Vice President, Application Security Specialist

CLS-Group

• $140K — $180K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Degree in Computer Science, Cybersecurity, or related field, or equivalent experience.
  • Relevant security certifications like CISSP or CSSLP preferred but not mandatory.
  • Strong experience in application security and vulnerability management.
  • Ability to read and interpret code for security validation.
  • Practical knowledge of security testing tools, prioritizing insight over administration.
  • Experience in threat modelling and security design reviews.
  • Excellent communication skills to convey security risks and solutions.

Responsibilities

  • Analyze and validate security findings from various testing methodologies.
  • Assess vulnerabilities considering business impacts and exploitability.
  • Collaborate with developers to prioritize remediation and secure coding practices.
  • Lead threat modeling and architecture security reviews for new features.
  • Promote secure coding standards and reusable security practices.
  • Provide expertise to enhance security testing and SDLC processes.

Benefits

  • 25 holiday days and 3 'life days' for UK/Asia; 23 holiday days for US.
  • 2 paid volunteer days for community support.
  • Generous parental leave policies and transition coaching.
  • Wellbeing and mental health support resources.
  • Inclusion-focused Employee Networks for support and growth.
  • Hybrid working model for work/life balance.
  • Monthly 'Heads Down Days' with no meetings.
  • Generous pension provision in the UK and 401K match in the US.
  • Private medical insurance and dental coverage.
  • Access to discounted gym membership and wellness programs.
  • Comprehensive learning platform with 1000+ courses available.
  • Frequent development sessions to support career growth.
Full Job Description
Role overview:
  • Job title - Application Security Specialist
  • Department - IT Security
  • Level - Vice President
  • Reports to - Director, Application Security
  • Location - New Jersey
  • Compensation - $140,000-$180,000 base salary + variable compensation + 401(k) match + benefits
We're hiring an Application Security Specialist to help development teams build secure, resilient software. This is a hands-on AppSec role for someone who can interpret security findings, understand real-world application risk, and turn that insight into practical guidance for engineers. This is not a DevSecOps tooling integration role: engineering teams own security tool integration, automation, and pipeline operation. Your focus will be on understanding the output of those tools, separating meaningful risk from noise, and partnering with developers to improve the security of the code we write. What you'll do:
  • Analyse and validate findings from SAST, DAST, SCA, API security testing, AI-assisted analysis, penetration testing, and code reviews.
  • Assess vulnerabilities in context, considering exploitability, business impact, compensating controls, and realistic application risk.
  • Work closely with development teams to explain issues clearly, prioritise remediation, and support secure implementation choices.
  • Lead or facilitate threat modelling, secure design reviews, and architecture risk reviews for new features, services, APIs, and platforms.
  • Promote secure coding standards, reusable security patterns, and practical guidance that reduce recurring vulnerability themes.
  • Provide AppSec subject-matter expertise to improve security testing, reporting, and SDLC processes without owning pipeline integration or tool administration.
What you'll bring:
  • Strong experience in application security, secure coding, secure-by-design practices, application security testing, and vulnerability management.
  • Solid understanding of common application and API vulnerability classes, including the OWASP Top 10, and how to remediate them in modern software environments.
  • Ability to read and reason about code well enough to validate findings, identify root causes, and discuss remediation options with developers.
  • Experience with threat modelling, architecture risk reviews, secure design reviews, or similar AppSec activities.
  • Practical knowledge of SAST, DAST, SCA, API security, secrets detection, and related testing approaches, with an emphasis on interpreting results rather than administering tools.
  • Working knowledge of at least one programming language such as Java, Python, JavaScript, C#, or Go.
  • Clear communication skills and the ability to translate security risk into practical guidance for engineering, product, and technology leadership audiences.
  • Collaborative mindset, sound risk judgement, and a coaching style that helps development teams improve their security capability over time.
Qualifications:
  • Degree in a technology discipline such as Computer Science, Information Management, Computer Engineering, Cybersecurity, or equivalent practical experience.
  • Relevant security certifications such as CISSP, CSSLP, GWAPT, GWEB, or equivalent are preferred but not required.
Our commitment to employees: At CLS, we celebrate inclusion and consider this to be one of our strongest assets. We are committed to fostering an environment in which everyone feels comfortable to be who they are, and inclusion is valued. All employees have access to our inclusive benefits, including:
  • Holiday - UK/Asia: 25 holiday days and 3 'life days' (in addition to bank holidays). US: 23 holiday days.
  • 2 paid volunteer days so that you can actively support causes within your community that are important to you.
  • Generous parental leave policies to ensure you can enjoy valuable time with your family.
  • Parental transition coaching programmes and support services.
  • Wellbeing and mental health support resources to ensure you are looking after yourself, and able to support others.
  • Employee Networks (including our Women's Forum, Black Employee Network and Pride Network) in support of our organisational commitment to embrace and always be learning more about inclusivity.
  • Hybrid working to promote a healthy work/life balance, enabling employees to work collaboratively in the office when needed and work from home when they don't.
  • Active support of flexible working for all employees where possible.
  • Monthly 'Heads Down Days' with no meetings across the whole company.
  • Generous non-contributory pension provision for UK/Asia employees, and 401K match from CLS for US employees.
  • Private medical insurance and dental coverage.
  • Social events that give you opportunities to meet new people and broaden your network across the organisation.
  • Annual flu vaccinations.
  • Discounts and savings and cashback across a wide range of categories including health and retail for UK employees.
  • Discounted Gym membership - Complete Body Gym Discount/Sweat equity program for US employees.
  • All employees have access to Discover - our comprehensive learning platform with 1000+ courses from LinkedIn Learning.
  • Access to frequent development sessions on a number of topics to help you be successful and develop your career at CLS.

Similar Jobs

More Jobs at CLS-Group

More Information Technology Jobs

Find similar Vice President, Application Security Specialist jobs: