Jobgether
Jobgether

Director, Application Security

engineeringfull-timeUS
SALARY
$220k – $352k/yr
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more

About the role

Accountabilities:

    • Lead and develop a multi-manager security organization spanning Application Security and Security Architecture, establishing clear priorities, strong team culture, and high-performance expectations.

    • Define and execute a 2–3-year strategic roadmap aligned with product and platform engineering priorities and the organization’s evolving security needs.

    • Own workforce planning, organizational design, talent acquisition, succession planning, and development of future security leaders.

    • Build and retain highly technical security teams, with an emphasis on engineers who can develop, automate, and integrate security capabilities into engineering environments.

    • Manage operational budgets, security tooling portfolios, and vendor relationships, prioritizing automation, measurable return on investment, consolidation, and reduction of unnecessary tool complexity.

    • Represent application security and architecture at executive and leadership levels, translating technical security risks into clear business and financial implications.

    • Lead an Application Security program that partners with engineering teams and embeds security capabilities into CI/CD pipelines, development frameworks, and developer tooling.

    • Develop security enablement programs, secure coding training, and internal tools that make secure development practices easier for engineers to adopt.

    • Ensure broad application security coverage across secure design reviews, SAST/DAST, dependency management, API security, and related application protection capabilities.

    • Establish product security practices that incorporate security considerations during product and feature design rather than relying primarily on end-of-development audits.

    • Build and maintain a risk-based vulnerability management program with defined service-level agreements, prioritization processes, and executive reporting.

    • Partner with Security Architecture and Platform Engineering to establish enterprise security patterns, reference architectures, and practical guardrails for cloud-native infrastructure.

    • Advance Zero Trust and identity-driven access principles across the environment, integrating security into infrastructure-as-code and platform capabilities.

    • Provide proactive, practical security guidance during product and platform design reviews to help engineering teams move quickly while managing risk.

    • Monitor emerging threats and technology developments, including AI/ML-related attack surfaces and cloud configuration risks, and evolve security architecture accordingly.

    • Requirements:

      • 12+ years of progressive experience in information security, including at least 5 years leading managers and multi-functional security teams.

      • Previous experience in a high-growth consumer technology, fintech, or similarly engineering-driven environment is strongly preferred.

      • Professional foundation in security engineering, software development, platform engineering, or a closely related technical discipline.

      • Demonstrated ability to lead multiple security domains simultaneously while maintaining strong organizational execution and technical standards.

      • Proven experience building and scaling Application Security programs that integrate into software development lifecycles, CI/CD environments, and developer workflows.

      • Deep knowledge of multi-cloud security, with strong experience in AWS preferred.

      • Hands-on understanding of infrastructure-as-code security, including technologies such as Terraform or CloudFormation, as well as Kubernetes and container security.

      • Strong understanding of Zero Trust architecture and identity-focused security patterns.

      • Experience with modern detection engineering, including custom detection pipelines, SOAR automation, and threat-model-driven security coverage.

      • Ability to quantify security risk and communicate its business and financial implications to executive stakeholders and, ideally, board-level audiences.

      • Demonstrated ability to recruit, develop, and retain highly experienced security engineers and senior individual contributors.

      • Familiarity with modern security technologies and tooling, including SIEM, SOAR, DLP, EDR, EPM, CSPM/CWPP, SAST/DAST, infrastructure-as-code security, and container security.

      • Strong judgment when evaluating security tooling, with an ability to rationalize and consolidate technologies rather than unnecessarily expanding the tool portfolio.

      • Proficiency in at least one scripting or programming language, such as Python or Go, with sufficient technical depth to review automation, detection logic, and security tooling developed by the team.

      • Strong communication, leadership, organizational design, strategic planning, and stakeholder-management skills.

      • Ability to operate effectively in a distributed, remote environment while maintaining close collaboration with engineering and business leadership.

      • Benefits:

        • Base salary of $220,200–$351,800 annually in California, Connecticut, Maryland, Massachusetts, New Jersey, New York, Washington State, and Washington, D.C.

        • Base salary of $209,200–$334,200 annually in Colorado, Hawaii, Illinois, Maine, Minnesota, Nevada, Ohio, Rhode Island, Vermont, and Virginia.

        • Compensation varies based on factors including location, experience, and performance, with applicable state salary requirements observed.

        • Eligibility for equity awards, with actual awards determined based on factors such as experience, performance, and location.

        • Fully remote work within the United States, with employees able to work from a physical location of their choice, subject to limited location exceptions.

        • A distributed-work environment built around flexibility, trust, collaboration, and productivity.

        • Opportunity to lead high-impact security initiatives across application security, cloud security, and security architecture.

        • Significant ownership of organizational strategy, technical roadmaps, budgets, tooling, and talent development.

        • Opportunity to work closely with senior engineering, product, legal, privacy, compliance, and executive stakeholders.

        • An inclusive and collaborative environment focused on innovation, professional growth, and meaningful technical impact.

        • Equal employment opportunity and reasonable accommodation support for qualified candidates.

✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply
Apply now
Director, Application Security at Jobgether — Remote