Manager, Application Security; Remote Eligible
Bellevue, King County, Washington, 98009, USA
Listed on 2025-12-27
-
IT/Tech
Cybersecurity, IT Project Manager, Systems Engineer, IT Consultant
For over 20 years, Smartsheet has helped people and teams achieve–well, anything. From seamless work management to smart, scalable solutions, we’ve always worked with flow. We’re building tools that empower teams to automate the manual, uncover insights, and scale smarter. But more than that, we’re creating space– space to think big, take action, and unlock the kind of work that truly matters.
Because when challenge meets purpose, and passion turns into progress, that’s magic at work, and it’s what we show up for everyday.
Automation and partnership are the keys to creating highly reliable and secure software systems. We are looking for a Manager of Application Security to lead a team of talented engineers dedicated to our "shift-left" mission. In this role, you will bridge the gap between security and engineering, fostering a culture where security is treated as a software engineering challenge.
You will partner closely with product and engineering teams to embed security into the development lifecycle, ensuring our platform is resilient and secure by design. This is a unique opportunity to blend technical expertise with leadership, working at the intersection of infrastructure, automation, and application security.
You will report to our Sr. Director of Engineering located in our Bellevue, WA office, or you may work remotely from anywhere in the US where Smartsheet is a registered employer.
You Will:- Lead and Mentor a High-Performing Team: Hire, develop, and retain top engineering talent. Foster a culture of technical excellence and ownership while providing coaching, career guidance, and performance management for your direct reports.
- Champion "Shift-Left" Security: Partner with development teams to embed security into the CI/CD process. Advocate for and operationalize automated security tooling (SAST, DAST, SCA) to provide developers with fast, actionable feedback.
- Manage External Security Assessments: Oversee the strategy and operations for both the Responsible Disclosure program and third-party penetration testing. You will handle scoping, vendor management, triage, and the facilitation of remediation with internal engineering teams.
- Advise on Customer-Facing Security Features: Collaborate with Product and Engineering teams to provide technical feedback and security requirements for customer-facing features (e.g., encryption controls, audit logging, identity management). You will ensure we are building product capabilities that solve security challenges for our customers.
- Execute the Security
Roadmap:
Collaborate with leadership to implement the strategy for security infrastructure and automation. Ensure your team’s work aligns with business objectives and effectively reduces risk. - Drive Security Automation: Prioritize the engineering of automated solutions for threat detection and vulnerability management. Ensure your team builds tools that allow us to respond to threats at machine speed.
- Enable Incident Response & Compliance: Oversee the team's participation in incident response activities and ensure technical controls support continuous compliance with frameworks such as FedRAMP, SOC 2, and ISO 27001.
- 7+ years of progressive experience in technology, with at least 1-2 years in a management or team lead role for a technical team (App Sec, Dev Sec Ops , or Site Reliability Engineering).
- Technical Background: A BS/MS in Computer Science or equivalent experience, with a strong background in scripting/programming (Python, Go, or Java) and agile development.
- App Sec & Cloud Expertise: Experience with modern application security tool chains (SAST, DAST), vulnerability management, and cloud environments (preferably AWS).
- Framework Knowledge: Familiarity with application security requirements for regulated markets (e.g., FedRAMP, HIPAA, SOC2).
- Collaboration
Skills:
Proven ability to build partnerships between engineering/development and security teams, influencing them to adopt best practices. - Communication
Skills:
Demonstrates the ability to communicate clearly and effectively, both in writing and verbally, with technical and non-technical stakeholders. - Planning and Execution: Ability to translate…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).