Manager - Application Security

Copart Catastrophe Response Fleet, LLCDallas, TexasOn-siteFull-timeSenior, 5–8 yearsListed 49 minutes ago

Apply now

About this role

Copart, Inc. a technology leader and the premier online vehicle auction platform globally, with over 200 facilities located across the world, Copart links vehicle sellers to more than 750,000 buyers in over 190 countries.  We believe in providing an unmatched experience, every day and everywhere, driven by our people, processes, and technology.

Copart is seeking an Application Security Manager to lead its Application Security team and help ensure that applications, websites, APIs, and services are designed, developed, and operated in accordance with rigorous security standards. This leader will define the AppSec strategy, develop engineers and penetration testers, identify and prioritize application risks, and build strong partnerships with Development, DevOps, Architecture, Infrastructure, and other technology teams across Copart.

Job Duties:

- Define the AppSec strategy, roadmap, day to day operations, and team objectives.
- Report program maturity, risks, and trends to security and technology leadership.
- Hire and manage a globally distributed application security team while providing mentorship and technical guidance.
- Partner with Development, DevOps, Architecture, Infrastructure and other technology teams.
- Lead security reviews and threat modeling for AI-enabled applications, agents, models, APIs, data integrations, and associated development pipelines.
- Conduct technical security assessments, code audits and architectural design reviews.
- Support SDLC and agile environments with application security testing.
- Develop automated solutions that mitigate risks throughout the organization.
- Continue improving developer security enablement, secure-coding education, and Security Champion programs that improve engineering ownership of application risk.
- Provide AppSec support during security incidents and high-severity production events.
- Integrate and automate application security controls, findings, workflows, and reporting across the software delivery lifecycle.

Qualifications:

- BS in Computer Science, Cybersecurity, Engineering, or a related discipline, or equivalent practical experience.
- 5+ years of progressive cybersecurity experience, including three or more years focused on application or product security.
- 2+ years of direct people-management experience.
- Relevant certification such as OSCP, CSSLP, CISSP, GIAC, or cloud-security certifications preferred.
- Strong knowledge of OWASP Top 10 web and the ability to effectively communicate methodologies and techniques with development teams.
- Demonstrated experience leading application security professionals, technical programs, or cross-functional security initiatives.
- Experience implementing security automation within modern source-control, CI/CD, cloud-native, and infrastructure-as-code environments.
- Experience in Java, Python, JavaScript.
- Experience with application security capabilities including SAST, DAST, IAST, SCA, secrets detection, ASPM, API security, container security, WAF/CDN controls, and penetration testing platforms.
- Hands-on experience with secure code review, threat modeling, architectural assessments, penetration testing, and application-security automation.
- Experience with threat modeling methodologies such as STRIDE.

Skills and Attributes:

- People leadership, team development, and managing globally distributed teams.
- Ability to establish strategic vision, roadmap, and team objectives.
- Strategic thinker with a proactive security mindset.
- Strong partnership skills to work cross functionally.
- Excellent communication and presentation skills.
- Continuous learner who stays current with emerging cybersecurity threats and technologies.

###

Benefits Summary: 
·        Medical/Dental/Vision 
·        401k plus a company match 
·        ESPP - Employee Stock Purchase Plan 
·        EAP - Employee Assistance Program (no cost to you) 
·        Vacation & Sick pay 
·        Paid Company Holidays 
·        Life and AD&D Insurance 
·        Discounts 
Along with many other employee benefits.

#LI-KK1

At Copart, we are focused on harnessing the power of diversity, inclusion, and collaboration. By embracing diverse perspectives, we open doors to innovation and unleash the full potential of our team. We are dedicated to fostering a workplace where everyone feels appreciated, included, and inspired to grow and contribute meaningfully.

E-Verify Program Participant: Copart participates in the Department of Homeland Security U.S. Citizenship and Immigration Services' E-Verify program (For U.S. applicants and employees only). Please click below to learn more about the E-Verify program:

- E-verify Participation (https://www.e-verify.gov/sites/default/files/everify/posters/EVerifyParticipationPoster.pdf)
- Right to Work (https://www.e-verify.gov/sites/default/files/everify/posters/IER_RightToWorkPoster%20Eng_Es.pdf)