Senior Application Security Compliance Lead

Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in application security or a related field
  • Experience with SAST, DAST, or similar security technologies
  • Knowledge of SSDLC principles and common security threats
  • Background in managing vulnerability remediation programs
  • Ability to analyze and explain code-level security issues
  • Familiarity with programming languages like C#, C++, Java, or Python
  • Experience with JIRA and Confluence for project tracking

Responsibilities

  • Partner with development teams to address security vulnerabilities
  • Monitor application security scanning programs and assessments
  • Review code to identify and communicate security risks
  • Collaborate with security and development teams to enhance secure practices
  • Work with vulnerability management to ensure compliance with SLAs
  • Create reports on application security metrics and trends
  • Conduct manual testing of security findings as needed

Benefits

  • Hybrid work model allowing flexibility between home and office
  • Opportunity for role-specific hybrid work arrangements
  • Focus on professional growth with process improvements initiatives
Full Job Description
JOB SUMMARY

As a Senior Application Security Compliance Lead, you will help strengthen SMBC's application security program by ensuring security findings are identified, prioritized, and addressed before code is released to production. You will work closely with software engineers, security teams, and technology leaders to improve secure development practices and reduce application risk. This role is well suited for someone with a strong technical background who can review code, explain security issues clearly, and guide remediation efforts across a diverse technology environment.

PRINCIPAL DUTIES AND RESPONSIBILITIES

  • Partner with application development teams to review security findings and drive timely remediation of vulnerabilities identified through security testing activities.
  • Monitor and support application security scanning programs, including SAST, SCA, DAST, IAST, and container security assessments.
  • Review code across multiple programming languages and explain security risks, root causes, and remediation approaches to technical and non-technical audiences.
  • Collaborate with application security, security architecture, and development teams to improve secure software development practices and threat mitigation strategies.
  • Work with vulnerability management teams to validate findings, track remediation progress, and ensure compliance with established service level agreements (SLAs).
  • Create and deliver reports and presentations that communicate application security posture, trends, risks, and remediation progress to leadership.
  • Perform targeted manual validation and testing of security findings, including vulnerability and penetration testing results when needed.
  • Contribute to process improvements, documentation, automation, and application security program maturity initiatives.


POSITION SPECIFICATIONS

  • 5+ years of experience in application security, application penetration testing, or a related cybersecurity discipline.
  • 5+ years of experience with Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), or similar application security technologies.
  • Strong knowledge of secure software development lifecycle (SSDLC) principles, OWASP Top 10, CWE, and common application security threats and mitigations.
  • Experience managing vulnerability remediation programs and engaging development teams to improve security outcomes.
  • Strong ability to read, analyze, and explain code-level security issues and remediation approaches.
  • Experience with one or more programming languages such as C#, C++, Java, Python, or .NET technologies.
  • Ability to develop remediation examples, automation scripts, and tooling to support cybersecurity initiatives.
  • Experience integrating security controls within CI/CD pipelines to improve code quality and vulnerability detection.
  • Experience with securing containerized environments and addressing container security risks.
  • Experience using Jira and Confluence for project tracking, documentation, and collaboration.
  • Strong attention to detail with the ability to create and maintain clear process documentation.


NICE TO HAVE
  • Experience building or leading security champion programs.
  • Experience with application security awareness and developer outreach initiatives.
  • Bug bounty participation or application penetration testing experience.
  • Experience presenting security metrics and program updates to senior leadership.

SMBC's employees participate in a Hybrid workforce model that provides employees with an opportunity to work from home, as well as, from an SMBC office. SMBC requires that employees live within a reasonable commuting distance of their office location. Prospective candidates will learn more about their specific hybrid work schedule during their interview process. Hybrid work may not be permitted for certain roles, including, for example, certain FINRA-registered roles for which in-office attendance for the entire workweek is required.

About Sumitomo Mitsui Financial Group, Inc.

Sumitomo Mitsui Financial Group, Inc. Careers

There has never been a more opportune time to join the dynamic team at Sumitomo Mitsui Financial Group, Inc. (SMFG)—a leading force in the financial services industry recognized for its leadership in innovation and diversity.

Explore Job Opportunities

Sumitomo Mitsui Financial Group, Inc. offers a plethora of job opportunities that cater to a variety of skills and interests. The company is renowned for its commitment to professional growth and leadership development, making it an ideal environment for ambitious individuals looking to advance their careers.

Experience Professional Growth

At SMFG, career advancement is not just a possibility but a priority. The company supports its team members with extensive training programs, including leadership development and diversity training, ensuring that every employee has the tools and knowledge necessary to succeed.

Join a Diverse and Inclusive Team

Diversity and inclusion are at the core of the company culture at Sumitomo Mitsui Financial Group, Inc. With a global team that values unique perspectives and fosters a collaborative and inclusive environment, SMFG is a place where everyone can thrive.

Internship Programs

For those starting their career journey, SMFG offers internship programs that provide a robust foundation in the financial sector. Interns gain invaluable experience, working alongside seasoned professionals and engaging in projects that offer real-world applications of their studies.

Benefits and Culture

Sumitomo Mitsui Financial Group, Inc. is dedicated to not only attracting but also retaining top talent by offering competitive benefits that enhance both personal and professional life. The company culture promotes work-life balance, employee well-being, and continuous learning.

Innovative Work Environment

Innovation is a key driver of SMFG’s success. Employees are encouraged to bring forward-thinking ideas to the table and are provided with the resources to transform these ideas into actionable solutions that drive the financial industry forward.

Networking and Career Development

Networking opportunities within SMFG are abundant. Employees are encouraged to connect with colleagues and industry leaders through various platforms and events, enhancing their professional network and opening doors to myriad career opportunities.

Apply for a Position

Sumitomo Mitsui Financial Group, Inc. is actively hiring and looking for talented individuals who are passionate, curious, and driven. Explore open positions that match your skills and interests on the SMFG careers page.

Stay Connected with SMFG Careers

Keep up to date with the latest career tips, industry insights, and company news from Sumitomo Mitsui Financial Group, Inc. Subscribe to receive updates and stay informed about new job openings and employment trends.

Prepare for Your Interview

Aspiring to join SMFG? Prepare your resume to reflect your best self and gear up for the interview process where you can showcase your skills and passion for finance and innovation.

Career Opportunities Await

At Sumitomo Mitsui Financial Group, Inc., the potential for professional development and personal growth is limitless. Discover the exciting and rewarding career opportunities that await at SMFG, where every position contributes to the company’s global success and leadership in the financial industry.
Learn more about Sumitomo Mitsui Financial Group, Inc.

Similar Jobs

More Jobs at Sumitomo Mitsui Financial Group, Inc.

More Information Technology Jobs

Find similar Senior Application Security Compliance Lead jobs: