Imprivata

Sr. Manager, DevSecOps and Application Security

Imprivata • $184K — $227K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, IT, Cybersecurity, Engineering, or equivalent experience.
  • 7+ years in DevOps, cloud engineering, software engineering, application security, or related fields.
  • 3+ years of leadership experience in security engineering, DevSecOps, or AppSec.
  • Experience with CI/CD pipelines, cloud platforms, and infrastructure as code.
  • Proficient in SAST, DAST, SCA, and secure software supply-chain practices.
  • Strong scripting or programming skills with knowledge of IAM and secure network design.
  • Ability to communicate technical risks to diverse stakeholders.

Responsibilities

  • Lead and develop the DevSecOps and Application Security team with clear goals and performance expectations.
  • Transition DevSecOps and Application Security into the Security organization, focusing on governance and processes.
  • Own program strategy, staffing, vendor relationships, and budget recommendations.
  • Establish security-by-design practices and provide developer guidance throughout the software lifecycle.
  • Mature application security practices, including secure design and vulnerability management.
  • Implement and govern various security testing and scanning tools.
  • Strengthen software supply-chain security and address risks involving agentic AI.

Benefits

  • Top-notch work environment and developmental opportunities.
  • Competitive total rewards package.
  • Hybrid work model with flexibility.
  • Focus on team culture and having fun.
Full Job Description
Description

We are seeking a Sr. Manager, DevSecOps and Application Security to join our team. This is a hybrid opportunity based out of our Waltham, MA; Austin, TX; or St. Petersburg, FL office.

Job Summary

The Sr. Manager of DevSecOps and Application Security leads Imprivata's unified DevSecOps and application security function. This role embeds security throughout the software and infrastructure lifecycle, from design through retirement. The manager leads the team and partners with Engineering, Product, IT, Cloud and Infrastructure, Quality, SecOps, GRC, and Architecture. The role supports cloud, on-premises, hybrid, API, traditional software, and agentic AI environments.

Duties and Responsibilities
  • Lead, coach, and develop the DevSecOps and Application Security team while establishing clear goals, performance expectations, and development opportunities.
  • Lead the transition of DevSecOps and Application Security into the Security organization, including the operating model, staffing, governance, processes, tools, and stakeholder communications.
  • Own the program strategy, roadmap, staffing plan, vendor relationships, tooling decisions, budget recommendations, intake processes, service expectations, and escalation paths.
  • Establish security-by-design practices, threat modeling, architecture reviews, policy-as-code, reusable engineering patterns, developer guidance, and security training across the software development lifecycle.
  • Mature application security practices, including secure design and code reviews, security testing, penetration testing, bug bounty intake, vulnerability management, and risk-based remediation.
  • Implement and govern SAST, DAST, SCA, secrets detection, container and image scanning, infrastructure-as-code scanning, API testing, license analysis, and risk-based pipeline controls.
  • Strengthen software supply-chain and platform security by protecting repositories, build systems, deployment identities, credentials, release artifacts, cloud services, and on-premises infrastructure.
  • Address security risks involving agentic AI and Model Context Protocol servers and clients, and partner with SecOps on monitoring, incident response, tabletop exercises, and post-incident reviews.
  • Establish ownership, severity criteria, remediation expectations, exception processes, executive reporting, and metrics for security findings and program performance.
  • Other duties as assigned and required.

Required Qualifications
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent practical experience.
  • 7+ years of experience in DevOps, cloud engineering, software engineering, application security, infrastructure security, or a related discipline.
  • Three or more years leading, managing, or mentoring security engineering, DevSecOps, or AppSec professionals, with experience building or maturing programs across multiple products or engineering organizations.
  • Experience embedding security into CI/CD pipelines, software development workflows, cloud platforms, infrastructure as code, containers, Kubernetes, Git-based source control, and CI/CD platforms such as GitHub Actions, GitLab, or Jenkins.
  • Experience with SAST, DAST, SCA, secrets detection, container security, IaC security, vulnerability management, threat modeling, and secure software supply-chain practices.
  • Strong scripting or programming experience and working knowledge of IAM, least privilege, authentication, authorization, encryption, certificates, logging, and secure network design.
  • Demonstrated ability to recruit, develop, motivate, and retain technical talent and translate technical risk for engineers, architects, executives, auditors, and nontechnical stakeholders.

Desired Qualifications
  • Experience securing healthcare, financial services, government, or other regulated-industry products; SaaS, on-premises, hybrid, virtualized, or customer-managed deployments.
  • Experience with identity security, zero trust, SBOMs, SLSA, Sigstore, artifact signing, provenance, policy-as-code, APIs, microservices, serverless, mobile, endpoint software, or agentic AI security.
  • Experience integrating security tools with Jira, ServiceNow, GitHub, GitLab, SIEM, CNAPP, vulnerability management, or GRC platforms.
  • Familiarity with STRIDE, PASTA, attack trees, or other threat-modeling methods; relevant certifications such as CISSP, CCSP, CSSLP, AWS Security Specialty, or equivalent.

This position offers a total compensation range of $184,000.00 to $227,700.00 (inclusive of base salary and variable compensation, such as bonuses and incentives). In addition, more information about Imprivata's benefit offerings can be found here. This range represents the high and low end of Imprivata's compensation range for this position. Actual compensation will vary and may be above or below the range based on various factors, such as a candidate's location, skills, experience, and qualifications.

At Imprivata, we have a top-notch work environment, developmental opportunities, a competitive total rewards package, and the desire to have fun. If you have the skills and qualifications as we have described above, we want to hear from you!

#LI-Hybrid #LI-ML1

About Imprivata

Imprivata is a healthcare IT security company that enables healthcare organizations to access, communicate, and transact patient information securely and conveniently. The company offers a range of products and services, including authentication and access management, secure communications, and patient engagement. Imprivata's solutions are used by over 1,000 healthcare organizations worldwide, including hospitals, clinics, and other healthcare providers. The company was founded in 2002 and is headquartered in Lexington, Massachusetts.
Learn more about Imprivata
Size
1,000 employees
Industry
Founded
2002

Similar Jobs

More Jobs at Imprivata

More Information Technology Jobs

Find similar Sr. Manager, DevSecOps and Application Security jobs: