Application Security Manager

Bed Bath & Beyond

Center (IN)

On-site

USD 150,000 - 185,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401k (6% match)
Flexible schedules
Tuition reimbursement & mentorship
Employee Resource Groups

Job summary

Bed Bath & Beyond is seeking an Application Security Manager to lead secure SDLC enablement across web, mobile, and cloud services. You will partner with CI/CD, DevOps, and engineering teams to embed security controls, perform threat modeling, and conduct architecture and code reviews.

Manage vulnerability intake, triage, remediation tracking, and external findings. The role requires hands-on AppSec experience, strong leadership, and a track record of improving security postures through metrics,

Qualifications

  • Hands-on experience with application security assessments, secure code reviews, threat modeling, and risk-based remediation.
  • Experience leading or coordinating application security, secure SDLC, vulnerability governance and bug bounty processes.
  • Experience with SAST, DAST, SCA, secrets detection, container scanning, and cloud security posture.
  • Ability to create clear metrics, dashboards, and leadership risk reporting.

Responsibilities

  • Lead the Application Security team across secure SDLC enablement, vulnerability management, secure code review, security testing, and developer partnership.
  • Oversee application security reviews including architecture/design review, threat modeling, code review, API security review, and targeted testing.
  • Own vulnerability governance: intake, triage, remediation tracking, validation, and leadership reporting.
  • Manage vulnerability disclosure, bug bounty, and external findings processes.
  • Partner with CI/CD, DevOps, SRE, Platform Engineering to integrate security controls into delivery pipelines.
  • Translate findings into remediation plans and maintain security requirements aligned to standards.

Skills

Application security assessments
Threat modeling
Secure code reviews
SAST/DAST/SCA
Cloud security
CI/CD security
WAF/RASP
Security leadership

Education

Bachelor's degree in Engineering/Information Systems/Computer Science or related field

Tools

SAST tooling
DAST tooling
SCA tooling
Secrets detection tooling
Container scanning tooling

Job description

We Go Beyond

At Bed Bath & Beyond, we believe that everyone should “Be You!”. Bed Bath & Beyond is a community that upholds a culture of understanding, acceptance, and respect. We believe a person’s individuality, traits, beliefs, and characteristics should be valued and embraced. Living by this ethos is essential to the success of our business. Our goal is to foster a more inclusive environment where every employee visibly demonstrates inclusive behaviors and respect for individuals.

  • Lead the Application Security team across secure SDLC enablement, vulnerability management, secure code review, security testing, and developer partnership.
  • Oversee application security reviews, including architecture and design review, threat modeling, code review, API security review, and targeted testing.
  • Own application vulnerability governance, including intake, triage, prioritization, SLA management, remediation tracking, validation, exceptions, and leadership reporting.
  • Manage vulnerability disclosure, bug bounty, and external findings processes.
  • Partner with CI/CD, DevOps, SRE, Platform Engineering, and development teams to integrate security controls into delivery pipelines.
  • Translate security findings into actionable remediation plans and maintain application security requirements and control expectations aligned to internal standards and industry practices.
  • Drive secure design and remediation for commerce platforms, APIs, web applications, mobile-supporting services, cloud workloads.
  • Identify and reduce software supply chain risk, including vulnerable or malicious packages, dependency management gaps, SBOM visibility, repository controls, and dependency confusion risks.
  • Support application-related security incidents and postmortems.
  • Partner with Security Operations on WAF, bot mitigation, cloud security, logging, alerting, and compensating controls when remediation requires staged mitigation or fast-follow delivery.
  • Create metrics and dashboards showing application security posture.
  • Deliver developer enablement through application security training, security champion content, secure coding guidance, and just-in-time coaching.
  • Evaluate application security tooling, vendor capabilities, proof-of-concepts, renewals, and integrations that improve outcomes without unnecessary operational friction.
  • Contribute to security reviews of AI-enabled development workflows, AI-native application components, model integrations, and emerging secure AI-SDLC practices.
  • Perform other job-related duties as assigned.
We Go Beyond

At Bed Bath & Beyond, we believe that everyone should “Be You!”. Bed Bath & Beyond is a community that upholds a culture of understanding, acceptance, and respect. We believe a person’s individuality, traits, beliefs, and characteristics should be valued and embraced. Living by this ethos is essential to the success of our business. Our goal is to foster a more inclusive environment where every employee visibly demonstrates inclusive behaviors and respect for individuals.

  • Lead the Application Security team across secure SDLC enablement, vulnerability management, secure code review, security testing, and developer partnership.
  • Oversee application security reviews, including architecture and design review, threat modeling, code review, API security review, and targeted testing.
  • Own application vulnerability governance, including intake, triage, prioritization, SLA management, remediation tracking, validation, exceptions, and leadership reporting.
  • Manage vulnerability disclosure, bug bounty, and external findings processes.
  • Partner with CI/CD, DevOps, SRE, Platform Engineering, and development teams to integrate security controls into delivery pipelines.
  • Translate security findings into actionable remediation plans and maintain application security requirements and control expectations aligned to internal standards and industry practices.
  • Drive secure design and remediation for commerce platforms, APIs, web applications, mobile-supporting services, cloud workloads.
  • Identify and reduce software supply chain risk, including vulnerable or malicious packages, dependency management gaps, SBOM visibility, repository controls, and dependency confusion risks.
  • Support application-related security incidents and postmortems.
  • Partner with Security Operations on WAF, bot mitigation, cloud security, logging, alerting, and compensating controls when remediation requires staged mitigation or fast-follow delivery.
  • Create metrics and dashboards showing application security posture.
  • Deliver developer enablement through application security training, security champion content, secure coding guidance, and just-in-time coaching.
  • Evaluate application security tooling, vendor capabilities, proof-of-concepts, renewals, and integrations that improve outcomes without unnecessary operational friction.
  • Contribute to security reviews of AI-enabled development workflows, AI-native application components, model integrations, and emerging secure AI-SDLC practices.
  • Perform other job-related duties as assigned.
Essential Job Duties
  • Lead the Application Security team across secure SDLC enablement, vulnerability management, secure code review, security testing, and developer partnership.
  • Oversee application security reviews, including architecture and design review, threat modeling, code review, API security review, and targeted testing.
  • Own application vulnerability governance, including intake, triage, prioritization, SLA management, remediation tracking, validation, exceptions, and leadership reporting.
  • Manage vulnerability disclosure, bug bounty, and external findings processes.
  • Partner with CI/CD, DevOps, SRE, Platform Engineering, and development teams to integrate security controls into delivery pipelines.
  • Translate security findings into actionable remediation plans and maintain application security requirements and control expectations aligned to internal standards and industry practices.
  • Drive secure design and remediation for commerce platforms, APIs, web applications, mobile-supporting services, cloud workloads.
  • Identify and reduce software supply chain risk, including vulnerable or malicious packages, dependency management gaps, SBOM visibility, repository controls, and dependency confusion risks.
  • Support application-related security incidents and postmortems.
  • Partner with Security Operations on WAF, bot mitigation, cloud security, logging, alerting, and compensating controls when remediation requires staged mitigation or fast-follow delivery.
  • Create metrics and dashboards showing application security posture.
  • Deliver developer enablement through application security training, security champion content, secure coding guidance, and just-in-time coaching.
  • Evaluate application security tooling, vendor capabilities, proof-of-concepts, renewals, and integrations that improve outcomes without unnecessary operational friction.
  • Contribute to security reviews of AI-enabled development workflows, AI-native application components, model integrations, and emerging secure AI-SDLC practices.
  • Perform other job-related duties as assigned.
Minimum Qualifications
  • Hands‑on experience with application security assessments, secure code reviews, threat modeling, API testing, security design reviews, and risk‑based remediation.
  • Experience leading or materially coordinating application security, secure SDLC, vulnerability governance, DevSecOps, vulnerability disclosure, bug bounty, external testing, or coordinated vulnerability intake processes.
  • Experience with SAST, DAST, SCA, secrets detection, container scanning, cloud security posture, WAF or runtime protection, and vulnerability management tooling.
  • Working knowledge of application architectures, APIs, authentication and authorization patterns, CI/CD pipelines, dependency management, Git‑based workflows, and cloud‑hosted delivery models.
  • Ability to partner with engineers, architects, platform teams, product leaders, and security teams to drive practical remediation, control adoption, and business‑appropriate security decisions.
  • Ability to create clear metrics, dashboards, technical documentation, remediation guidance, project plans, executive summaries, and leadership‑ready risk reporting.
  • Proficiency in at least one common development or scripting language such as Java, Python, JavaScript, TypeScript, or Node.js.
Required Skills And Experience
  • Experience securing retail, ecommerce, payments, loyalty, customer identity, fraud prevention, or high‑traffic customer‑facing platforms built on modern web, cloud, container, CDN, or edge architectures.
  • Experience with application security and delivery platforms.
  • Experience improving AppSec outcomes through automation, prototypes, AI security practices, secure AI‑assisted development, model/component inventory, or developer remediation workflows.
Impact
  • The Application Security Manager is a key role in reducing application risk across Bed Bath & Beyond’s technology environment. This position drives the execution of secure SDLC practices, improves remediation discipline, matures developer‑facing security capabilities, and ensures application security risks are visible, prioritized, and addressed through defensible governance. The manager grows the capability of the Application Security team while serving as a trusted advisor to engineering and product leaders.
Skills
  • Application Security Scanning: SAST, DAST, SCA
  • Containerization and CI/CD Toolsets
  • Public Cloud Security: AWS, GCP, Azure, Oracle Cloud
  • Web Application Security: Web Application Firewalls (WAF), Runtime Application Self‑Protection (RASP), Bot Identification and Prevention
  • Languages: Java, python, node.js and/or other popular languages
Education/Licensing/Certifications
  • Graduation from an accredited institution with a Bachelor’s degree in Engineering, Information Systems, Computer Science or a related field or any combination of education and/or experience.
  • OSCP
  • SANS/GIAC (GWAPT, GSEC, GCIH, GCIA, etc.)
  • Public Cloud DevOps certifications
  • CEH
  • Relevant coding certifications
Base Pay Range

$150,000 - $185,000 per year DOE

Who We Are

We’re a passionate group of collaborative problem solvers and creative innovators, working on cutting‑edge technology. From building award‑winning retail applications (with amazing AR functionality) to creating leading blockchain and machine learning technologies, each of us embodies a unique value and contributes a diverse perspective to the team.

What We Offer
  • 401k (6% match)
  • Flexible Schedules
  • Tuition Reimbursement, Leadership Development Program, & Mentorship Program
  • Employee Resource Groups (LatinX, Black Employee Network, LGBTQIA+, Women’s Network, Women In Tech)
  • And More
  • Benefits vary based on position, tenure, location, and employee election
Physical Requirements

This position requires you to sit, stand and perform general office functions. You may also be required to lift up to 25 pounds occasionally. Bending, stooping and reaching are also frequently required.

Equal Employment Opportunity

It is our policy to provide equal employment opportunity for all applicants and associates. This policy includes our commitment to ensure that all employment decisions are made without regard to race, color, religion, gender, national origin, disability, pregnancy, veteran status (including Vietnam era veterans), age, sexual orientation, gender identity, or any other non‑job‑related characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Manager
Application Security Manager

Bed Bath & Beyond, Inc. • Center (IN)

On-site
USD 150,000 - 185,000
401k (6% match)
Flexible Schedules
Tuition Reimbursement, Leadership Dev.
+3
Application Security Manager
Application Security Manager

Overstock.Com • United States

On-site
USD 150,000 - 185,000
401k (6% match)
Flexible schedules
Tuition reimbursement
+2
Assistant Merchant
Assistant Merchant

Bed Bath & Beyond, Inc. • Franklin Center (PA)

On-site
USD 60,000 - 90,000
401k match
Flexible schedules
Tuition reimbursement
+3
Assistant Merchant
Assistant Merchant

Bed Bath & Beyond • Dallas Center (IA)

On-site
USD 65,000 - 90,000
401k match
Flexible schedules
Tuition reimbursement
+3
Assistant Merchant
Assistant Merchant

Bed Bath & Beyond, Inc. • Dallas Center (IA)

On-site
USD 52,000 - 72,000
401k 6% match
Flexible schedules
Tuition reimbursement
+3
Assistant Merchant
Assistant Merchant

Bed Bath & Beyond • Franklin Center (PA)

On-site
USD 55,000 - 85,000
401k (6% match)
Flexible schedules
Tuition reimbursement
+3
Director, FP&A
Director, FP&A

Bed Bath & Beyond, Inc. • Town of Texas (WI)

On-site
USD 85,000 - 125,000
401k match
Flexible schedules
Tuition reimbursement
+3
Machine Learning Engineer II
Machine Learning Engineer II

Bed Bath & Beyond, Inc. • Georgia

Hybrid
USD 120,000 - 160,000
401k (6% match)
Flexible Schedules
Onsite Health Clinic
+4
Director, FP&A
Director, FP&A

Bed Bath & Beyond • Dallas (TX)

On-site
USD 90,000 - 130,000
401k (6% match)
Flexible Schedules
Tuition Reimbursement
+3
Resource Center Specialist
Resource Center Specialist

Bed Bath & Beyond, Inc. • Dallas (TX)

On-site
USD 70,000 - 100,000
401k
Flexible schedules
Tuition reimbursement
+3