Job Description: Job SummaryWe are seeking a visionary leader in Application Security to drive the security strategy for mission-critical applications and APIs. This role sits at the intersection of technology and business impact, leading secure coding practices and advancing DevSecOps maturity across the organization. You will guide a high-performing security team while embedding security into every phase of the software development lifecycle.
Duties & ResponsibilitiesLead & Inspire- Manage and mentor a team of application security professionals, fostering excellence and continuous improvement
Security Leadership- Serve as the subject matter expert for development, product, and business teams
- Integrate security best practices throughout the SDLC
Secure Design & Testing- Champion OWASP Top 10 and API Top 10 standards
- Promote secure architecture and proactive vulnerability prevention
Strategic Planning- Align secure coding initiatives with development roadmaps
- Develop metrics and reporting on application risk posture
Threat Readiness- Evolve security frameworks and policies to address emerging threats and compliance needs
Hands-On Oversight- Review SAST, DAST, and IAST findings
- Ensure vulnerabilities are remediated prior to production release
DevSecOps Advocacy- Guide tool enhancements and process improvements
- Influence enterprise-wide security modernization efforts
Qualifications, Skills & Experience- 10+ years of experience in Application Security
- Strong expertise in cloud environments (Azure and AWS)
- Deep knowledge of Secure SDLC frameworks and modern security tools
- Proven ability to balance strategic vision with tactical execution
- Excellent communication skills bridging technical and business teams
- Relevant certifications such as CISSP, CISM, CCSK, or OSCP preferred
Working Place: Boston, Massachusetts, United States Company : 2026 Feb 26th Virtual - Berkshire Hathaway Specialty Insurance