Application Security Manager

Terumo Blood and Cell Technologies

Apurímac

Híbrido

PEN 403.000 - 638.000

Jornada completa

Hace 2 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

No envíes un currículum genérico — crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Descripción de la vacante

Terumo Blood and Cell Technologies is seeking an Application Security Manager to lead the Global Cybersecurity team's application security program. You will partner with software, cloud, architecture, and product teams to embed security throughout the application lifecycle and drive adoption of best practices in line with NIST, OWASP, and CIS controls.

You will manage a team of analysts, define security metrics, oversee SAST/DAST/IAST/SCA testing, and guide secure coding across cloud platforms.

Formación

  • 8–10+ years of cybersecurity experience.
  • 5+ years in Application Security.
  • 3+ years leading security teams.
  • Experience implementing enterprise DevSecOps programs.
  • Experience working with Agile and CI/CD environments.
  • Experience with cloud-native application security.

Responsabilidades

  • Lead, mentor, and develop Application Security Analysts.
  • Define AppSec metrics, KPIs, and maturity goals with security leaders.
  • Integrate security into all phases of the application portfolio.
  • Oversee SAST, DAST, SCA, IAST, and API security testing programs.
  • Facilitate threat modeling sessions and architectural reviews.
  • Establish vulnerability management processes and report metrics.
  • Provide secure coding guidance across cloud platforms like AWS.
  • Drive security awareness and training across teams.
  • Support incident response and forensics related to applications.
  • Ensure compliance with NIST CSF 2.0, SSDF, OWASP ASVS, PCI DSS, HIPAA, ISO/IEC 27001, SOC 2.

Conocimientos

Cybersecurity
Application Security
DevSecOps
Cloud security
CI/CD
Agile

Educación

Bachelor's degree in Computer Science / Cybersecurity
Master's degree preferred

Herramientas

SAST tooling
DAST tooling
SCA tooling
IAST tooling
CI/CD tooling
Cloud platforms (AWS)

Descripción del empleo

Enterprise Application Portfolio - The Application Security Manager is responsible for leading the organization's Application Security program, ensuring that security is integrated throughout the Application Cycle (SDLC). This role partners closely with the software teams, cloud, architecture, infrastructure, and potentially product teams to identify, assess, and mitigate application security risks while enabling secure software delivery.

The successful candidate will lead a team of application security analysts, establish secure development standards, oversee security testing programs, and drive adoption of security best practices aligned with industry standards such as NIST SP 800-218 (Secure Software Development Framework), NIST Cybersecurity Framework (CSF) 2.0, OWASP, and CIS Controls.

Employment Type: Full-time

Department: Global Cybersecurity

Role Reports to: Security Operations Leader

Work Arrangement: Hybrid

Scope: Regional

ESSENTIAL DUTIES (or key responsibilities)
Application Security Leadership
  • Collaborate with other global and regional leaders within to develop the enterprise Application Security strategy.
  • Lead, mentor, and develop Application Security Analysts.
  • Define AppSec metrics, KPIs, and maturity goals in collaboration with regional and global security leaders.
Secure Software Lifecycle
  • Integrate security into all phases of the enterprise application portfolio.
  • Ensure security requirements are incorporated during design and architecture reviews.
  • Promote security-by-design principles across application teams.
Security Testing

Manage and oversee:

  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Software Composition Analysis (SCA)
  • Interactive Application Security Testing (IAST)
  • API Security Testing
  • Container Security
  • Infrastructure as Code (IaC) Security
  • Mobile Application Security Testing
  • Review findings, prioritize remediation, and validate fixes.
  • Assist in Supply Chain Security
Threat Modeling
  • Facilitate threat modeling sessions with development teams.
  • Identify abuse cases and attack paths.
  • Recommend architectural improvements.
  • Ensure high-risk applications undergo formal security architecture reviews.
Vulnerability Management
  • Establish application vulnerability management processes
  • Track remediation SLAs
  • Report vulnerability metrics to executive leadership

Support secure development within cloud platforms including:

  • AWS
  • Provide secure coding guidance
  • Coach development teams on remediation
API Security
  • Establish and set-up safe rules
  • Find weak spots through testing
  • Monitor logs to spot shadow APIs and strange traffic patterns
Security Awareness

Collaboration on training programs covering:

  • OWASP Top 10
  • Secure Coding
  • API Security
  • Common software vulnerabilities
  • Perform application security risk assessments.

Support cyber incident response by:

  • Investigating application security incidents.
  • Supporting forensic analysis.
  • Identifying root causes.
  • Developing preventive controls.
Compliance
  • NIST CSF 2.0
  • NIST SP 800-218 (SSDF)
  • NIST SP 800-53
  • OWASP ASVS
  • PCI DSS
  • HIPAA
  • SOX
  • ISO/IEC 27001
  • SOC 2
OTHER DUTIES AND RESPONSIBILITIES
MINIMUM QUALIFICATION REQUIREMENTS
Education
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field.
  • Master's degree preferred.
Experience
  • 8-10+ years of cybersecurity experience.
  • 5+ years in Application Security.
  • 3+ years leading security teams.
  • Experience implementing enterprise DevSecOps programs.
  • Experience working with Agile and CI/CD environments.
  • Experience with cloud-native application security.

-Or-

An equivalent competency level acquired through a variation of these qualifications may be considered.

Certificates, Licenses, Registrations
  • CISSP
  • CSSLP
  • GIAC Secure Software Programmer (GSSP)
  • Certified Cloud Security Professional (CCSP)
  • Certified Information Security Manager (CISM)
  • Microsoft Certified: Cybersecurity Architect Expert
  • Microsoft Certified: Azure Security Engineer Associate
  • Strong people leadership
  • Strategic planning
  • Executive communication
  • Cross-functional collaboration
  • Risk-based decision making
  • Program management
  • Coaching and mentoring
Key Performance Indicators (KPIs)
  • Critical vulnerability remediation SLA compliance
  • Mean time to remediate (MTTR)
  • Percentage of applications covered by SAST, DAST, and SCA
  • Security defects identified pre-production
  • Reduction in high-risk application vulnerabilities
  • CI/CD pipeline security coverage
  • Secure code review completion rate
  • Developer secure coding training completion
  • Penetration test remediation completion
  • Application security maturity score
  • Audit and compliance findings related to application security
PHYSICAL REQUIREMENTS (for US only)

Typical Office Environment requirements include: reading, speaking, hearing, close vision, traverse, bending, sitting, and occasional lifting up to 20 pounds.

Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Platform Architect ( Armis/Veza)
Platform Architect ( Armis/Veza)

ServiceNow • San Francisco de Cayrán

Híbrido
PEN 202.000 - 302.000
Flexible work model
IT Security Engineer
IT Security Engineer

Blue Bird • Asia

Presencial
PEN 235.000 - 336.000
Senior Cloud DevSecOp Engineer IRC303764
Senior Cloud DevSecOp Engineer IRC303764

GlobalLogic • Lima Metropolitana

Presencial
PEN 303.000 - 437.000
Competitive salaries
Family medical insurance
Extended paternity leave
+2
Sr Customer Success Manager ( Armis/Veza)
Sr Customer Success Manager ( Armis/Veza)

ServiceNow • San Francisco de Cayrán

A distancia
PEN 202.000 - 302.000
Product Manager De Canales Digitales
Product Manager De Canales Digitales

Central Sport Perú • Áncash

Presencial
PEN 302.000 - 437.000
Service Operations Admin
Service Operations Admin

Atlas Technica LLC • Lima Metropolitana

A distancia
PEN 134.000 - 202.000
Competitive salary
Comprehensive benefits
Career development opportunities
Senior Information Technology Engineer
Senior Information Technology Engineer

HKA • Comas

Híbrido
PEN 371.000 - 472.000
Healthcare benefits
401(k) with company match
Paid time off (PTO)
+2
Mid Market Account Executive
Mid Market Account Executive

Cyberhaven • Los Angeles

Presencial
PEN 302.000 - 504.000
Cybersecurity Business Advisor
Cybersecurity Business Advisor

Empresa Confidencial • Lima Metropolitana

Presencial
PEN 90.000 - 150.000
Analista de Ciberseguridad
Analista de Ciberseguridad

RANSA COMERCIAL S.A.C • Miraflores

Presencial
PEN 60.000 - 90.000