





Specialized senior security leadership with regulatory focus and metro location yields medium candidate competition.
High because financial-regulatory AppSec, SOC2/PCI/DORA audit experience, and supply-chain security requirements limit cross-industry fit.
Explicit 10+ years, 4+ years leading AppSec, and mandatory compliance/tooling experience create highly strict screening.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead and grow a multi-disciplinary Security Engineering team responsible for Secure SDLC, AppSec, and cloud security across the product portfolio.
Oversee vulnerability operations including risk scoring, remediation prioritization, and SLA management to reduce mean-time-to-remediate.
Act as technical SME for customer security audits, regulatory evidence, incident response, and drive security tooling and supply-chain security strategies.
10+ years in application/product and cloud security with 4+ years leading AppSec or Security Engineering teams.
Direct experience running secure SDLC programs for B2B software vendors in regulated financial services.
Hands-on familiarity with at least two frameworks among OWASP SAMM, BSIMM, OWASP DSOMM, AWS SRA, or equivalent cloud security frameworks.
Strong knowledge of AWS security, DORA, PCI DSS v4.0.1, ISO 27001, SOC 2 Type 2, GDPR, and integration of security tooling into CI/CD pipelines.
Experienced in managing security programs within regulated financial services contexts, including customer audit and regulatory engagements.
Proficient in advanced AppSec tooling and modern threat modelling methodologies, including emerging GenAI/LLM security risks and mitigations.
Strategic leader capable of balancing hands-on technical involvement with team leadership, mentoring, and cross-organizational partnership.