Application Security Manager

Alter Domus

New York (NY)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible arrangements
Generous holidays
24/7 Employee Assistance Program

Job summary

Alter Domus is seeking an Application Security Manager to lead and enhance their Application Security program. This role will embed security within the development lifecycle, working closely with both the Engineering and Security teams.

You will be responsible for secure design reviews, managing security automation, and guiding development teams on security practices. Ideal candidates will possess over four years of application security experience and strong knowledge in CI/CD workflows.

Alter Domus offers comprehensive benefits including learning opportunities, flexible arrangements, and support for professional accreditations.

Qualifications

  • 4+ years of hands‑on application security experience.
  • Strong working knowledge of modern CI/CD workflows, including Azure Pipelines.
  • Familiarity with the OWASP Top 10 for web applications and APIs.

Responsibilities

  • Lead secure design reviews and threat modeling.
  • Define and enforce SLA governance for security findings.
  • Serve as a trusted advisor to development teams.

Skills

Application security experience
Secure code reviews
CI/CD workflows
Cloud platforms (AWS, Azure)
Communication of security concepts

Education

Bachelor’s degree in Computer Science or related field

Tools

Snyk
Burp Suite
Docker
Kubernetes

Job description

Application Security Manager

We are looking for an Application Security Manager to lead and scale our Application Security program. Reporting to the Global Head of Security, you will be the connective tissue between Engineering and Security — embedding security into how we build, not bolting it on after the fact.

Your responsibilities
  • Lead secure design reviews and threat modeling to surface risks early in the development lifecycle.
  • Deploy and operationalize SAST, DAST, SCA, and secrets scanning across repositories and pipelines.
  • Partner with the Platform DevOps team to build and maintain security automation that embeds inline checks into CI/CD pipelines.
  • Help architect secure-by-default frameworks, workflows, and reusable patterns for engineering teams.
  • Conduct application security code reviews and provide clear, developer-friendly remediation guidance aligned with secure coding practices.
Vulnerability & Risk Management
  • Define and enforce SLA governance for security findings — from identification and prioritization through to remediation tracking.
  • Maintain accurate and up-to-date application asset inventory.
  • Create and maintain Developer Security Standards with deep familiarity across Azure DevOps, GitHub Enterprise, and GitHub Advanced Security.
  • Evaluate and implement security tooling and automation to continuously improve application security posture and operational efficiency.
  • Lead the Security Champions Program to build a security-first culture across engineering and IT operations.
  • Serve as a trusted advisor to development and cross-functional teams, translating security risks into concrete, prioritized actions.
  • Deliver training on secure coding practices that empowers developers to proactively own security outcomes.
Your profile
  • 4+ years of hands‑on application security experience, including cloud‑based and containerized environments.
  • Proven experience with secure code reviews and ability to interpret SAST, SCA, and DAST findings and translate them into developer‑friendly guidance.
  • Strong working knowledge of modern CI/CD workflows, including Azure Pipelines and GitHub Actions.
  • Deep familiarity with the OWASP Top 10 for web applications and APIs, and how to apply them in practice.
  • Hands‑on experience with security tooling such as Snyk, Cycode, Apiiro, Burp Suite, or equivalents.
  • Familiarity with cloud platforms (AWS, Azure) and containerization technologies (Docker, Kubernetes).
  • Ability to communicate complex security concepts clearly and drive buy‑in across engineering levels with minimal supervision.
  • Strong collaboration skills and a developer‑first mindset — you make security easier, not harder.
Nice to Have
  • Proficiency in Python, Java, or C#.
  • Exposure to AI‑SBOM and familiarity with AI‑SDLC security considerations.
  • Experience building or scaling a Security Champions program.
  • Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent professional experience).
What we offer

We are committed to supporting your development, advancing your career, and providing benefits that matter to you.

Our industry‑leading Alter Domus Academy offers six learning zones for every stage of your career, with resources tailored to your ambitions and resources from LinkedIn Learning.

Our global benefits also include:
  • Support for professional accreditations
  • Flexible arrangements, generous holidays, plus an additional day off for your birthday
  • Continuous mentoring along your career progression
  • Active sports, events and social committees across our offices
  • 24/7 support available from our Employee Assistance Program
  • The opportunity to invest in our growth and success through our Employee Share Plan

Alter Domus is an Equal Opportunity Employer: Equity Statement
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Manager
Application Security Manager

Alter Domus • Chicago (IL)

Hybrid
USD 120,000 - 150,000
Flexible arrangements
Generous holidays
Employee Share Plan
Senior Application Security Architect
Senior Application Security Architect

Payactiv • Milpitas (CA)

On-site
USD 130,000 - 160,000
Health, Dental, and Vision insurance
401(k) with company match
Unlimited Paid Time Off
+2
Application Security Architect
Application Security Architect

Updata Partners • United States

Hybrid
USD 130,000 - 160,000
Competitive base and incentive plan
Stock options
Unlimited flexible paid time off
+1
AppSec Manager: Build Secure DevOps & Risk Aware
AppSec Manager: Build Secure DevOps & Risk Aware

Alter Domus • New York (NY)

On-site
USD 120,000 - 150,000
Flexible arrangements
Generous holidays
24/7 Employee Assistance Program
Staff Application Security Engineer
Staff Application Security Engineer

Triwill Group • United States

On-site
USD 120,000 - 145,000
Fully remote work arrangement
Staff Application Security Architect
Staff Application Security Architect

Rocket Homes Real Estate LLC • Seattle (WA)

On-site
USD 149,000 - 318,000
Senior Security Manager - Vulnerability Management
Senior Security Manager - Vulnerability Management

Alter Domus • New York (NY)

On-site
USD 180,000 - 240,000
Professional accreditations support
Flexible work arrangements
Generous holidays
+3
Application Security Engineer-68257
Application Security Engineer-68257

Worky • Dallas (TX)

On-site
USD 120,000 - 180,000
Senior Application Security Engineer
Senior Application Security Engineer

Clear Capital | CubiCasa • Reno (NV)

On-site
USD 111,000 - 144,400
Medical, dental, and vision insurance
401(k) with employer match
Paid time off and holidays
+3
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000