Director, App Security

World Wrestling Entertainment, Inc.

New York (NY)

Hybrid

USD 143,000 - 190,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

TKO Group Holdings, Inc. is seeking a hands-on Director, Application Security Engineering to strengthen cybersecurity across web, mobile, data, and AI-enabled workflows.

This hybrid role embeds security into delivery practices, working with software engineering, DevOps, and security teams to mature SSDLC, expand guardrails, and enable secure development. 3 days in-office, preference for NYC, Stamford, Orlando, Austin, or Las Vegas.

Qualifications

  • Hands-on application security with experience in DevSecOps.
  • Ability to implement SSDLC and shift-left practices.
  • Experience reviewing code-level vulnerabilities and guiding remediation.
  • Familiarity with CI/CD pipelines and secure tooling.

Responsibilities

  • Own and evolve application security practices across the SSDLC with developer alignment.
  • Operate and improve SAST, SCA, secret scanning, and repository protections.
  • Develop secure development enablement for citizen developers and AI-assisted tools.
  • Review vulnerabilities, validate findings, and drive remediation plans.
  • Conduct threat modelling and security design reviews for new systems and APIs.
  • Advise teams on secure coding, authN/authZ, secrets handling, and data protection.
  • Improve guardrails for pipelines, containers, and third-party components.
  • Mature risk-based vulnerability management and reporting.
  • Support secure adoption of AI-assisted development and agentic systems.
  • Create standards, playbooks, and documentation to improve consistency.

Skills

Application security
DevSecOps
SAST/SCA tooling
Threat modelling
SSDLC
CI/CD security
Cloud security
AI security
Security design reviews

Tools

SonarQube
Dependabot
GitHub Advanced Security

Job description

Who We Are

TKO Group Holdings, Inc. (NYSE: TKO) is a premium sports and entertainment company. TKO owns iconic properties including UFC, the world’s premier mixed martial arts organization; WWE, the global leader in sports entertainment; and PBR, the world’s premier bull riding organization. Together, these properties reach 1 billion households across 210 countries and territories and organize more than 500 live events year-round, attracting more than three million fans. TKO also services and partners with major sports rights holders through IMG, an industry-leading global sports marketing agency; and On Location, a global leader in premium experiential hospitality.

Overview

We are looking for a hands-on Director, Application Security Engineering to strengthen our cybersecurity posture and partner directly with teams building software across web, mobile, data, and AI-enabled workflows. This role will embed security into delivery practices, improve how we prevent and remediate risk, and communicate clearly with both technical and non-technical stakeholders. This Director will work across software engineering, platform, DevOps, architecture, QA, infrastructure, compliance, and security teams to mature secure SDLC (i.e., SSDLC) practices, expand developer-friendly guardrails, and improve application and agent security. They should be comfortable moving between code review, tooling configuration, threat modelling, vulnerability management, automation, security enablement, and emerging AI security considerations. This is a hybrid role (3 days/week in-office). Preference given to candidates near a TKO office, including NYC, Stamford, Orlando, Austin, or Las Vegas.

The Role and What You’ll Do
  • Own and evolve application security practices across the SSDLC, emphasizing scalable, developer-aligned, shift-left controls
  • Operate and improve SAST, SCA, secret scanning, code scanning, repository protections, and related controls across repositories and CI/CD pipelines
  • Develop secure development enablement for citizen developers, vibe coding, and AI-assisted development, including practical guidance for tooling, code assurance, identity, observability, and enterprise standards
  • Review application and code-level vulnerabilities, validate findings, reduce noise, and drive risk-based remediation plans
  • Conduct threat modelling and security design reviews for new systems, major changes, integrations, APIs, and high-risk workflows
  • Advise teams on secure coding, authentication and authorization, session management, secrets handling, logging, encryption, dependency hygiene, and data protection
  • Improve security guardrails for build pipelines, containers, APIs, third-party components, and deployment practices across modern and legacy environments
  • Mature risk-based vulnerability management across intake, validation, prioritization, remediation guidance, exception handling, and reporting
  • Support secure adoption of AI-assisted development and agentic systems by assessing trust boundaries, data exposure paths, prompt and tool-invocation risks, and misuse scenarios
  • Develop pragmatic standards, playbooks, reference architectures, documentation, and office-hour support that improve consistency without slowing teams down unnecessarily
  • Track recurring weaknesses, recommend structural fixes, and help leadership understand where engineering investment will reduce risk most effectively
  • Use AI productively and responsibly to accelerate analysis, triage, documentation, coding support, and security review while maintaining strong human judgment
Required Skills and Experience
  • 5+ years of hands-on experience in application security, product security, DevSecOps, and security engineering or a closely related software security role
  • Proven experience working directly with engineering teams in fast-moving delivery environments
  • Hands-on experience configuring, tuning, and operationalizing SAST, SCA, and related tooling such as SonarQube, Dependabot, GitHub, GitHub Advanced Security, or comparable platforms
  • Ability to interpret and reason about code, identify meaningful risk, and provide specific, implementable remediation guidance to engineers
  • Practical experience with SSDLC and shift-left practices, including automated code review support, threat modelling, security design review, and vulnerability management
  • Strong understanding of application and API security, including common software weaknesses, authN/authZ, secrets handling, dependency risk, injection, deserialization, and data protection
  • Experience integrating reliable, scalable, and minimally disruptive security controls into CI/CD pipelines and developer workflows
  • Hands-on familiarity with cloud and modern software delivery patterns, including containers, IaC, and Git-based workflows
  • Strong judgment in vulnerability triage, balancing severity, exploitability, business impact, and engineering realities
  • Ability to write clear guidance, standards, and technical documentation for technical and non-technical audiences
  • Bias toward automation, simplification, and scalable solutions over manual heroics
  • Broad DevSecOps mindset across code, pipelines, dependencies, platforms, deployment, and operations
  • Experience using AI tools responsibly to improve engineering and security outcomes
Preferred Skills and Experience
  • Experience securing AI agents, LLM-enabled applications, copilots, or agentic workflows in production or near-production environments
  • Experience with DAST, API security testing, penetration testing coordination, red-team support, or adversarial testing of application and AI systems
  • Experience with policy-as-code, IaC scanning, container/image security, software supply-chain security, SBOMs, provenance, attestation, and secrets management
  • Familiarity with cloud security across AWS and/or GCP and the application-layer implications of cloud-native architectures
  • Experience in regulated, audit-sensitive, or event-critical environments where evidence, controls, and operational rigor matter
  • Experience building metrics, dashboards, or reporting that show AppSec posture and remediation progress
  • Experience mentoring engineers and influencing secure engineering culture without direct people management responsibility
What Good Looks Like in This Role
  • Engineering teams get faster, clearer, and more actionable security guidance as well as assistance with implementation and mechanics for a 'teach a person to fish' approach
  • Security tooling produces more trustworthy signals and leads to better adoption, not just more alerts
  • Teams catch and remediate issues earlier in design and development rather than late in release cycles
  • Application and agent-security risks are surfaced in practical terms with concrete mitigation paths
  • Standards, playbooks, and tooling make secure delivery easier and more consistent
  • Security becomes more embedded in day-to-day engineering execution and technical operations, and less dependent on last-minute security scrambles and efforts,
Salary and Benefits

Hiring Rate Minimum: $142,500 annually(minimum will not fall below the applicable State/local minimum salary thresholds)

Hiring Rate Maximum: $190,000 annually

The company strives to provide locally competitive rewards packages, which include base rate along with, as applicable, short- and long-term incentives, growth and developmental opportunities, and robust benefits, such as health care, retirement, vacation and other paid time off, and additional offerings.

Equal Opportunity

TKO is an Equal Opportunity Employer and complies with all applicable federal, state, and local laws regarding non-discrimination in employment. TKO makes employment decisions based on merit and qualifications, without considering an employee’s or applicant’s race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, marital status, veteran status, or any other basis prohibited under federal, state or local laws governing non-discrimination in employment in every location in which the Company has facilities.

TKO also provides reasonable accommodations for qualified individuals with disabilities in accordance with the Americans with Disabilities Act (ADA) and applicable state or local laws.

For information about Privacy and Information Security for TKO employment candidates, please review our Privacy Policy. For information regarding Terms of Use for this and other TKO websites, please review our Terms of Use.

UFC is the world’s premier mixed martial arts organization (MMA), with more than 700 million fans and approximately 300 million social media followers. The organization produces more than 40 live events annually in some of the most prestigious arenas around the world while broadcasting to over 950 million households across more than 170 countries. UFC’s athlete roster features the world’s best MMA athletes representing more than 80 countries. The organization’s digital offerings include UFC FIGHT PASS, one of the world’s leading streaming services for combat sports. UFC is part of TKO Group Holdings (NYSE: TKO) and is headquartered in Las Vegas, Nevada. For more information, visit UFC.com and follow UFC at Facebook.com/UFC and @UFC on X, Snapchat, Instagram, and TikTok: @UFC.

TKO Group Holdings, Inc. (NYSE: TKO) is a premium sports and entertainment company. TKO owns iconic properties including UFC, the world’s premier mixed martial arts organization; WWE, the global leader in sports entertainment; and PBR, the world’s premier bull riding organization. Together, these properties reach 1 billion households across 210 countries and territories and organize more than 500 live events year-round, attracting more than three million fans. TKO also services and partners with major sports rights holders through IMG, an industry-leading global sports marketing agency; and On Location, a global leader in premium experiential hospitality.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Operations Shift Lead
Operations Shift Lead

World Wrestling Entertainment, Inc. • Connecticut

Hybrid
USD 94,000 - 125,000
Health care
Retirement plan
Paid time off
VP, Recruiting
VP, Recruiting

World Wrestling Entertainment, Inc. • Stamford (CT)

Hybrid
USD 220,000 - 340,000
Facilities Coordinator
Facilities Coordinator

World Wrestling Entertainment, Inc. • Stamford (CT)

On-site
USD 34,000 - 55,000
Senior Coordinator, LA28 Olympic & Paralympic Hospitality
Senior Coordinator, LA28 Olympic & Paralympic Hospitality

World Wrestling Entertainment, Inc. • Los Angeles (CA)

On-site
USD 56,000 - 75,000
Medical, dental, vision, life, and DIS
Paid time off
401k plan
Motion Graphic Designer
Motion Graphic Designer

World Wrestling Entertainment, Inc. • Las Vegas (NV)

On-site
USD 60,000 - 85,000
Director, Technical Accounting
Director, Technical Accounting

World Wrestling Entertainment, Inc. • New York (NY)

On-site
USD 143,000 - 190,000
Health care
Retirement plan
Paid time off
Senior Manager, Sports Medicine
Senior Manager, Sports Medicine

World Wrestling Entertainment, Inc. • Las Vegas (NV)

On-site
USD 140,000 - 200,000
Manager, IT Governance, Risk and Compliance
Manager, IT Governance, Risk and Compliance

TKO • New York (NY)

On-site
USD 105,000 - 140,000
Manager, IT Governance, Risk and Compliance
Manager, IT Governance, Risk and Compliance

TKO • Town of Florida (NY)

On-site
USD 105,000 - 140,000
Health care
Retirement plan
Paid time off
Manager, IT Governance, Risk and Compliance
Manager, IT Governance, Risk and Compliance

TKO • Connecticut

On-site
USD 105,000 - 140,000