About this role
Role Overview
The Head of
Application Security & DevSecOps is responsible for integrating security
into the organization's software development and technology delivery processes. This role
partners directly with Engineering to build security into the development
lifecycle rather than relying primarily on post-development security reviews.
Key
Responsibilities
- Own application and API security
practices.
- Establish and mature the Secure
SDLC.
- Conduct and facilitate threat
modeling.
- Implement and manage SAST, DAST,
SCA and secrets scanning capabilities.
- Integrate security controls into
CI/CD pipelines.
- Manage application vulnerabilities
and remediation.
- Address open-source, dependency
and software supply-chain risk.
- Establish secure coding standards
and developer security practices.
- Define security requirements for
production access and deployments.
- Partner directly with U.S. and
offshore Engineering teams.
- Improve developer security
awareness and adoption.
- Automate application security
testing and remediation workflows.
- Establish meaningful application
security metrics and reporting.
Requirements
Candidate
Requirements
- 7+ years of application security,
DevSecOps, software engineering or cybersecurity experience.
- Strong understanding of modern
application, API and cloud architectures.
- Hands-on experience with CI/CD and
application security tooling.
- Experience working directly with
software engineering teams.
- Strong understanding of software
supply-chain and dependency risk.
- Ability to translate security
requirements into practical engineering solutions.
- Financial services, fintech or
regulated-industry experience preferred.
- Remote- US Shift