Unknown Company

Director Application Security

northern, ky • Posted 6 days ago
Onsite Full Time IT & Technology

Mentions AI-assisted ('vibe coding') software development governance — role involves securing and governing vibe coding practices.

About the Role

Lead and mature Western Union's enterprise Application Security program, embedding secure-by-design principles across the software development lifecycle and partnering with engineering, product, DevOps, and cloud teams to enable secure, rapid delivery of products.

Job Description

Role

Director-level leader responsible for developing and executing an enterprise Application Security strategy, maturing a scalable AppSec program, and integrating security into the SDLC to enable secure-by-design engineering practices.

Key Responsibilities

  • Develop and execute enterprise application security strategy and multi-year transformation roadmap.
  • Build and mature a scalable Application Security program for cloud, web, mobile, APIs, containers, and emerging technologies.
  • Lead implementation and continuous improvement of a Secure Software Development Lifecycle (SSDLC) and define security standards and requirements for development.
  • Integrate security early into CI/CD pipelines and promote developer-friendly security practices.
  • Oversee application security testing and assurance: SAST, DAST, SCA, IAST, API security testing, container security, IaC security, secure code review, and coordinate penetration testing and bug bounty programs.
  • Partner with DevOps and engineering teams to automate security controls, streamline vulnerability management, and reduce developer burden.
  • Operationalize Continuous Threat & Exposure Management (CTEM) across critical applications and services; consolidate exposure signals and establish a common exposure taxonomy and risk model.
  • Provide guidance for cloud-native architectures, microservices, APIs, containers, Kubernetes, serverless, AI/ML applications, and third-party integrations.
  • Build trusted relationships with engineering leadership, champion security as an engineering quality function, and develop security champions programs.
  • Lead, mentor, and grow an Application Security team; manage vendors and technologies; set performance metrics and operational objectives.

Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related field required; advanced degree preferred.
  • 10+ years progressive experience in Application Security, Software/Product Security, or related cybersecurity disciplines.
  • 5+ years leading Application Security teams and demonstrated success building or transforming AppSec programs in enterprise organizations.
  • Experience partnering with software engineering organizations in Agile and DevSecOps environments.
  • Strong understanding of SSDLC, OWASP Top 10, secure coding principles, threat modeling, API security, cloud-native and container security, CI/CD security, DevSecOps, software supply chain security, and application vulnerability management.
  • Knowledge of AI-assisted software development governance and secure use.
  • Possesses at least one certification (or comparable alternative): CISSP, CSSLP, GIAC GSSP, or GIAC GCSA.

What Success Looks Like (12–18 months)

  • Complete an Application Security maturity assessment and deliver a multi-year transformation roadmap.
  • Fully integrate security into CI/CD across major engineering organizations and implement risk-based application security metrics and dashboards.
  • Reduce remediation times while maintaining or improving developer satisfaction; standardize threat modeling, secure code review, and testing practices.

Benefits (US-specific highlights)

  • Base salary plus variable target incentive; short-term incentives.
  • Medical, dental, and life insurance; accident insurance; multiple health insurance options.
  • Parental leave; Family First Programs.
  • Tuition repayment assistance program.
  • Access to best-in-class development platforms.

SAST DAST SCA IAST API Security Container Security Infrastructure-as-Code (IaC) Security Kubernetes Serverless CI/CD Microservices Cloud-native Penetration testing Bug bounty Attack-surface management Threat intelligence Artificial Intelligence and Machine Learning applications OWASP Top 10

Skills

Application Security Secure Software Development Lifecycle (SSDLC) DevSecOps Threat Modeling Vulnerability Management Security Testing Oversight CI/CD Integration Cloud Security Container Security Cross-functional Collaboration Leadership Program Management Vendor Management Mentoring Risk Management Automation Communication Stakeholder Influence

#J-18808-Ljbffr

Director Application Security in northern at Unknown Company

This position is listed as full time and onsite.

Back to Job Search