×
Register Here to Apply for Jobs or Post Jobs. X

Senior Application Security Compliance Lead

Job in Charlotte, Mecklenburg County, North Carolina, 28245, USA
Listing for: SMBC Group
Full Time position
Listed on 2026-08-01
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 120000 - 180000 USD Yearly USD 120000.00 180000.00 YEAR
Job Description & How to Apply Below

SMBC Group is a top-tier global financial group. Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. The Group has more than 130 offices and 80,000 employees worldwide in nearly 40 countries. Sumitomo Mitsui Financial Group, Inc. (SMFG) is the holding company of SMBC Group, which is one of the three largest banking groups in Japan.

SMFG’s shares trade on the Tokyo, Nagoya, and New York (NYSE: SMFG) stock exchanges.
In the Americas, SMBC Group has a presence in the US, Canada, Mexico, Brazil, Chile, Colombia, and Peru. Backed by the capital strength of SMBC Group and the value of its relationships in Asia, the Group offers a range of commercial and investment banking services to its corporate, institutional, and municipal clients. It connects a diverse client base to local markets and the organization’s extensive global network.

The Group’s operating companies in the Americas include Sumitomo Mitsui Banking Corp. (SMBC), SMBC Nikko Securities America, Inc., SMBC Capital Markets, Inc., SMBC MANUBANK, JRI America, Inc., SMBC Leasing and Finance, Inc., Banco Sumitomo Mitsui Brasileiro S.A., and Sumitomo Mitsui Finance and Leasing Co., Ltd.
As a Senior Application Security Compliance Lead, you will help strengthen SMBC's application security program by ensuring security findings are identified, prioritized, and addressed before code is released to production. You will work closely with software engineers, security teams, and technology leaders to improve secure development practices and reduce application risk. This role is well suited for someone with a strong technical background who can review code, explain security issues clearly, and guide remediation efforts across a diverse technology environment.
Principal Duties And Responsibilities

  • Partner with application development teams to review security findings and drive timely remediation of vulnerabilities identified through security testing activities.
  • Monitor and support application security scanning programs, including SAST, SCA, DAST, IAST, and container security assessments.
  • Review code across multiple programming languages and explain security risks, root causes, and remediation approaches to technical and non-technical audiences.
  • Collaborate with application security, security architecture, and development teams to improve secure software development practices and threat mitigation strategies.
  • Work with vulnerability management teams to validate findings, track remediation progress, and ensure compliance with established service level agreements (SLAs).
  • Create and deliver reports and presentations that communicate application security posture, trends, risks, and remediation progress to leadership.
  • Perform targeted manual validation and testing of security findings, including vulnerability and penetration testing results when needed.
  • Contribute to process improvements, documentation, automation, and application security program maturity initiatives.

POSITION SPECIFICATIONS

  • 5+ years of experience in application security, application penetration testing, or a related cybersecurity discipline.
  • 5+ years of experience with Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), or similar application security technologies.
  • Strong knowledge of secure software development lifecycle (SSDLC) principles, OWASP Top 10, CWE, and common application security threats and mitigations.
  • Experience managing vulnerability remediation programs and engaging development teams to improve security outcomes.
  • Strong ability to read, analyze, and explain code-level security issues and remediation approaches.
  • Experience with one or more programming languages such as C#, C++, Java, Python, or .NET technologies.
  • Ability to develop remediation examples, automation scripts, and tooling to support cybersecurity initiatives.
  • Experience integrating security controls within CI/CD pipelines to improve code quality and vulnerability detection.
  • Experience with securing containerized environments and addressing container security…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary