Lead Application Security Engineer

Apollo Global Management, Inc.

$190K — $250K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of hands-on experience in Application Security with a strong software development background.
  • Bachelor's degree in Computer Science, Information Technology, or related field.
  • Demonstrated success in partnering with software development teams for security oversight.
  • Proven expertise with IDEs, version control systems, and secure SDLC practices.
  • Experience with Snyk and GitHub is highly desirable.
  • Strong understanding of application architecture and penetration testing methodologies.
  • Exceptional collaboration and critical thinking skills for dynamic environments.
  • Familiarity with security standards like OWASP and NIST; experience in regulated industries is a plus.

Responsibilities

  • Lead application threat modeling for risk identification and mitigation.
  • Guide teams in secure design principles and validate adherence to security controls.
  • Define and implement secure SDLC processes and drive adoption across development teams.
  • Integrate security tools to streamline analysis, reporting, and remediation workflows.
  • Build a security champion program to foster developer engagement and understanding of secure coding practices.
  • Oversee penetration testing and application assessments for vulnerability identification and remediation.
  • Establish governance frameworks to ensure compliance with internal policies and regulatory requirements.

Benefits

  • Outperform expectations
  • Challenge convention
  • Champion opportunity
  • Lead responsibly
  • Drive collaboration
Full Job Description
Position Overview

We are seeking a Director of Application Security to join Apollo's global Cyber Security & Risk team within Engineering. This leader will define and drive the firm's application security strategy-strengthening secure development practices, architecture, and runtime environments across a diverse, expanding portfolio.

You will oversee the design and operation of a scalable application security program, partnering closely with engineering, security, and business teams to embed security throughout the software lifecycle.

Primary Responsibilities
  • Application Threat Modeling:
    Lead threat modeling for new and existing applications to identify risks, recommend mitigations, and ensure control alignment with enterprise standards.
  • Application Design & Architecture:
    Guide teams in secure design principles, validate adherence to security controls, and ensure threat models inform architectural decisions.
  • Secure SDLC Development & Implementation:
    Define and implement secure development lifecycle (SDLC) processes and tools-including SAST, SCA, and secret scanning-and drive adoption across development teams.
  • Operationalization of Security Tools:
    Integrate and maintain security tooling to streamline analysis, reporting, and remediation workflows throughout the software lifecycle.
  • Application Security Awareness & Enablement:
    Build and sustain a security champion program, fostering developer engagement and ensuring teams understand secure coding practices and delivery expectations.
  • Application Security Testing:
    Oversee penetration testing, code reviews, and application assessments to identify vulnerabilities and guide timely remediation.
  • Governance, Risk, and Compliance:
    Establish governance frameworks to ensure compliance with internal security policies, industry standards, and regulatory requirements. Monitor, report, and continuously improve the firm's compliance posture.


Qualifications & Experience
  • 10+ years of hands-on experience in Application Security, with a strong background in software development (IDE/CLI environments).
  • Bachelor's degree in Computer Science, Information Technology, Information Security, or a related field.
  • Demonstrated success partnering with software development teams to provide security oversight across complex application ecosystems.
  • Proven expertise with IDEs, version control systems, CI/CD pipeline management, secure SDLC practices, and SaaS-based security tools (SCA, SAST, DAST) as well as application inventory management.
  • Experience with Snyk and GitHub is highly desirable.
  • Strong understanding of application architecture, security controls, cloud environments, and penetration testing methodologies.
  • Exceptional collaboration and critical thinking skills, with the ability to operate effectively in a fast-paced, dynamic environment.
  • Familiarity with leading security standards and frameworks (OWASP, NIST, ISO 27001, MITRE ATT&CK) and testing tools such as Burp Suite.
  • Experience working within or alongside regulated industries (e.g., financial services) and understanding their impact on application security practices.
  • Ongoing commitment to staying informed on emerging threats and trends to proactively enhance security measures.
  • Professional certifications such as CISSP, CSSLP, CASE, GWEB, or MCSA/MCSE are strongly preferred


Our Benefits

Apollo relies on its people to keep it a leader in alternative investment management, and the firm's benefit programs are crafted to offer meaningful coverage for both you and your family. Please reach out to your Human Capital Business Partner for more detailed information on specific benefits.
  • Outperform expectations
  • Challenge Convention
  • Champion Opportunity
  • Lead responsibly
  • Drive collaboration


Pay Range
$190,00 - $250,000

Similar Jobs

More Jobs at Apollo Global Management, Inc.

More Information Technology Jobs

Find similar Lead Application Security Engineer jobs: