Sr. Manager, DevSecOps and Application Security
Listed on 2026-10-08
-
IT/Tech
Cybersecurity
Ready to join a team that's all in? At Imprivata, we deliver unified access and security management programs that eliminate friction, empowering healthcare and mission-critical organizations to work smarter, faster, and more securely.
We believe work can be more than a job or task-it's a collective spirit; the type that emboldens creativity, embraces challenge, and fosters excitement. We are constantly raising the bar on what's possible, owning the outcome of our triumphs and trials, staying nimble amidst change, and cultivating an environment where we win together. Here, your ideas matter, your differences are celebrated, and your work drives real results-for your career, your teammates, and our customers.
When you join Imprivata, you embark on a shared journey of ambition and growth. We're committed to building an inclusive workplace where everyone feels valued and supported. If you're looking for a place to match your passion with purpose—and where every day you can make an impact—you'll find it here.
We are seeking a Sr. Manager, Dev Sec Ops and Application Security to join our team. This is a hybrid opportunity based out of our Waltham, MA;
Austin, TX; or St. Petersburg, FL office.
The Sr. Manager of Dev Sec Ops and Application Security leads Imprivata's unified Dev Sec Ops and application security function. This role embeds security throughout the software and infrastructure lifecycle, from design through retirement. The manager leads the team and partners with Engineering, Product, IT, Cloud and Infrastructure, Quality, Sec Ops, GRC, and Architecture. The role supports cloud, on-premises, hybrid, API, traditional software, and agentic AI environments.
Dutiesand Responsibilities
- Lead, coach, and develop the Dev Sec Ops and Application Security team while establishing clear goals, performance expectations, and development opportunities.
- Lead the transition of Dev Sec Ops and Application Security into the Security organization, including the operating model, staffing, governance, processes, tools, and stakeholder communications.
- Own the program strategy, roadmap, staffing plan, vendor relationships, tooling decisions, budget recommendations, intake processes, service expectations, and escalation paths.
- Establish security-by-design practices, threat modeling, architecture reviews, policy-as-code, reusable engineering patterns, developer guidance, and security training across the software development lifecycle.
- Mature application security practices, including secure design and code reviews, security testing, penetration testing, bug bounty intake, vulnerability management, and risk-based remediation.
- Implement and govern SAST, DAST, SCA, secrets detection, container and image scanning, infrastructure-as-code scanning, API testing, license analysis, and risk-based pipeline controls.
- Strengthen software supply-chain and platform security by protecting repositories, build systems, deployment identities, credentials, release artifacts, cloud services, and on-premises infrastructure.
- Address security risks involving agentic AI and Model Context Protocol servers and clients, and partner with Sec Ops on monitoring, incident response, tabletop exercises, and post-incident reviews.
- Establish ownership, severity criteria, remediation expectations, exception processes, executive reporting, and metrics for security findings and program performance.
- Other duties as assigned and required.
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent practical experience.
- 7+ years of experience in Dev Ops, cloud engineering, software engineering, application security, infrastructure security, or a related discipline.
- Three or…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).