
Director, Application Security
Posted 4 hours ago

Posted 4 hours ago
This is a fully remote position, open to applicants in United States.
• Lead and cultivate a multi-manager organization focused on Application Security and Security Architecture.
• Develop and implement a strategic roadmap for the next 2–3 years that aligns with product and platform engineering goals.
• Oversee workforce planning, organizational structure, talent acquisition, and the development of future leaders in security.
• Manage the budget, tools portfolio, and relationships with vendors.
• Represent Application Security in executive and leadership discussions, translating technical risks into business implications.
• Direct an AppSec organization in collaboration with product engineering teams.
• Integrate security capabilities into CI/CD pipelines, frameworks, and developer tools.
• Establish security enablement initiatives, including secure coding training and internal tools.
• Ensure comprehensive coverage of the application portfolio, including secure design reviews, DAST/SAST integration, dependency management, and API security.
• Own the product security strategy and incorporate security into product design.
• Develop and sustain a vulnerability management program with SLAs, risk-based prioritization, and executive-level reporting.
• Create enterprise security patterns, reference architectures, and guardrails for AWS-centric cloud-native infrastructure.
• Promote Zero Trust principles and identity-driven access.
• Integrate security patterns into infrastructure-as-code and platform primitives.
• Collaborate in platform and product design evaluations.
• Assess emerging threats and technological advancements to adapt existing controls.
• Over 12 years of advancing security experience.
• A minimum of 5 years in leadership positions managing managers and multifunctional security teams.
• Experience in a rapidly growing consumer technology or fintech organization is highly preferred.
• Background in security engineering, software development, or platform engineering.
• Proven experience managing multiple security domains at once.
• Successful history of building Application Security programs integrated into the SDLC, CI/CD, and developer workflows.
• Extensive expertise in multi-cloud security, particularly AWS.
• Familiarity with IaC security using Terraform or CloudFormation.
• Knowledge of Kubernetes and container security.
• Experience with Zero Trust architecture.
• Background in detection engineering, including custom detection pipelines, SOAR automation, and threat-model-driven coverage.
• Ability to quantify and articulate security risks in business and financial contexts.
• Experience presenting to executive leadership and ideally to board-level audiences.
• Proven track record in hiring and developing top-tier security engineers.
• Knowledge of SIEM, SOAR, DLP, EDR, EPM, CSPM/CWPP, SAST/DAST, IaC, and container security tools.
• Proficient in at least one scripting or programming language such as Python or Go.
• Equity awards based on experience, performance, and location.
• Option for remote work from any physical location chosen by the employee.
• Flexible working arrangements to allow employees to work from wherever they are most productive through Cloud HQ.
• Commitment to equal employment opportunities and support for accommodations.
Alcoa
McKesson
Truelogic Software
Truelogic Software
Get handpicked remote jobs straight to your inbox weekly.