Director, Application Security

Zillow Group, Inc.

$220K — $351K *
US-AnywhereRemote in United States
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 12+ years in security, including 5+ years in leadership roles managing multi-functional teams.
  • Background in security engineering or software development with a focus on practical application.
  • Experience owning multiple security domains such as AppSec and architecture simultaneously.
  • Proven record in Application Security leadership, integrating programs into engineering workflows.
  • Expertise in multi-cloud security, particularly AWS and modern security frameworks.
  • Strong analytical skills to communicate security risks in business terms.
  • Reputation as a talent magnet for hiring top-tier security engineers.

Responsibilities

  • Lead and develop a multi-manager organization in Application Security and Security Architecture.
  • Establish a strategic roadmap for security initiatives aligned with product and engineering priorities.
  • Handle workforce planning, talent acquisition, and the development of future security leaders.
  • Manage budget and tool portfolio, focusing on consolidation and efficiency.
  • Represent Application Security at the executive level, translating technical risks to business impacts.
  • Foster a developer-first security culture through training and enablement programs.
  • Partner with Security Architecture to embed secure practices in cloud infrastructure.

Benefits

  • Remote work flexibility with no permanent corporate office.
  • Work from any physical location within the U.S.
  • Opportunity for equity awards based on performance and location.
Full Job Description
About the role

As Director of Information Security, drive the strategy, execution, and maturity Application Security, and Security Architecture and our India Security Team. This is an M5 leadership role that reports directly to the VP, Information Security , and carries significant accountability for the security posture, talent, and engineering culture of a large, multi-function organization.

We are looking for a builder, someone who has led application security organizations inside high-growth technology companies where engineering velocity is a first-class value. You have a background that started in software engineering or security engineering, and you've never fully left it behind. You are the leader who can earn trust with a senior engineers and peers, recruit principal-level security engineers, and then go present business risk.

You will manage a team of managers and senior individual contributors across your four domains, partnering deeply with Platform Engineering, Product, Legal, Privacy, and Compliance. You will set multi-year technical roadmaps, own the operational budget and tooling strategy for your org, and serve as a key voice in defining the company's overall security risk posture and investment priorities.

Responsibilities

Leadership & Organizational Strategy
  • Lead and develop a multi-manager organization across Application Security, and Security Architecture, setting clear direction, healthy team culture, and high-performance expectations at every level.
  • Establish and execute a 2-3-year strategic roadmap for your domains that is tightly coupled to Zillow's product and platform engineering priorities, not just industry compliance frameworks.
  • Own workforce planning, org design, talent acquisition, and the development of a bench of future security leaders-with a specific focus on recruiting and retaining engineers who want to build, not just advise.
  • Manage budget, tooling portfolio, and vendor relationships across your scope, with a bias toward consolidation, automation ROI, and eliminating tool sprawl.
  • Represent Application Security at the executive and leadership level; translate complex technical risk into business impact for the VP


Application Security
  • Lead an AppSec organization that partners with product engineering rather than policing it-building "paved road" security capabilities embedded in CI/CD pipelines, frameworks, and developer tooling.
  • Drive a developer-first security culture: create security enablement programs, secure coding training, and internal tooling that make the secure path the easy path for Zillow's engineers.
  • Ensure comprehensive coverage of Zillow's application portfolio including secure design review, DAST/SAST integration, dependency management, and API security.
  • Own product security strategy, ensuring that security is a design-time consideration in new product features, not an audit checkpoint at the end of the SDLC.
  • Build and maintain a vulnerability management program with clear SLAs, risk-based prioritization, and executive-facing reporting.


Security Architecture
  • Partner with the Security Architecture function to establish and maintain enterprise security patterns, reference architectures, and guardrails for Zillow's cloud-native, AWS-centric infrastructure.
  • Drive Zero Trust principles and identity-driven access across the environment, working with Platform Engineering to embed security patterns into infrastructure-as-code and platform primitives.
  • Ensure security architecture is a proactive partner in platform and product design reviews, providing clear, opinionated guidance that accelerates rather than slows engineering delivery.
  • Maintain a forward-looking architecture posture: evaluate emerging threats and technology shifts (e.g., AI/ML-driven attack surfaces, cloud configuration risk) and evolve controls accordingly.


This role has been categorized as a Remote position. "Remote" employees do not have a permanent corporate office workplace and, instead, work from a physical location of their choice, which must be identified to the Company. U.S. employees may live in any of the 50 United States, with limited exceptions.

In California, Connecticut, Maryland, Massachusetts, New Jersey, New York, Washington state, and Washington DC the standard base pay range for this role is $220,200.00 - $351,800.00 annually. This base pay range is specific to these locations and may not be applicable to other locations.In Colorado, Hawaii, Illinois, Maine, Minnesota, Nevada, Ohio, Rhode Island, Vermont, and Virginia the standard base pay range for this role is $209,200.00 - $334,200.00 annually. The base pay range is specific to these locations and may not be applicable to other locations.

In addition to a competitive base salary this position is also eligible for equity awards based on factors such as experience, performance and location. Actual amounts will vary depending on experience, performance and location. Employees in this role will not be paid below the salary threshold for exempt employees in the state where they reside.

Who you are
  • 12+ years of progressive security experience, with at least 5 years in leadership roles managing managers and multi-functional security teams; prior experience in a high-growth consumer technology or fintech company is strongly preferred.
  • Roots in security engineering, software development, or platform engineering-you have built things, not just governed them, and your technical instincts remain sharp enough to engage credibly with principal engineers and architects.
  • Demonstrated experience owning multiple security domains simultaneously (e.g., SOC/detection, AppSec, architecture) with the organizational maturity to drive excellence across each without personally bottlenecking any of them.
  • Proven track record in Application Security leadership at scale-specifically, building AppSec programs that integrate natively into SDLC, CI/CD, and developer workflows inside technology-forward organizations.
  • Deep expertise in multi cloud security (AWS preferred), including IaC security (Terraform/CloudFormation), Kubernetes/container security, and Zero Trust architecture patterns.
  • Strong detection engineering mindset: experience moving a SOC from alert triage to custom detection pipelines, SOAR automation, and threat-model-driven coverage.
  • Ability to quantify and communicate security risk in business and financial terms; experience presenting to executive leadership and, ideally, board-level audiences.
  • Talent magnet: a reputation for hiring and developing elite security engineers, with the technical credibility to attract senior ICs who could work anywhere.
  • Familiarity with the modern security tooling ecosystem: SIEM, SOAR, DLP,EDR, EPM, CSPM/CWPP ,SaST /DaST. IAC, and container security - with the judgment to rationalize and consolidate rather than accumulate.
  • Proficiency in at least one scripting or programming language (Python, Go, or similar); sufficient to review automation, detection logic, and security tooling code written by your team.

Similar Jobs

More Jobs at Zillow Group, Inc.

More Information Technology Jobs

Find similar Director, Application Security jobs: