Gainwell Technologies

Director of Application and DevSecOps Security

Gainwell Technologies$150K — $214K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in cybersecurity focusing on application security and DevSecOps.
  • 5+ years in a leadership role managing teams.
  • Expertise in secure SDLC and application security testing including SAST, DAST, and SCA.
  • Experience with CI/CD pipeline integration in cloud environments (AWS, Azure, GCP).
  • Strong understanding of container, Kubernetes, and serverless security.

Responsibilities

  • Define and lead Application Security and DevSecOps strategy to align with business goals.
  • Build and evolve a shift-left security program integrated in CI/CD.
  • Establish API security roadmap covering governance and runtime protection.
  • Develop guardrails and self-service security tooling for engineering teams.
  • Lead and mentor a high-performing security engineering team.

Benefits

  • Fully remote work opportunity.
  • Minimal travel required (0-20%).
  • Flexible vacation policy for work-life balance.
  • 401(k) employer match for retirement savings.
  • Comprehensive health benefits and educational assistance.
Full Job Description
Summary

The Director of Application & DevSecOps Security is responsible for leading the organization's strategy and execution of secure software development practices across application security, API security, and DevOps (shift-left) initiatives.

This role establishes and enforces SDLC security policies, defines secure design requirements, and builds scalable training programs to embed security into the engineering culture, ensuring the organization can deliver secure, resilient, and compliant solutions at scale.

This leader partners cross-functionally with Engineering, Product, DevOps, and Risk teams to ensure security is integrated early and continuously throughout the development lifecycle.

Your role in our mission

  • Define and lead the enterprise Application Security and DevSecOps strategy aligned to business objectives.
  • Build and mature a shift-left security program integrated into CI/CD pipelines.
  • Establish and implement roadmap for API security, including governance, discovery, and runtime protection.
  • Balance governance with enablement by establishing guardrails, reusable patterns, and self-service security tooling that empower engineering teams.
  • Lead, mentor, and grow a high-performing security engineering team.
  • Oversee secure coding practices, SAST/DAST/SCA tooling, and vulnerability management processes.
  • Define API security standards including authentication, authorization, rate limiting, and data protection.
  • Drive threat modeling practices across critical applications and services.
  • Partner with engineering and development teams to remediate risks and improve secure design patterns.
  • Embed automated security controls into CI/CD pipelines.
  • Champion developer-first security tooling and workflows
  • Partner with DevOps teams to ensure secure infrastructure-as-code (IaC) practices.
  • Measure and improve security posture through pipeline metrics and KPIs.
  • Define and maintain secure SDLC policies, standards, and control frameworks.
  • Establish secure design and architecture requirements for new systems.
  • Ensure alignment with regulatory and compliance requirements (e.g., SOC 2, ISO 27001, NIST).
  • Lead security reviews and design approvals for critical initiatives.
  • Design and implement role-based and just-in-time developer security training programs.
  • Build secure coding guidelines and internal knowledge resources.
  • Drive security awareness and culture across engineering teams.
  • Partner with leadership to ensure adoption and accountability.
  • Define KPIs and KRIs for application and DevSecOps security maturity.
  • Report on risk posture, vulnerabilities, and program effectiveness to executive leadership.
  • Continuously assess and improve tooling, processes, and coverage.


What we're looking for

  • 10+ years of experience in cybersecurity with a strong focus on application security and DevSecOps.
  • 5+ years in a leadership or director-level role managing teams.
  • Deep expertise in secure SDLC, application security testing (SAST, DAST, SCA), and API security.
  • Experience integrating security into CI/CD pipelines and cloud-native environments (AWS, Azure, or GCP).
  • Experience with container security, Kubernetes security, serverless security concepts and delivery.
  • Strong knowledge of modern architectures (microservices, containers, Kubernetes).
  • Proven experience building security programs and influencing engineering culture.


What you should expect in this role

  • Fully Remote Opportunity - Work from anywhere in the U.S.
  • Minimal Travel Required - Occasional travel opportunities (0-20%).
  • Video cameras must be used during all interviews, as well as during the initial week of orientation.


The deadline to submit applications for this posting is June 5, 2026.

The pay range for this position is $150,200.00 - $214,500.00 per year, however, the base pay offered may vary depending on geographic region, internal equity, job-related knowledge, skills, and experience among other factors. Put your passion to work at Gainwell. You'll have the opportunity to grow your career in a company that values work flexibility, learning, and career development. All salaried, full-time candidates are eligible for our generous, flexible vacation policy, a 401(k) employer match, comprehensive health benefits, and educational assistance. We also have a variety of leadership and technical development academies to help build your skills and capabilities.

About Gainwell Technologies

Gainwell Technologies offerings including Medicaid Management Information Systems (MMIS), fiscal agent services, program integrity, care management, immunization registry, and eligibility services. With over 50 years of proven experience, Gainwell carries forward a reputation for technological innovation, service excellence, and unparalleled industry expertise in offering clients scalable and flexible health and human services solutions for their most complex challenges.

Gainwell Technologies Careers

There has never been a more opportune time to join Gainwell Technologies, a leader in providing cutting-edge technology solutions. As a hub of innovation and diversity, Gainwell Technologies offers a plethora of job opportunities aimed at enhancing the digital landscape.

Work You’ll Do

Join Gainwell Technologies' esteemed team to assist some of the most prominent organizations in mastering their technological advancements and digital transformations. At Gainwell Technologies, the focus is on leveraging a unique blend of technology, industry expertise, and digital innovation to lead the market. Professionals at Gainwell Technologies are positioned uniquely at the crossroads of technology and consulting, driving leadership and growth in various sectors through transformative solutions.

Gainwell Technologies Professional Growth and Opportunities

The team is dedicated to building a leading-edge environment that fosters professional growth and innovation. Gainwell Technologies is not just about addressing the current needs of the market but also about foreseeing and shaping the future of technology.

Innovative Work

At Gainwell Technologies, employees engage in groundbreaking work at the intersection of technology and practical application. The company is home to a large group of dedicated professionals who are committed to delivering robust solutions on trusted platforms.

Career Advancement

Embark on a career journey with Gainwell Technologies where the sky is the limit. The company supports ambitious professionals with comprehensive training, development programs, and diverse certification opportunities designed to future-proof careers in the technology sector.

Explore Job Opportunities and Culture

Gainwell Technologies is committed to creating a workplace culture that promotes diversity and inclusion, where every team member’s contribution is valued. Explore various job opportunities, from internships to full-time positions, and become part of a team that values innovation and leadership.

The Gainwell Technologies Commitment to Diversity and Professional Development

Gainwell Technologies recognizes the importance of diversity training and professional development in creating a thriving workplace. The company is dedicated to providing employees with the resources they need to succeed in their careers and contribute to the industry effectively.

Stay Connected with Gainwell Technologies Careers

Join the Team

Discover open positions that align with your skills and interests. Gainwell Technologies is on the lookout for passionate, curious, and creative professionals who are driven to find solutions and excel in their careers. SEARCH GAINWELL TECHNOLOGIES JOBS

Keep Up to Date

Stay informed with career tips, insider perspectives, and industry-leading insights you can immediately apply—all from the professionals who work at Gainwell Technologies.

READ CAREERS BLOG

Job Alert Emails

Customize your subscription to receive job alerts, the latest news, and insider tips tailored to your preferences. Explore the exciting and rewarding opportunities that await at Gainwell Technologies.
Learn more about Gainwell Technologies
Size
10,001 employees
Industry

Similar Jobs

More Jobs at Gainwell Technologies

More Information Technology Jobs

Find similar Director of Application and DevSecOps Security jobs: