← Back to Jobs
Director Application Security
Austin, TX
$200k - $215k
1 week ago
💻 Open SourceMentions AI-assisted ('vibe coding') software development governance — role involves securing and governing vibe coding practices.
About the Role
Lead and mature Western Union's enterprise Application Security program, embedding secure-by-design principles across the software development lifecycle and partnering with engineering, product, DevOps, and cloud teams to enable secure, rapid delivery of products.
Job Description
Role
Director-level leader responsible for developing and executing an enterprise Application Security strategy, maturing a scalable AppSec program, and integrating security into the SDLC to enable secure-by-design engineering practices.
Key Responsibilities
- Develop and execute enterprise application security strategy and multi-year transformation roadmap.
- Build and mature a scalable Application Security program for cloud, web, mobile, APIs, containers, and emerging technologies.
- Lead implementation and continuous improvement of a Secure Software Development Lifecycle (SSDLC) and define security standards and requirements for development.
- Integrate security early into CI/CD pipelines and promote developer-friendly security practices.
- Oversee application security testing and assurance: SAST, DAST, SCA, IAST, API security testing, container security, IaC security, secure code review, and coordinate penetration testing and bug bounty programs.
- Partner with DevOps and engineering teams to automate security controls, streamline vulnerability management, and reduce developer burden.
- Operationalize Continuous Threat & Exposure Management (CTEM) across critical applications and services; consolidate exposure signals and establish a common exposure taxonomy and risk model.
- Provide guidance for cloud-native architectures, microservices, APIs, containers, Kubernetes, serverless, AI/ML applications, and third-party integrations.
- Build trusted relationships with engineering leadership, champion security as an engineering quality function, and develop security champions programs.
- Lead, mentor, and grow an Application Security team; manage vendors and technologies; set performance metrics and operational objectives.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or related field required; advanced degree preferred.
- 10+ years progressive experience in Application Security, Software/Product Security, or related cybersecurity disciplines.
- 5+ years leading Application Security teams and demonstrated success building or transforming AppSec programs in enterprise organizations.
- Experience partnering with software engineering organizations in Agile and DevSecOps environments.
- Strong understanding of SSDLC, OWASP Top 10, secure coding principles, threat modeling, API security, cloud-native and container security, CI/CD security, DevSecOps, software supply chain security, and application vulnerability management.
- Knowledge of AI-assisted software development governance and secure use.
- Possesses at least one certification (or comparable alternative): CISSP, CSSLP, GIAC GSSP, or GIAC GCSA.
What Success Looks Like (12–18 months)
- Complete an Application Security maturity assessment and deliver a multi-year transformation roadmap.
- Fully integrate security into CI/CD across major engineering organizations and implement risk-based application security metrics and dashboards.
- Reduce remediation times while maintaining or improving developer satisfaction; standardize threat modeling, secure code review, and testing practices.
Benefits (US-specific highlights)
- Hybrid work arrangement.
- Base salary plus variable target incentive; short-term incentives.
- Medical, dental, and life insurance; accident insurance; multiple health insurance options.
- Parental leave; Family First Programs.
- Tuition repayment assistance program.
- Access to best-in-class development platforms.