- • The Application Security Manager has an important role and is responsible for ensuring TSB applications and third party products are developed and maintained is a secure way protects that Bank from threats.
- • Spearhead the red teaming across our software application estate, including mobile, web, cloud and API's - orchestrating a comprehensive assessment along with simulated attacks to ultimately ensure a fortified security posture and inspire confidence into the TSB business.
- • Work closely with Business Value Streams and 3rd party suppliers to ensure application risks are identified, resolved and reported appropriately.
- • Support the business in meeting the Bank’s security standards as part of the system development lifecycle and proactively work with many areas of the wider Group to continually detect, respond and remediate application threats and weakness.
Requirements
- Ability to lead the implementation and ongoing management of application security and vulnerability management capabilities, ensuring alignment with the NIST Cybersecurity Framework, internal policies, regulatory requirements, and industry best practice.
- Ability to own the application security strategy and control environment, including the delivery of security services, metrics, governance, compliance activities, and continuous improvement initiatives across the application estate.
- Ability to maintain visibility and security oversight of the application and API estate, ensuring all assets are identified, onboarded to security tooling, and subject to appropriate security monitoring and testing.
- Direct experience using Veracode & Sonar cube at an enterprise application security level supporting multiple workstreams and release pipelines.
- Ability to oversee the delivery and operation of application and container security services, including SAST, DAST, SCA, RASP, perimeter scanning, and associated security testing capabilities.
- Experience of supporting Red Team and penetration testing activities, including test planning, scheduling, execution oversight, and integration of findings into the wider security improvement programme.
- Experience of driving vulnerability management across applications and supporting infrastructure, ensuring vulnerabilities are identified, prioritised, remediated, tracked, and reported in line with risk appetite and agreed service levels.
- Ability to partner with engineering and development teams to improve security outcomes, providing guidance on vulnerability remediation, secure coding practices, and risk-based prioritisation of security findings.
- Ability to develop and maintain a deep understanding of TSB's technology estate and customer journeys, ensuring security testing and assurance activities are focused on critical business services, key applications, and supporting infrastructure.
- Experience of leadership, governance, and reporting to senior stakeholders, delivering insight into security posture, emerging risks, remediation progress, and overall control effectiveness.
- Ability to lead, coach, and support junior team members, acting as a role model to ensure responsibilities are delivered consistently to a high standard and in line with expected quality and professional standards.
- Confident people manager, able to lead through pace, ambiguity and competing operational priorities.
Core Competencies
Demonstrates expertise in application security management, vulnerability management, and the implementation of security strategies aligned with the NIST Cybersecurity Framework. Proven ability to lead security initiatives, oversee security testing, and collaborate with engineering teams to enhance security outcomes.
Highest-signal resume keywords
- Application Security Management
- Vulnerability Management
- NIST Cybersecurity Framework
- Red Team and Penetration Testing
- Veracode & SonarQube
ATS Optimization Keywords
Hard Skills
- Application Security
- Vulnerability Management
- Security Testing
- Secure Coding Practices
- SAST
- DAST
- SCA
- RASP
- Perimeter Scanning
- Risk-Based Prioritization
Soft Skills
- Leadership
- Coaching
- Stakeholder Reporting
- Collaboration
- People Management
Industry Keywords
- Application Security Strategy
- Security Posture
- Compliance Activities
- Continuous Improvement
- Security Standards
Tools & Technologies
- Veracode
- SonarQube
- Security Tooling
- Application Security Services
- Container Security Services