Senior Application Security Compliance Lead — Vice President
Charlotte, NC (Hybrid) | Full Time
Our client, a top-tier global financial institution, is scaling its application security program and needs a VP-level lead who can sit between security and engineering — reading code, interpreting scan output, and turning findings into remediation that actually happens.
You’ll own the SAST/DAST/SCA/IAST and container security programs end to end, work directly with development teams on fixes, and be the voice that translates technical risk into a story leadership acts on. It’s a hands‑on, high‑visibility seat with real influence over how a global bank builds secure software.
Responsibilities
- Drive remediation of vulnerabilities found via SAST, SCA, DAST, IAST, and container scanning
- Review code across multiple languages; explain risk and remediation to technical and non-technical audiences
- Validate findings and track SLA compliance with vulnerability management teams
- Report on application security posture and remediation progress to leadership
- Manually validate findings, including penetration test results
- Drive process, automation, and maturity improvements across the program
Requirements
- 5+ years in application security, penetration testing, or related cybersecurity discipline
- 5+ years with SAST/DAST or similar tooling
- Strong grounding in SSDLC, OWASP Top 10, CWE
- Experience managing vulnerability remediation programs
- Proficiency in C#, C++, Java, Python, or .NET
- CI/CD security integration and container security experience