Overview
Manager- Application Security will provide technical leadership and hands-on application security work while managing the AppSec domain and team.
What you'll do
- Spend ~60% of time on application security testing, vulnerability assessments, penetration testing, code reviews, and automation.
- Spend ~40% of time managing AppSec strategy, roadmap, and measurable KPIs and coordinating with stakeholders.
- Lead the Application Security program across products, platforms, and engineering teams.
- Run hands-on SAST, DAST, manual code reviews, penetration testing, and vulnerability validation for web, mobile (Android and iOS), APIs, and cloud.
- Perform security assessments for AI/ML and GenAI systems including LLM applications, model endpoints, RAG pipelines, and agentic workflows.
- Drive remediation governance by triaging, tracking, and reporting vulnerabilities with SLAs and accountability.
- Conduct security architecture and design reviews and define secure coding and threat modeling/hardening standards.
What you'll need
- 10 to 14 years of experience.
- Proven leadership experience in application security, DevSecOps, or software security engineering while staying hands-on.
- Deep hands-on understanding of SAST, DAST, and secure SDLC integration.
- Working knowledge of AI/ML and LLM security, threat modeling, and testing against OWASP Top 10 for LLM Applications, OWASP ML Security Top 10, and MITRE ATLAS.
- Skills to manage AppSec tooling such as Checkmarx, Burp Suite Enterprise, OWASP ZAP, MobSF, and open-source frameworks.
- Familiarity with CI/CD automation, scripting (Python, Bash, PowerShell), and container security (Docker/Kubernetes).
- Certifications such as OSCP, GWAPT, GPEN, or equivalent are preferred.
Details
Read the full description and apply on the company’s own careers page.