Hytech is seeking a forward-thinking Manager of Software Security Architect to lead the strategic development and execution of a world-class application security program. This highly technical leadership role will shape and drive the vision for embedding security across the software development lifecycle (SDLC), including modern AI and machine learning platforms.
The ideal candidate brings deep expertise in secure software development, application security engineering, CI/CD automation, and the ability to integrate security into traditional, cloud-native, and AI-enabled development environments. You will lead a global team of security engineers, build scalable, developer-centric security capabilities, and influence security strategies across engineering, infrastructure, DevOps, and data science teams.
What You’ll Do:
- Own and evolve the enterprise application security program, including long-term vision, technical direction, and execution.
- Define and implement scalable and modern AppSec practices that support cloud-native and AI-enabled application development.
- Lead, mentor, and grow a globally distributed team of application security engineers and specialists.
- Champion a proactive, "shift-left" security culture by embedding security into the entire SDLC.
- Act as a strategic partner to development, DevOps, AI/ML, and product teams to embed secure practices into software delivery and data science workflows.
- Build strong cross-functional relationships to promote security-first thinking and align security investments with business value.
- Represent application security in broader enterprise architecture, risk, and compliance initiatives.
- Drive adoption and optimization of security tooling (SAST, DAST, SCA, IAST, secrets scanning, etc.) integrated into CI/CD workflows.
- Design and deploy developer-friendly tooling for threat modeling, code scanning, secrets detection, and dependency analysis.
- Collaborate with AI/ML engineering teams to implement secure design patterns for model development, training pipelines, and AI service deployment.
- Develop and enforce security controls for AI applications including data integrity, adversarial robustness, model governance, and prompt injection prevention.
- Evaluate and integrate emerging tools focused on securing machine learning pipelines, generative AI models, and AI APIs.
- Build scalable security enablement programs for engineering teams, including secure coding workshops, bootcamps, and self-service platforms.
- Guide the development of internal security documentation, policies, and standards.
- Implement secure-by-default frameworks and reference architectures for internal use.
- Stay current on application security threats, AI security research, and evolving best practices in cloud and software engineering.
- Define key performance indicators (KPIs) to measure security posture and program effectiveness.
What We’re Looking For:
- 6+ years in information security or technology risk roles with a focus on application security, DevSecOps, or product security.
- 2+ years of leadership experience managing high-performing technical teams.
- Hands-on software development background (5+ years), including experience with secure coding and architecture.
- Deep experience building or securing AI/ML platforms, APIs, or pipelines, especially in enterprise-scale environments.
- Proven track record in building AppSec frameworks, secure SDLC processes, and security tooling at scale.
- Deep understanding of OWASP Top 10, threat modeling, secure architecture, vulnerability management, and software supply chain risks.
- Expertise in CI/CD security and integrating tools such as GitHub Actions, Jenkins, Terraform, CloudFormation, etc.
- Experience implementing AI security best practices, including model input validation, training data protection, and secure deployment of LLMs.
- Knowledge of AI/ML-specific risks such as model inversion, data poisoning, adversarial examples, and prompt injection.
- Proficiency with cloud-native environments and container security (e.g., Docker, Kubernetes).
- Ability to build and lead high-performing global teams, including contractors and remote contributors.
- Strong communication skills, capable of translating complex security concepts to executive and engineering audiences.
- Highly collaborative, with the ability to navigate complex environments and influence across functions.
- Comfortable operating in dynamic, high-growth, and high-stakes environments.
- CISSP, CSSLP, AWS Security Specialty, GCIH, GCED, or relevant AI/ML certifications (e.g., Google Cloud ML, AWS Machine Learning Specialty).