Terumo Medical Corporation

TG IT Application Security Manager

Terumo Medical Corporation$121K — $151K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field; Master's degree preferred.
  • 8-10+ years of cybersecurity experience.
  • 5+ years in an Application Security role.
  • 3+ years of experience leading security teams.
  • Familiarity with enterprise DevSecOps programs, Agile, and CI/CD environments.
  • Experience with cloud-native application security.

Responsibilities

  • Collaborate with global leaders to shape enterprise Application Security strategy.
  • Lead and mentor Application Security Analysts for team growth.
  • Define key metrics and maturity goals for Application Security in partnership with security leaders.
  • Integrate security practices into all phases of the application lifecycle.
  • Oversight of diverse security testing methodologies including SAST and DAST.
  • Facilitate threat modeling sessions to enhance application defenses.
  • Manage and report on application vulnerability remediation processes.

Benefits

  • Comprehensive medical, dental, and vision plans.
  • Robust wellness program for enhanced employee well-being.
  • Life insurance and disability coverage options.
  • 401(k) retirement plan with matching contributions.
  • Vacation and sick time for work-life balance.
  • Additional voluntary programs for personal security and convenience.
Full Job Description
Requisition ID: 35487

Application Security Manager

JOB SUMMARY

Enterprise Application Portfolio - The Application Security Manager is responsible for leading the organization's Application Security program, ensuring that security is integrated throughout the Application Cycle (SDLC). This role partners closely with the software teams, cloud, architecture, infrastructure, and potentially product teams to identify, assess, and mitigate application security risks while enabling secure software delivery.

The successful candidate will lead a team of application security analysts, establish secure development standards, oversee security testing programs, and drive adoption of security best practices aligned with industry standards such as NIST SP 800-218 (Secure Software Development Framework), NIST Cybersecurity Framework (CSF) 2.0, OWASP, and CIS Controls.

Employment Type: Full-time

Department: Global Cybersecurity

Role Reports to: Security Operations Leader

Location: Americas

Work Arrangement: Hybrid

Scope: Regional

ESSENTIAL DUTIES (or key responsibilities)

Application Security Leadership
  • Collaborate with other global and regional leaders within to develop the enterprise Application Security strategy.
  • Lead, mentor, and develop Application Security Analysts.
  • Define AppSec metrics, KPIs, and maturity goals in collaboration with regional and global security leaders.


Secure Software Lifecycle
  • Integrate security into all phases of the enterprise application portfolio.
  • Ensure security requirements are incorporated during design and architecture reviews.
  • Promote security-by-design principles across application teams.


Security Testing

Manage and oversee:
  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Software Composition Analysis (SCA)
  • Interactive Application Security Testing (IAST)
  • API Security Testing
  • Container Security
  • Infrastructure as Code (IaC) Security
  • Mobile Application Security Testing
  • Secrets Detection
  • Review findings, prioritize remediation, and validate fixes.
  • Assist in Supply Chain Security


Threat Modeling
  • Facilitate threat modeling sessions with development teams.
  • Identify abuse cases and attack paths.
  • Recommend architectural improvements.
  • Ensure high-risk applications undergo formal security architecture reviews.


Vulnerability Management
  • Establish application vulnerability management processes
  • Prioritize remediation using risk-based methodologies
  • Track remediation SLAs
  • Report vulnerability metrics to executive leadership
  • Coordinate penetration testing remediation activities
  • Threat Intelligence


Cloud Application Security

Support secure development within cloud platforms including:
  • AWS
  • Microsoft Azure
  • Google Cloud Platform


Secure Code Reviews
  • Conduct manual secure code reviews
  • Review high-risk applications
  • Provide secure coding guidance
  • Coach development teams on remediation


API Security
  • Establish and set-up safe rules
  • Find weak spots through testing
  • Monitor logs to spot shadow APIs and strange traffic patterns


Security Awareness

Collaboration on training programs covering:
  • OWASP Top 10
  • Secure Coding
  • API Security
  • Cloud Security
  • Common software vulnerabilities
  • Secure design principles


Application Risk Management
  • Perform application security risk assessments.
  • Support enterprise application risk management initiatives.


Incident Response

Support cyber incident response by:
  • Investigating application security incidents.
  • Supporting forensic analysis.
  • Identifying root causes.
  • Leading post-incident reviews.
  • Developing preventive controls.


Compliance

Support compliance initiatives including:
  • NIST CSF 2.0
  • NIST SP 800-218 (SSDF)
  • NIST SP 800-53
  • OWASP ASVS
  • PCI DSS
  • HIPAA
  • SOX
  • ISO/IEC 27001
  • SOC 2


OTHER DUTIES AND RESPONSIBILITIES

MINIMUM QUALIFICATION REQUIREMENTS

Education
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field.
  • Master's degree preferred.


Experience
  • 8-10+ years of cybersecurity experience.
  • 5+ years in Application Security.
  • 3+ years leading security teams.
  • Experience implementing enterprise DevSecOps programs.
  • Experience working with Agile and CI/CD environments.
  • Experience with cloud-native application security.


-Or-

An equivalent competency level acquired through a variation of these qualifications may be considered.

Certificates, Licenses, Registrations
  • CISSP
  • CSSLP
  • GIAC Web Application Penetration Tester (GWAPT)
  • GIAC Secure Software Programmer (GSSP)
  • Certified Cloud Security Professional (CCSP)
  • Certified Information Security Manager (CISM)
  • Microsoft Certified: Cybersecurity Architect Expert
  • Microsoft Certified: Azure Security Engineer Associate


Korn Ferry Competencies

Leadership Competencies
  • Strong people leadership
  • Strategic planning
  • Executive communication
  • Stakeholder management
  • Cross-functional collaboration
  • Risk-based decision making
  • Program management
  • Coaching and mentoring
  • Conflict resolution
  • Continuous improvement mindset


Key Performance Indicators (KPIs)
  • Critical vulnerability remediation SLA compliance
  • Mean time to remediate (MTTR)
  • Percentage of applications covered by SAST, DAST, and SCA
  • Security defects identified pre-production
  • Reduction in high-risk application vulnerabilities
  • CI/CD pipeline security coverage
  • Secure code review completion rate
  • Threat model completion rate
  • Developer secure coding training completion
  • Penetration test remediation completion
  • Application security maturity score
  • Audit and compliance findings related to application security


PHYSICAL REQUIREMENTS (for US only)

Typical Office Environment requirements include: reading, speaking, hearing, close vision, traverse, bending, sitting, and occasional lifting up to 20 pounds.

Target Pay Range: $121,400.00 to $151,800.00 - Salary to be determined by the education, experience, knowledge, skills, and abilities of the applicant, internal equity, and alignment with market data
Target Bonus on Base: 15.0

We anticipate this requisition will be open for a minimum of five days, from 09/16/2026. We encourage your prompt application.

At Terumo Blood and Cell Technologies, we provide competitive total reward offerings that consist of compensation, benefits, recognition, along with a wealth of other well-being, work-life and recognition programs which support in unlocking the potential for you and your family. Included in our expansive list of benefits offerings are multiple group medical, dental and vision plans, a robust wellness program, life insurance and disability coverages, also a variety of voluntary programs such as group accident, hospital indemnity, critical illness, pet insurance and much more. To help you save for retirement, we offer a 401(k) plan with a matching contribution and for work-life balance we have vacation and sick time programs for associates. For us, it's about protecting the personal welfare of our associates and their families, helping to achieve personal goals and offering those extra touches for convenience, security and overall peace of mind.

About Terumo Medical Corporation

Terumo Medical Corporation is a subsidiary of Terumo Corporation, a global medical technology company based in Japan. Terumo Medical Corporation is a leading manufacturer and distributor of medical devices and supplies, including syringes, needles, catheters, and blood bags. The company's products are used in a wide range of medical procedures, including cardiovascular surgery, dialysis, and blood transfusions. Terumo Medical Corporation is committed to improving patient outcomes and has a strong focus on research and development. The company has a global presence, with operations in North America, Europe, and Asia.
Learn more about Terumo Medical Corporation
Size
28,294 employees
Industry
Founded
1972
NASDAQ

Similar Jobs

More Jobs at Terumo Medical Corporation

More Information Technology Jobs

Find similar TG IT Application Security Manager jobs: