We are looking for an experienced Application Security Manager to lead and manage application security initiatives across the organization, with a strong focus on Application Security, Product Security, AI Security, Secure SDLC, DevSecOps, vulnerability management, third-party security assessments, and M&A integration. The role will partner closely with Product, Engineering, DevOps, Architecture, AI, TPRM, Infrastructure, and Security teams to embed security throughout the application lifecycle—from design and development through deployment and production. The ideal candidate will combine strong technical depth in application security with the ability to lead security assessments, influence engineering teams, manage security platforms, assess emerging AI risks, and communicate security risk effectively to technical and executive stakeholders.
1. Application Security & Veracode Platform Management
· Own and manage the organization's Veracode application security platform, including SAST application onboarding, scan configuration, platform administration, and operational support.
· Drive application onboarding and establish appropriate security scanning requirements based on application risk.
· Integrate application security testing into CI/CD pipelines and DevSecOps processes.
· Review, triage, and analyze application security findings and vulnerabilities.
· Provide remediation guidance to Product and Engineering teams and drive findings through closure.
· Support vulnerability prioritization based on severity, exploitability, business impact, and application risk.
· Troubleshoot scanning, integration, configuration, and platform-related issues.
· Manage coordination with the Veracode vendor and support teams.
· Develop application security dashboards, metrics, reports, and management-level insights.
· Establish and maintain application security onboarding, scanning, remediation, and exception-management processes.
2. DAST & Application Security Testing
· Manage and coordinate Dynamic Application Security Testing (DAST) activities across the application portfolio.
· Review and validate DAST reports and security findings.
· Work with Product and Engineering teams to understand vulnerabilities and define remediation strategies.
· Coordinate DAST requirements, scheduling, execution, and remediation tracking.
· Collaborate with internal security teams, external security partners, and application teams to ensure effective DAST operations.
· Track vulnerabilities through closure and provide risk-based recommendations where immediate remediation is not feasible.
· Coordinate with relevant security stakeholders on penetration testing requirements and other applicable security assessments.
3. Product Security & Secure SDLC
· Partner with Product and Engineering teams to define and implement security requirements throughout the Software Development Lifecycle.
· Conduct application security risk assessments and security architecture/design reviews.
· Review application architecture, design, code, integrations, APIs, data flows, and security controls.
· Assess applications against recognized security standards, including OWASP ASVS, addressing product security risks across both design and code layers.
· Ensure required security testing, including SAST, DAST, and SCA, is performed based on application risk and security requirements.
· Drive adoption of Secure SDLC and DevSecOps practices across Product and Engineering organizations.
· Provide security consultation from architecture and design through development, testing, deployment, and production.
· Identify security gaps and define appropriate remediation, mitigation, and compensating controls.
· Establish security checklists, standards, runbooks, processes, and reusable guidance for Product and Engineering teams.
· Track application security risks, vulnerabilities, remediation activities, exceptions, and security readiness.
· Support security reviews for new technologies, POCs, tools, application onboarding initiatives, and emerging technology platforms.
4. AI Security & Agentic AI Security
· Conduct AI security risk assessments for AI-enabled applications, products, platforms, and use cases.
· Review AI architecture, security controls, data flows, integrations, access controls, and deployment models.
· Assess AI solutions against applicable security requirements and identify control gaps.
· Evaluate security risks associated with agentic AI, including agent autonomy, tool usage, access privileges, integrations, data access, and execution of actions.
· Review and assess agentic AI security controls as part of application and AI security assessments.
· Provide risk mitigation recommendations for AI use cases and AI-enabled applications.
· Partner with Product, Engineering, Architecture, Data, and AI teams to embed security into AI solution design and implementation.
· Contribute to the development of AI security standards, controls, assessment frameworks, and governance processes.
· Track AI security findings and ensure appropriate remediation or risk acceptance.
5. AI Security Review Committee
· Perform initial security reviews of proposed AI use cases.
· Assess AI-related security risks and applicable security requirements.
· Participate in AI Security Review Committee discussions with business, technology, risk, privacy, legal, and other stakeholders.
· Identify missing information, documentation, or controls required for security review.
· Provide security recommendations and risk mitigation guidance.
· Support risk-based approval, conditional approval, or rejection decisions for AI use cases.
· Track actions and follow-ups resulting from AI security reviews through completion.
6. Third-Party Product & SaaS Security
· Conduct security assessments of third-party SaaS and technology products.
· Engage with vendors to obtain security questionnaires, architecture information, Trust Center documentation, SOC reports, certifications, penetration testing reports, and other relevant security evidence.
· Review vendor security controls and assess the overall security posture of proposed solutions.
· Identify security risks, control gaps, and potential business impacts.
· Develop risk-based security recommendations and remediation requirements.
· Partner with the Third-Party Risk Management (TPRM) team to finalize vendor risk profiles and security recommendations.
· Communicate security findings and requirements effectively to business, procurement, technology, and vendor stakeholders.
7. M&A & Application Integration Security
· Support cybersecurity integration activities for newly acquired or onboarded applications and technology environments.
· Coordinate with business, application, engineering, vendor, and security teams during M&A integration.
· Support onboarding of acquired applications into Veracode and established application security processes.
· Configure security scans and support troubleshooting during application onboarding.
· Assess application security posture and identify security gaps.
· Provide vulnerability remediation guidance and track outstanding security risks.
· Ensure acquired applications progressively align with organizational Application Security, Product Security, and DevSecOps standards.
8. Security Governance, Risk & Reporting
· Develop and maintain application security standards, processes, runbooks, checklists, and operating procedures.
· Establish and maintain application security metrics and reporting for Security and business leadership.
· Track application security coverage, SAST/DAST/SCA adoption, vulnerability remediation, security SLA compliance, application onboarding, security assessment status, and open security risks and exceptions.
· Communicate security risks, remediation requirements, and recommendations to technical and executive stakeholders.
· Represent Application Security in relevant Product, Technology, AI, Risk, and Security governance forums.
· Support ad hoc security assessments, technology evaluations, POCs, tool evaluations, and emerging security initiatives.
· Drive continuous improvement and automation of application security processes.
Required Qualifications
· Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related discipline.
· 8+ years of experience in Cybersecurity, Application Security, Product Security, Information Security, or a related field.
· Strong experience in Application Security / Product Security and Secure SDLC practices.
· Hands-on experience with SAST, DAST, and SCA solutions.
· Strong experience with Veracode or a comparable application security platform.
· Experience integrating application security tools with CI/CD and DevSecOps pipelines.
· Strong understanding of application vulnerabilities, vulnerability triage, remediation, and risk management.
· Experience conducting security architecture and application design reviews.
· Experience with OWASP standards, particularly OWASP ASVS.
· Experience working directly with Product and Engineering teams throughout the software lifecycle.
· Experience conducting third-party/SaaS security assessments.
· Strong understanding of modern application and cloud architectures.
· Experience with AI security assessments, AI governance, or AI risk management is highly desirable.
· Strong stakeholder management, communication, and influencing skills.
· Ability to translate complex technical security risks into clear business-level recommendations.
Preferred Certifications
· CISSP
· CSSLP
· CISM
· OSCP / OSWE
· CEH
· GIAC certifications
· Azure / AWS / GCP Security certifications
· AI Security / AI Risk certifications
Leadership & Behavioral Competencies
· Strong ownership and accountability.
· Strategic and risk-based decision-making.
· Strong analytical and problem-solving skills.
· Ability to influence Product and Engineering teams without relying solely on authority.
· Excellent written and verbal communication.
· Strong stakeholder and vendor management.
· Comfortable operating in a fast-paced and evolving technology environment.
· Ability to balance security requirements with business and delivery priorities.
· Strong leadership and mentoring capabilities.
· Ability to manage multiple security initiatives simultaneously.
· Curiosity and willingness to continuously learn emerging technologies, particularly AI, cloud, and application security.
Software Powered by ICIMS
www.icims.com