Ensemble Health Partners

AVP Cybersecurity

Ensemble Health Partners$171K — $257K *
US-AnywhereRemote in United States
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in application security or DevSecOps, with hands-on engineering experience.
  • 3+ years in a leadership role, capable of mentoring while remaining technical.
  • Familiarity with security frameworks like OWASP ASVS and NIST SSDF.
  • Hands-on experience with security tools (SAST/DAST/SCA) and ability to troubleshoot them.
  • Proficient in one or more programming languages (e.g., Java, Python, Go) for code review and automation.

Responsibilities

  • Lead the development and continuous improvement of the application security and DevSecOps program.
  • Engage directly with team members in code reviews and security assessments, rather than just overseeing tasks.
  • Mentor and grow the skills of application security engineers and security advocates within the organization.
  • Design and integrate security tools into CI/CD pipelines in collaboration with engineering teams.
  • Manage the application vulnerability program, including prioritization and escalation of risks.
  • Collaborate with cross-functional teams to embed security into product design phases.
  • Develop security policies and train engineering staff on secure coding practices.

Benefits

  • Remote work flexibility with required travel based on business needs.
  • Opportunities for professional development and mentoring in a collaborative environment.
Full Job Description
The Opportunity:

The AVP, Application Security (DevSecOps) is a working, hands-on leader who builds, runs, and matures the organization's application security program while remaining an active technical contributor. This role owns secure software development lifecycle (SDLC) strategy, DevSecOps tooling and automation, and application-layer vulnerability management, while also mentoring engineers and security team members and personally performing security architecture reviews, threat modeling, and critical vulnerability triage when needed. The Director partners closely with engineering, product, and infrastructure leaders to embed security into every stage of the software development lifecycle and reports on application risk posture to executive leadership.

Job Competencies
  • Valuing Differences - Works effectively with individuals of diverse cultures, interpersonal styles, abilities, motivations, or backgrounds; seeks out and uses unique abilities, insights, and ideas. Considers the collective.
  • Collaboration - Works cooperatively within teams and partners with others, both internally and externally as needed, to achieve success; focuses on the results of the team, not the achievements of one person. It's "All for One and One for All"
  • Accountability - Accepts personal responsibility and/or consequences of failure and successes, delivering on commitments and refocusing effort when needed. Someone who is willing to step up and own it.
  • Time Management - Effectively manages personal time and resources to ensure that work is completed efficiently.
  • Developing Trust - Gains others' confidence by acting with integrity and following through on commitments; treats others and their ideas with respect and supports them in the face of challenges
  • Takes Initiative - Takes prompt action to accomplish goals and achieve results beyond what is required; is proactive and pursues relentlessly.


Essential Job Functions
  • Build, lead, and continuously mature a comprehensive application security (AppSec) and DevSecOps program spanning secure SDLC, SAST/DAST/SCA, container and cloud-native security, and API security.
  • Serve as a working, hands-on member of the team: perform secure code reviews, threat modeling, security architecture reviews, and hands-on remediation guidance alongside individual contributors, not just through delegation.
  • Mentor and develop application security engineers and embedded security champions, providing technical guidance, pairing on complex issues, and building the team's long-term technical capability.
  • Design, implement, and tune the AppSec toolchain (e.g., SAST, DAST, SCA, container scanning, secrets detection) and integrate security gates into CI/CD pipelines in partnership with engineering teams.
  • Own the application vulnerability management program, including triage, prioritization, remediation SLAs, and escalation of critical findings, personally leading response on high-severity issues.
  • Partner with engineering, product, and architecture teams to embed security requirements and threat modeling into the design phase of new products and features ("shift-left").
  • Develop and maintain application security policies, secure coding standards, and DevSecOps playbooks, and train engineering staff on secure development practices.
  • Manage third-party and open-source software risk, including software composition analysis and remediation of vulnerable dependencies.
  • Report on application security risk posture, program metrics, and remediation trends to executive leadership and other stakeholders.
  • Participate in application-level security incident response, including root cause analysis and remediation planning.


Other Preferred Knowledge, Skills and Abilities
  • 8+ years of experience in application security, secure software development, or DevSecOps, including hands-on engineering or security engineering work
  • 3+ years in a leadership or technical lead capacity, with a demonstrated ability to remain hands-on while managing or mentoring a team
  • Relevant certification preferred (e.g., CSSLP, OSCP, GWAPT, CISSP) and familiarity with frameworks such as OWASP ASVS, OWASP Top 10, and NIST SSDF
  • Hands-on experience with SAST, DAST, and SCA tools (e.g., Checkmarx, Veracode, Snyk, Semgrep, Fortify) and the ability to configure, tune, and troubleshoot them directly
  • Working proficiency in one or more programming languages (e.g., Java, Python, JavaScript/TypeScript, Go, C#) sufficient to review code and build automation or tooling
  • Experience integrating security into CI/CD pipelines and DevOps toolchains (e.g., Jenkins, GitHub Actions, GitLab CI, Azure DevOps)
  • Experience with cloud security and container/orchestration security (e.g., AWS, Azure, or GCP; Docker, Kubernetes)
  • Experience conducting threat modeling (e.g., STRIDE) and security architecture reviews
  • Experience building and scaling a vulnerability management program, including remediation SLAs and executive reporting
  • Strong communication and presentation skills, with the ability to translate technical risk for non-technical stakeholders
  • Ability to work independently, lead a highly skilled AppSec team, and remain a credible technical practitioner
  • Strong analytical and critical thinking skills, with the ability to prioritize under pressure and meet deadlines
  • This position pays between $171,750-257,700 based on experience
  • Must be inquisitive and demonstrate openness to innovation including AI to explore better processes and ways to alleviate friction and improve patient and client experiences
  • This is a remote position; however, candidates must be willing and able to travel to and work onsite at client, temporary, or corporate office locations as business needs require


This posting addresses s state specific requirements to provide pay transparency. Compensation decisions consider many job-related factors, including but not limited to geographic location; knowledge; skills; relevant experience; education; licensure; internal equity; time in position. A candidate entry rate of pay does not typically fall at the minimum or maximum of the role's range.

#LI-LP1

#LI-Remote

Similar Jobs

More Jobs at Ensemble Health Partners

More Information Technology Jobs

Find similar AVP Cybersecurity jobs: