Leads application security and DevSecOps, embedding security into the software development lifecycle and CI/CD pipelines rather than post-development reviews. Day to day this means owning API/app security, running threat modeling, managing SAST/DAST/SCA and secrets scanning, and driving vulnerability remediation with US and offshore engineering teams.
The Head of
Application Security & DevSecOps is responsible for integrating security
into the organization's software development and technology delivery processes. This role
partners directly with Engineering to build security into the development
lifecycle rather than relying primarily on post-development security reviews.
Key
Responsibilities
Own application and API security
practices.
Establish and mature the Secure
SDLC.
Conduct and facilitate threat
modeling.
Implement and manage SAST, DAST,
SCA and secrets scanning capabilities.
Integrate security controls into
CI/CD pipelines.
Manage application vulnerabilities
and remediation.
Address open-source, dependency
and software supply-chain risk.
Establish secure coding standards
and developer security practices.
Define security requirements for
production access and deployments.
Partner directly with U.S. and
offshore Engineering teams.
Improve developer security
awareness and adoption.
Automate application security
testing and remediation workflows.
Establish meaningful application
security metrics and reporting.
Requirements
Candidate
Requirements
7+ years of application security,
DevSecOps, software engineering or cybersecurity experience.
Strong understanding of modern
application, API and cloud architectures.
Hands-on experience with CI/CD and
application security tooling.
Experience working directly with
software engineering teams.
Strong understanding of software
supply-chain and dependency risk.
Ability to translate security
requirements into practical engineering solutions.
Financial services, fintech or
regulated-industry experience preferred.