OverviewDirector, Application Security
Location: Remote – US Work Model: Remote
About the Role
The Director, Application Security is responsible for the security strategy, governance, risk mitigation, and compliance across a diverse array of platforms. This position works in teams to identify, design, and manage a security development lifecycle that includes risk detection, mitigation, and remediation programs and compliance audits.
Here's What You'll Do
- Oversee and plan the strategic vision, organizational structure, operating policies, and procedures to ensure every product is developed securely; identify and oversee the implementation of key architectural mechanisms to enhance software security through reuse and standardization
- Ensure the definition, creation, scaling, maturation, and management of the security technology and tooling platform; design and implement automated controls and tools to create force multipliers that maximize the value of work
- Build and manage the security processes and security organization; establish built-in checks and balances to define and reach corporate security goals and objectives; serve as an expert in data security and privacy through the implementation of regulatory compliance needs across the business
- Direct the security development lifecycle to ensure the incident response process includes triage of security defects, review of mitigation and remediation plans, and external communication of identified or reported security defects; direct the escalation of software security incidents and security reviews
- Provide executive summary reports of assurance metrics to leadership with a comprehensive inventory of attack surface, the state of testing and defensive coverage, and a real-time accounting of open risks; establish direction for data-driven decision-making including operational metrics and track performance against established goals
- Oversee the management of performance and compensation for direct reports; provide coaching and development opportunities; manage and track emerging technologies within the security space to ensure security and compliance standards are continually met
Technology Tools
- Modern Development Languages
- Cloud Platforms
Role Essentials
- Minimum of 15 years' experience with software product development; minimum of five years' experience managing corporate application and product security programs and teams
- Minimum of five years' experience managing a Secure Software Development Life Cycle (SDL) that integrates security into all stages of software development for a large development organization
- Demonstrated technical expertise and understanding of modern development languages and cloud platforms; exceptional skills driving product security initiatives and delivering software security
- Superb written and verbal communication skills; advanced interpersonal and presentation skills; proven ability to facilitate a collaborative team environment and lead consensus within a team
- Experience building, developing, and leading highly effective security teams; demonstrated commitment to excellence with the leadership ability to direct and motivate a team to provide industry-leading security
What We'd Like to See
- Demonstrated ability to provide exceptional follow-through and excellent customer service; exceptionally organized and proactive on next steps and in anticipating issues
- Proven ability to work successfully in a team environment, collaborating with other members of the management team across the organization
- Experience confirming that technology risk considerations are identified and adequately addressed with new and modified software; experience enforcing procedures and standards to meet established audit and compliance requirements
- Experience providing executive summary reports on assurance metrics and attack surface inventory to leadership, with real-time accounting of open risks accrued across verticals
- Experience managing and tracking emerging technologies within the security space to ensure security and compliance standards are continually met; demonstrated ability to ensure team adherence to company standards, tools, and guidelines