Security Engineer Manager, SVP – Application & Product Security
Listed on 2026-08-02
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Blackstone is the world’s largest alternative asset manager. Blackstone seeks to deliver compelling returns for institutional and individual investors by strengthening the companies in which the firm invests. Blackstone’s over $1.3 trillion in assets under management include global investment strategies focused on real estate, private equity, credit, infrastructure, life sciences, growth equity, secondaries and hedge funds. Further information is available at
Blackstone Technology and Innovations (BXTI) is the technology team at the core of each of Blackstone’s businesses and new growth initiatives. Serving both internal and external clients, we work to build the next generation of systems that manage risk, create efficiency, and improve transparency within the firm and across our broad community of investors and portfolio companies.
BXTI is fast paced and entrepreneurial – our open, iterative design processes and rapid pace of development mean that everyone on the team has the opportunity to make an impact from day one. We are problem solvers who can take projects from idea to implementation. We believe in active mentoring and developing excellence. We collaborate to find the best answers for our customers and for Blackstone.
We are critical to the firm maintaining its competitive edge.
Blackstone's Security Engineering (Sec Eng) team is responsible for securing the firm's software, cloud, AI, and platform ecosystems through scalable controls, developer enablement, and secure-by-design engineering practices. We are seeking a Security Engineering Manager to lead Blackstone's Application Security program. This individual will be responsible for managing a team of security engineers and driving the strategy, execution, and continuous improvement of application and product security capabilities across the firm.
The role partners closely with Software Engineering, Platform Engineering, Cloud Infrastructure, Security Operations, Data Science, and Technology Leadership teams to ensure security is embedded throughout the software development lifecycle. The Application Security team performs security design reviews, technical security reviews, secure code reviews, penetration testing, vulnerability management, software supply chain security, developer security enablement, and AI security assessments. The team also develops and operates internally built security tooling that enables secure software delivery at scale.
The ideal candidate combines strong technical depth in application security with proven leadership experience managing engineers, driving security programs, and influencing stakeholders across a large enterprise environment.
Responsibilities:- Lead and manage Blackstone's Application Security team, providing technical leadership, mentoring, career development, and performance management.
- Own the Application Security program roadmap, strategy, and execution across software, cloud-native, and AI-enabled platforms.
- Oversee Security Design Reviews (SDRs), Technical Security Reviews (TSRs), Source Code Reviews (SCRs), Vulnerability Disclosure, penetration testing activities, and vulnerability remediation programs.
- Partner with engineering organizations to embed security controls and secure-by-design principles throughout the software development lifecycle.
- Drive adoption of secure development practices including static analysis, software composition analysis (SCA), SAST, secret scanning, CI/CD security controls, and policy enforcement.
- Lead software supply chain security initiatives, including dependency management, artifact security, and build pipeline protections.
- Establish security standards, reference architectures, and guardrails for cloud-native applications, AI-enabled systems, APIs, and platform services.
- Support security architecture reviews for AWS, Kubernetes, containers, Infrastructure-as-Code, and modern developer platforms.
- Drive vulnerability reduction programs and risk remediation efforts across application portfolios.
- Partner with Security Operations, Infrastructure Security, IAM, and Incident Response teams during investigations involving application or software…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).