Application Security Program Manager I-II

Cybersecurity Jobs

Honolulu (HI)

On-site

USD 87,000 - 138,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

The Application Security Program Manager provides leadership and governance for the bank’s application security, identity management, fraud-related technology risk, and emerging technology risk programs within the Information Security Program.

This role establishes standards, risk assessment methodology, reporting, and a multi-year roadmap, coordinating with Technology and business leaders to align security expectations with regulatory requirements and business objectives.

Qualifications

  • Bachelor’s degree from a four-year university in information security, MIS, or computer science.
  • 7+ years of information security experience focusing on application security and regulatory privacy laws.
  • 3+ years leading enterprise-wide cross-functional teams and programs.

Responsibilities

  • Develop and maintain information security risk management processes aligned with regulatory requirements.
  • Plan, coordinate, implement, and manage security measures addressing risks to systems and data.
  • Lead a risk-based application security review program with appropriate controls.
  • Train staff on application security, identity management, and risk assessment methodologies.
  • Oversee vendor security assessments and manage remediation with accountable stakeholders.
  • Provide leadership reporting and risk insights to information security leadership and stakeholders.

Skills

Information security
Application security
Regulatory compliance
Leadership
Risk management

Education

Bachelor’s degree in Information Security

Job description

The Application Security Program Manager provides leadership and governance for the bank’s application security, identity management, fraud-related technology risk, and emerging technology risk programs within the Information Security Program. This role establishes standards, risk assessment methodology, reporting, and a multi-year roadmap, coordinating with Technology and business leaders to align security expectations with regulatory requirements and business objectives.

Location & Employment Details
  • Location: Honolulu, HI (onsite)
  • Compensation: USD 86,503 - 138,365 per year
Core Responsibilities
  • Develop and maintain information security risk management processes that are clear, workable, up to date, and reflect regulatory and bank-specific requirements and issues.
  • Assist with communicating risk management processes across the business, including training sessions where appropriate.
  • Plan, coordinate, implement, and manage security measures that address risks to systems and data, including preventing unauthorized modification, destruction, or disclosure of information, including by outsider service providers.
  • Analyze and evaluate new products and systems for security weaknesses, and provide measures to prevent exposure and loss.
  • Train staff on policies and standards related to application security and identity management best practices, including methodologies for conducting related risk assessments.
  • Review and delegate work tied to governance and oversight of controls for application security and identity management.
  • Lead and motivate a team to support engagement, performance, and productivity, including setting goals and providing guidance.
  • Conduct regular performance reviews, provide constructive feedback, identify skills gaps, and support professional growth through training, mentorship, or cross-functional collaboration.
  • Lead a risk-based application security review program to ensure appropriate security controls are designed, implemented, and operating effectively.
  • Validate application and related reference architectures for security best practices and recommend changes to enhance security and reduce risk where applicable.
  • Oversee application risk assessments and control reviews, identify weaknesses, and drive remediation plans with accountable stakeholders.
  • Lead security risk evaluations for emerging technologies, new business initiatives, and material changes to the application and identity ecosystem.
  • Conduct or facilitate threat modeling for services and applications, linked to associated risk and data.
  • Provide strategic oversight for application security tooling, processes, and service models to support scalable coverage and risk visibility.
  • Conduct incident response exercises and incorporate lessons learned into existing security architectures and practices.
  • Conduct forensic analysis of security-related incidents in a manner consistent with best practices and counsel.
  • Perform risk analyses for the bank’s security needs and prepare recommendations based on risk and exposure versus cost.
  • Prepare and deliver research findings in written and/or oral form, including presenting objectives, alternatives, risk analyses, and cost/benefit analyses.
  • Assist with planning and directing information security activities to support compliance with internal and external audits and federal and State regulations, including FDIC, relevant sections of the Gramm-Leach-Bliley Act (GLBA), Sarbanes-Oxley Act Section 404 provisions, and other duties as assigned.
  • Maintain an outward-facing, forward-looking view to ensure the Information Security Program remains current and relevant.
  • Design, implement, and manage Information Security data identification, aggregation, analytics, and validation to meet department goals.
  • Collaborate on application security documentation (policies, standards, procedures, templates, and related materials) used for security governance in projects and operations.
  • Initiate and execute process improvements and policy/procedure updates.
  • Track developments and changes in digital banking and threat environments to ensure they are addressed in security strategy plans.
  • Document data flows of sensitive information within the organization (for example, PII or ePHI) and recommend controls to secure this data (such as encryption and tokenization).
  • Serve as Subject Matter Expert for application security, identity management, and API security, including security planning consulting in application and related infrastructure projects.
  • Partner with cross-functional teams to ensure security requirements are incorporated into processes and operations.
  • Liaison with vendor management to conduct security assessments of existing and prospective vendors, particularly those involving intellectual property and regulated or protected data (including SaaS, cloud/IaaS, managed service providers, and other relevant categories).
  • Own the bank’s application security, identity governance, and fraud-related technology risk programs, accountable for strategy, governance, maturity, and measurable risk outcomes.
  • Establish program objectives, control standards, operating procedures, risk tolerances, and performance metrics aligned to regulatory expectations.
  • Develop and maintain a multi-year roadmap for people, process, and technology capabilities, including investment priorities, control enhancements, and maturity targets.
  • Provide leadership reporting and risk insights to Information Security leadership, executive stakeholders, governance committees, auditors, regulators, and other appropriate parties.
Required Qualifications
  • Education: Bachelor’s Degree from a 4-year university required, preferably in Information Security, MIS, Computer Science
  • Experience (Program Manager I): 7+ years of experience with information security, application security, and regulations and privacy laws related to release of information, plus security and access control technologies (or equivalent experience)
  • Program Manager I Management Experience: 3+ years managing or serving as a team lead with enterprise-wide cross-functional leadership responsibilities
  • Experience (Program Manager II): 10+ years of experience with information security, application security, and regulations and privacy laws related to release of information, plus security and access control technologies (or equivalent experience)
  • Program Manager II Management Experience: 5+ years managing or serving as a team lead with enterprise-wide cross-functional leadership responsibilities
Preferred Certifications
  • CISSP, CISA, TOGAF, SANS GCSA, or equivalent certification (indicate upon hire)
Physical Requirements & Working Conditions
  • Ability to perform light physical work and to move or lift items, including boxes, files, and papers, up to 20 pounds unless otherwise indicated.
  • Ability to operate and use standard office equipment, including phone, copier, personal computer, and other work-related mechanical or electronic devices and applications.
  • Ability to clearly communicate verbally and in writing with internal and external customers; able to hear sufficiently for daily discussions and interactions.
  • Ability to read and understand bank-related documents.
  • Ability to work in a conventional office setting, involving sitting at a desk or workstation for extended periods, and adapt to different work environments as needed.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Program Manager I-II (On-Site)
Application Security Program Manager I-II (On-Site)

Central Pacific Bank • Honolulu (HI)

On-site
USD 87,000 - 138,000
Application Security Program Manager I-II (On-Site)
Application Security Program Manager I-II (On-Site)

CPB Group Pty • Honolulu (HI), Northern (KY)

Hybrid
USD 87,000 - 138,000
Application Security Program Manager I-II (On-Site)
Application Security Program Manager I-II (On-Site)

Central Pacific Bank (HI) • Honolulu (HI)

On-site
USD 87,000 - 138,000
Application Security Program Lead (I–II)
Application Security Program Lead (I–II)

Central Pacific Bank (HI) • Honolulu (HI)

On-site
USD 87,000 - 138,000
Product Manager – Tech Delivery - Application Security Adjudication & Risk Management
Product Manager – Tech Delivery - Application Security Adjudication & Risk Management

Bank of America • Washington

On-site
USD 170,000 - 210,000
Senior Application Security & Risk Program Lead
Senior Application Security & Risk Program Lead

CPB Group Pty • Honolulu (HI), Northern (KY)

Hybrid
USD 87,000 - 138,000
Product Manager – Application Security & Risk Management - Tech Delivery
Product Manager – Application Security & Risk Management - Tech Delivery

Bank of America • Washington

On-site
USD 140,000 - 190,000
Senior Application Security Program Lead
Senior Application Security Program Lead

Central Pacific Bank • Honolulu (HI)

On-site
USD 87,000 - 138,000
Product Manager - Application Security & Risk Management - Tech Delivery
Product Manager - Application Security & Risk Management - Tech Delivery

Bank of America • Denver (CO)

On-site
USD 135,000 - 217,000
Product Manager - Application Security & Risk Management - Tech Delivery
Product Manager - Application Security & Risk Management - Tech Delivery

Bank of America • Chicago (IL)

On-site
USD 135,000 - 217,000
Industry-leading benefits
Discretionary incentive eligibility