Director, App Security

UFC GYM

New York (NY)

Hybrid

USD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

TKO Group Holdings, Inc. is seeking a hands‑on Director of Application Security Engineering to strengthen cybersecurity and embed security into software delivery across web, mobile, data, and AI workflows.

This hybrid role requires collaboration with engineering, DevOps, architecture, QA, and compliance teams to mature SSDLC practices, expand guardrails, and drive risk-based remediation across modern and legacy environments.

Qualifications

  • 5+ years of hands-on experience in application security, product security, DevSecOps, or related security engineering.
  • Experience collaborating with engineering teams in fast-moving delivery environments.
  • Hands-on experience configuring and operating SAST/SCA tooling.

Responsibilities

  • Own and evolve SSDLC practices with scalable, developer-aligned controls.
  • Operate and improve SAST, SCA, secret scanning, and code scanning in CI/CD pipelines.
  • Provide secure development guidance for tooling, identity, observability, and data protection.
  • Review vulnerabilities, validate findings, and drive risk-based remediation plans.
  • Conduct threat modeling and security design reviews for new systems and APIs.
  • Advise teams on secure coding, authN/authZ, secrets handling, and data protection.
  • Improve guardrails for build pipelines, containers, APIs, and third-party components.
  • Support secure adoption of AI-assisted development and agentic systems.

Skills

Application security
DevSecOps
SSDLC
Threat modeling
Vulnerability management
SAST/SCA tooling
Code review
CI/CD integration
Cloud security
AI security considerations

Tools

SonarQube
Dependabot
GitHub
GitHub Advanced Security

Job description

Who We Are

TKO Group Holdings, Inc. (NYSE: TKO) is a premium sports and entertainment company. TKO owns iconic properties including UFC, the world’s premier mixed martial arts organization; WWE, the global leader in sports entertainment; and PBR, the world’s premier bull riding organization. Together, these properties reach 1 billion households across 210 countries and territories and organize more than 500 live events year-round, attracting more than three million fans. TKO also services and partners with major sports rights holders through IMG, an industry-leading global sports marketing agency; and On Location, a global leader in premium experiential hospitality.

Overview

We are looking for a hands‑on Director, Application Security Engineering to strengthen our cybersecurity posture and partner directly with teams building software across web, mobile, data, and AI‑enabled workflows. This role will embed security into delivery practices, improve how we prevent and remediate risk, and communicate clearly with both technical and non‑technical stakeholders.

This Director will work across software engineering, platform, DevOps, architecture, QA, infrastructure, compliance, and security teams to mature secure SDLC (i.e., SSDLC) practices, expand developer‑friendly guardrails, and improve application and agent security. They should be comfortable moving between code review, tooling configuration, threat modeling, vulnerability management, automation, security enablement, and emerging AI security considerations. This is a hybrid role (3 days/week in-office). Preference given to candidates near a TKO office, including NYC, Stamford, Orlando, Austin, or Las Vegas.

The Role and What You’ll Do
The Director, Application Security Engineering Will
  • Own and evolve application security practices across the SSDLC, emphasizing scalable, developer‑aligned, shift‑left controls
  • Operate and improve SAST, SCA, secret scanning, code scanning, repository protections, and related controls across repositories and CI/CD pipelines
  • Develop secure development enablement for citizen developers, vibe coding, and AI‑assisted development, including practical guidance for tooling, code assurance, identity, observability, and enterprise standards
  • Review application and code‑level vulnerabilities, validate findings, reduce noise, and drive risk‑based remediation plans
  • Conduct threat modeling and security design reviews for new systems, major changes, integrations, APIs, and high‑risk workflows
  • Advise teams on secure coding, authentication and authorization, session management, secrets handling, logging, encryption, dependency hygiene, and data protection
  • Improve security guardrails for build pipelines, containers, APIs, third‑party components, and deployment practices across modern and legacy environments
  • Mature risk‑based vulnerability management across intake, validation, prioritization, remediation guidance, exception handling, and reporting
  • Support secure adoption of AI‑assisted development and agentic systems by assessing trust boundaries, data exposure paths, prompt and tool‑invocation risks, and misuse scenarios
  • Develop pragmatic standards, playbooks, reference architectures, documentation, and office‑hour support that improve consistency without slowing teams down unnecessarily
  • Track recurring weaknesses, recommend structural fixes, and help leadership understand where engineering investment will reduce risk most effectively
  • Use AI productively and responsibly to accelerate analysis, triage, documentation, coding support, and security review while maintaining strong human judgment
Required Skills And Experience
  • 5+ years of hands‑on experience in application security, product security, DevSecOps, and security engineering or a closely related software security role
  • Proven experience working directly with engineering teams in fast‑moving delivery environments
  • Hands‑on experience configuring, tuning, and operationalizing SAST, SCA, and related tooling such as SonarQube, Dependabot, GitHub, GitHub Advanced Security, or comparable platforms
  • Ability to interpret and reason about code, identify meaningful risk, and provide specific, implementable remediation guidance to engineers
  • Practical experience with SSDLC and shift‑left practices, including automated code review support, threat modeling, security design review, and vulnerability management
  • Strong understanding of application and API security, including common software weaknesses, authN/authZ, secrets handling, dependency risk, injection, deserialization, and data protection
  • Experience integrating reliable, scalable, and minimally disruptive security controls into CI/CD pipelines and developer workflows
  • Hands‑on familiarity with cloud and modern software delivery patterns, including containers, IaC, and Git‑based workflows
  • Strong judgment in vulnerability triage, balancing severity, exploitability, business impact, and engineering realities
  • Ability to write clear guidance, standards, and technical documentation for technical and non‑technical audiences
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, App Security
Director, App Security

WWE • New York (NY)

Hybrid
USD 142,000 - 190,000
Director, App Security
Director, App Security

TKO • New York (NY)

Hybrid
USD 143,000 - 190,000
Director, App Security
Director, App Security

Ultimate Fighting Championship • New York (NY)

Hybrid
USD 142,000 - 190,000
Health care
Retirement plan
Paid time off
Senior Application Security Engineer
Senior Application Security Engineer

TKO • New York (NY)

Hybrid
USD 180,000 - 240,000
Director of Application Security Engineering
Director of Application Security Engineering

TKO • New York (NY)

Hybrid
USD 180,000 - 240,000
Director, Application Security — Lead Secure SDLC
Director, Application Security — Lead Secure SDLC

TKO • New York (NY)

Hybrid
USD 143,000 - 190,000
Director of Application Security Engineering
Director of Application Security Engineering

Ultimate Fighting Championship • New York (NY)

Hybrid
USD 142,000 - 190,000
Health care
Retirement plan
Paid time off
Director, Secure SDLC & AI-Driven Development
Director, Secure SDLC & AI-Driven Development

UFC GYM • New York (NY)

Hybrid
USD 180,000 - 240,000
Director, App Security Engineering — Hybrid, AI-Enabled
Director, App Security Engineering — Hybrid, AI-Enabled

World Wrestling Entertainment, Inc. • New York (NY)

Hybrid
USD 142,000 - 190,000
Health care
Retirement plan
Paid time off
Director, Cyber Security Wanted!
Director, Cyber Security Wanted!

HealthCare Talent • Irvine (CA)

On-site
USD 130,000 - 160,000