Application Security Lead / Manager

Iru

$120K — $150K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years in Application Security, Product Security, or Security Engineering.
  • Strong grasp of secure software development and modern application architectures.
  • Experience in threat modeling and conducting security assessments.
  • Hands-on knowledge of vulnerability management and remediation processes.
  • Proven track record of managing external penetration testing engagements.
  • Familiarity with modern AppSec tools and CI/CD security integration.
  • Excellent communication skills to influence engineering stakeholders.

Responsibilities

  • Manage the Application Security program and secure software development lifecycle (SSDLC).
  • Establish and refine application security standards, policies, and procedures.
  • Integrate security requirements into engineering roadmaps and development workflows.
  • Conduct technical security reviews and application assessments.
  • Lead threat modeling initiatives across various products and platforms.
  • Drive the vulnerability management lifecycle for applications.
  • Oversee implementation of application security tools and CI/CD integration.

Benefits

  • Hybrid work environment (3 days in office per week).
  • 100% individual and dependent medical, dental, and vision coverage.
  • 401(K) with a 4% company match.
  • 20 days PTO with additional wellness week.
  • Equity offered for full-time employees.
  • Paid leave for new parents up to 16 weeks.
  • Modern Health mental health benefits for individuals and dependents.
  • Onsite fitness center and free parking.
Full Job Description
The Opportunity

Iru is seeking an experienced and hands-on Application Security Lead / Manager to own and mature our Application Security program. This role will serve as the operational leader for AppSec, partnering closely with Engineering, Product, and Security leadership to ensure security is embedded throughout the software development lifecycle.

The ideal candidate combines strong technical application security expertise with the ability to influence engineering teams, drive remediation accountability, and scale security processes in a fast-moving environment.

This position is critical to strengthening our security posture, reducing risk, and enabling engineering teams to deliver secure products at speed.

Responsibilities

Application Security Program Ownership
  • Own and manage the Application Security program and secure software development lifecycle (SSDLC).
  • Establish, maintain, and continuously improve application security standards, policies, and procedures.
  • Ensure security requirements are integrated into engineering roadmaps and development processes.
Security Assessments & Threat Modeling
  • Conduct technical security reviews and application security assessments.
  • Lead threat modeling initiatives across products and platforms.
  • Identify architectural and design-level security risks and partner with engineering teams on mitigation strategies.
Vulnerability Management & Remediation
  • Drive the end-to-end vulnerability management lifecycle for applications and services.
  • Establish remediation priorities and accountability across engineering teams.
  • Track, report, and improve vulnerability remediation performance and risk reduction metrics.
Penetration Testing & Offensive Security
  • Manage external penetration testing engagements and red team activities.
  • Coordinate findings validation, remediation planning, and closure activities.
  • Ensure testing results are translated into actionable security improvements.
Security Tooling & CI/CD Integration
  • Oversee implementation and optimization of application security tooling, including:
    • SAST
    • DAST
    • Software Composition Analysis (SCA)
    • Secrets detection
    • Infrastructure-as-Code scanning
  • Integrate security controls and automated testing into CI/CD pipelines.
  • Continuously improve security gates while maintaining developer productivity.
Engineering Partnership & Enablement
  • Serve as the primary security partner to Engineering leadership.
  • Drive security awareness and secure coding practices across development teams.
  • Build scalable processes that enable engineers to identify and address security issues efficiently.
  • Promote a culture of shared security ownership.


Minimum Qualifications

  • 7+ years of experience in Application Security, Product Security, or Security Engineering.
  • Strong understanding of secure software development practices and modern application architectures.
  • Experience performing threat modeling, security assessments, and code review activities.
  • Hands-on experience with vulnerability management and remediation programs.
  • Experience managing external penetration testing engagements.
  • Deep familiarity with modern AppSec tooling and CI/CD security integration.
  • Strong communication skills with the ability to influence engineering and product stakeholders.


Preferred Qualifications

  • Experience leading or building AppSec programs in cloud-native environments.
  • Knowledge of AWS, Azure, or GCP security best practices.
  • Experience with DevSecOps methodologies and automation.
  • Relevant security certifications such as CISSP, CSSLP, GWAPT, GWEB, or OSCP.


Success Metrics

Success in this role will be measured by:
  • Reduction in critical and high-severity security vulnerabilities.
  • Improved Mean Time to Remediation (MTTR).
  • Increased developer adoption and engagement with security programs.
  • Reduction in recurring security findings across products.
  • Effectiveness and integrity of pull request security gates.
  • Maturity and efficacy of security review pipelines.
  • Successful integration of security requirements into engineering planning and delivery.


Benefits & Perks

Competitive salary

Hybrid work environment (3 days in office per week)

100% individual and dependent medical + dental + vision coverage

401(K) with a 4% company match

20 days PTO

Iru Wellness Week the first week in July

Equity for full-time employees

In-office lunch stipend provided

Up to 16 weeks of paid leave for new parents

Paid Family and Medical Leave

Modern Health mental health benefits for individuals and dependents

Fertility benefits

Working Advantage employee discounts

Onsite fitness center

Free parking

Exciting opportunities for career growth

We are excited to be serving a significant need for a fast-growing market, and are proud of the high-performing team we have brought together so far. If you're someone who wants to engage in new, exciting projects that will challenge your skills in the best way possible, we would love to connect with you.

At Iru, we believe in fostering an inclusive environment in which employees feel encouraged to share their unique perspectives, leverage their strengths, and act authentically. We know that diverse teams are strong teams, and welcome those from all backgrounds and varying experiences.

Similar Jobs

More Jobs at Iru

More Information Technology Jobs

Find similar Application Security Lead / Manager jobs: