.
Key Responsibilities- Develop and execute enterprise application security strategy and multi-year transformation roadmap.
- Build and mature a scalable Application Security program for cloud, web, mobile, APIs, containers, and emerging technologies.
- Lead implementation and continuous improvement of a Secure Software Development Lifecycle (SSDLC) and define security standards and requirements for development.
- Integrate security early into CI/CD pipelines and promote developer-friendly security practices.
- Oversee application security testing and assurance: SAST, DAST, SCA, IAST, API security testing, container security, IaC security, secure code review, and coordinate penetration testing and bug bounty programs.
- Partner with Dev Ops and engineering teams to automate security controls, streamline vulnerability management, and reduce developer burden.
- Operationalize Continuous Threat & Exposure Management (CTEM) across critical applications and services; consolidate exposure signals and establish a common exposure taxonomy and risk model.
- Provide guidance for cloud-native architectures, microservices, APIs, containers, Kubernetes, serverless, AI/ML applications, and third-party integrations.
- Build trusted relationships with engineering leadership, champion security as an engineering quality function, and develop security champions programs.
- Lead, mentor, and grow an Application Security team; manage vendors and technologies; set performance metrics and operational objectives.
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related field required; advanced degree preferred.
- 10+ years progressive experience in Application Security, Software/Product Security, or related cybersecurity disciplines.
- 5+ years leading Application Security teams and demonstrated success building or transforming App Sec programs in enterprise organizations.
- Experience partnering with software engineering organizations in Agile and Dev Sec Ops environments.
- Strong understanding of SSDLC, OWASP Top 10, secure coding principles, threat modeling, API security, cloud-native and container security, CI/CD security, Dev Sec Ops , software supply chain security, and application vulnerability management.
- Knowledge of AI-assisted software development governance and secure use.
- Possesses at least one certification (or comparable alternative): CISSP, CSSLP, GIAC GSSP, or GIAC GCSA.
- Complete an Application Security maturity assessment and deliver a multi-year transformation roadmap.
- Fully integrate security into CI/CD across major engineering organizations and implement risk-based application security metrics and dashboards.
- Reduce remediation times while maintaining or improving developer satisfaction; standardize threat modeling, secure code review, and testing practices.
- Base salary plus variable target incentive; short-term incentives.
- Medical, dental, and life insurance; accident insurance; multiple health insurance options.
- Parental leave;
Family First Programs. - Tuition repayment assistance program.
- Access to best-in-class development platforms.
SAST DAST SCA IAST API Security Container Security Infrastructure-as-Code (IaC) Security Kubernetes Serverless CI/CD Microservices Cloud-native Penetration testing Bug bounty Attack-surface management Threat intelligence Artificial Intelligence and Machine Learning applications OWASP Top 10
SkillsApplication Security Secure Software Development Lifecycle (SSDLC) Dev Sec Ops Threat Modeling Vulnerability Management Security Testing Oversight CI/CD Integration Cloud Security Container Security Cross-functional Collaboration Leadership Program Management Vendor Management Mentoring Risk Management Automation Communication Stakeholder Influence
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).