
Senior Application Security Manager – Affirmative Action Position for Women
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Brazil.
• Establish the vision, roadmap, and OKRs for Application Security, ensuring alignment with engineering and business objectives.
• Recruit, develop, and retain a talented team of AppSec engineers and security architects; oversee hiring, performance evaluations, career development, and succession planning.
• Oversee budget management, contract negotiations, and vendor relationships.
• Present the security posture to executive leadership.
• Propel the automation of security processes.
• Communicate intricate technical strategies to executive stakeholders.
• Design and manage automated controls (SAST, DAST, SCA, secret scanning, IaC scanning, container scanning) within CI/CD pipelines.
• Supervise quality gates and monitor associated metrics.
• Implement policy-as-code and admission controls in Kubernetes; guarantee supply chain traceability (SBOM, artifact signing, provenance).
• Oversee the vulnerability management program.
• Conduct and escalate threat modeling and secure design reviews for new systems and structural modifications.
• Establish architectural standards for authentication and authorization, encryption and key management, secrets management, API security, multi-tenant isolation, and service-to-service communication.
• Assess risks associated with new technologies adopted by engineering teams.
• Manage a distributed Security Champions program across various product teams.
• Define the secure coding curriculum and effectively enhance engineering security maturity.
• Serve as the technical point of escalation for application security incidents; facilitate blameless post-mortems and ensure corrective actions tackle root structural issues.
• Assist in compliance and privacy requirements (PCI-DSS, SOC 2, ISO 27001, LGPD) by translating regulatory mandates into engineering controls.
• Proven technical experience in DevSecOps, Offensive Security, and Application Security Architecture.
• Familiarity with governance concerning artificial intelligence risks in the context of cybersecurity.
• Capacity to define and implement security strategies that align with business goals.
• Experience in leading, building, and retaining teams focused on AppSec and security architecture.
• Knowledge of SAST, DAST, SCA, secret scanning, IaC scanning, and container scanning methodologies.
• Understanding of CI/CD, quality gates, policy-as-code, and Kubernetes.
• Acquainted with SBOM, artifact signing, and supply chain provenance concepts.
• Knowledgeable in threat modeling and conducting secure design reviews.
• Expertise in authentication, authorization, encryption, key and secrets management, API security, multi-tenant isolation, and service-to-service communication.
• Familiarity with compliance frameworks such as PCI-DSS, SOC 2, ISO 27001, and LGPD.
• Competitive salary and performance-based bonuses.
• Comprehensive health, dental, and vision insurance.
• Retirement savings plan with company matching.
• Opportunities for professional development and continuing education.
• Flexible work arrangements and remote work options.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.