





Tier-1 brand, mid-level role, metro location, and broad hiring pool increase competition.
Strong domain bias toward enterprise Application Security and regulatory experience reduces cross-industry transferability.
Explicit 5+ years InfoSec, leadership experience, and specific AppSec tool and certification requirements enforce stringent filters.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Manage and lead a team of engineers responsible for designing, testing, and maintaining complex application security solutions and tools across the Secure Software Development Life Cycle (SSDLC).
Own and drive the Application Security product portfolio, including strategy, platform modernization, roadmap execution, vendor management, and adoption of shift-left security practices leveraging DevSecOps and automation.
Collaborate cross-functionally with technology and business teams to improve security testing accuracy, develop secure coding standards, and provide risk-based guidance while managing resources and mentoring talent.
Minimum 5+ years in Information Security Engineering or equivalent via work experience, training, education, or military experience.
At least 2+ years of leadership experience managing security teams.
Experience managing Application Security product teams or tools such as Checkmarx, Fortify, AppScan, Black Duck, etc., and familiarity with DevSecOps, Secure SDLC, API, container, and cloud security.
Bachelor's or Master's degree in Computer Science, Information Systems, Cybersecurity, or related field; industry-recognized certifications like CISSP, CISM, or CSSLP preferred.
Experienced leader with 5+ years managing and developing application security engineering teams and programs, including hands-on with enterprise security tools and security product roadmaps.
Strong knowledge of application security vulnerabilities, secure coding practices, threat mitigation, and integration of security automation into modern software development pipelines.
Able to influence stakeholders, collaborate across functions, manage vendor relationships, and lead strategic security initiatives in a complex, Agile-driven, and cloud-first environment.