Get more replies from employers
Send a job-specific resume in minutes.
Western Union is seeking a Director of Application Security to lead the strategy, development, and execution of the Application Security program. The role reports to the VP of Security Operations and focuses on maturing security across the SDLC while enabling rapid product delivery.
Ideal candidates will have 10+ years in Application Security and 5+ years in leadership, with a proven ability to influence engineering culture and collaborate across Engineering, Product, Architecture, DevOps, and
We are seeking an experienced and visionary Director Application Security to lead the strategy, development, and execution of our Application Security program. Reporting to the Vice President of Security Operations, this leader will be responsible for maturing and optimizing application security capabilities across the software development lifecycle, ensuring secure-by-design principles are embedded into engineering practices while enabling rapid delivery of innovative products.
This individual will partner closely with Engineering, Product Management, Architecture, DevOps, Cloud Engineering, and Security Operations to integrate security into every phase of software development.
The successful candidate will have extensive experience building or transforming Application Security programs within complex technology organizations and will possess the ability to influence engineering culture through collaboration rather than gatekeeping.
Develop and execute the enterprise Application Security strategy aligned with business and technology objectives. Build and mature a scalable Application Security program supporting modern software development practices. Define the long-term roadmap for secure software development across cloud, web, mobile, APIs, and emerging technologies. Establish secure-by-design principles and integrate them throughout the Software Development Life Cycle (SDLC).
Lead the implementation and continuous improvement of a Secure Software Development Lifecycle (SSDLC). Develop standards and security requirements for application development. Partner with engineering teams to integrate security early within CI/CD pipelines. Promote developer-friendly security practices that minimize friction while improving software security.
Partner with DevOps teams to embed automated security controls into CI/CD pipelines. Improve automation of security testing and vulnerability management. Reduce developer burden through integrated tooling and streamlined workflows. Measure security effectiveness while enabling engineering velocity.
Define CTEM scope around critical business services, crown-jewel applications, sensitive data, material APIs, and externally exposed assets. Consolidate exposure signals from application testing, attack-surface management, cloud security, vulnerability management, penetration testing, bug bounty, and threat intelligence. Establish a common exposure taxonomy and risk model that incorporates exploitability, reachability, business criticality, threat activity, and compensating controls. Maintain an evidence-backed view of application exposure rather than relying primarily on scanner severity.
Provide application security guidance for: Cloud-native applications Microservices APIs Containers Kubernetes Serverless architectures Artificial Intelligence and Machine Learning applications Third-party integrations
Build trusted relationships with engineering leadership. Champion security as an engineering quality function. Develop security champions programs across engineering organizations.
Lead, mentor, and develop a high-performing Application Security team. Establish performance metrics and operational objectives. Manage vendor relationships and application security technologies. Support hiring and organizational growth as the program matures. Mentor developers on secure coding practices and emerging threats.
Within the first 12-18 months, this leader will Complete a comprehensive assessment of the organization's Application Security maturity. Develop and execute a multi-year Application Security transformation roadmap. Fully integrate security into CI/CD pipelines across major engineering organizations. Implement meaningful risk-based application security metrics and executive dashboards. Reduce application vulnerability remediation times while improving engineering satisfaction. Standardize threat modeling, secure code review, and security testing practices. Develop measurable improvements in software security posture without negatively impacting developer productivity.
Benefits You will also have access to short-term incentives, multiple health insurance options, accident and life insurance, and access to best-in-class development platforms, to name a few. Please see the benefits below specific to your country. If applicable, additional role-specific benefits will be mentioned during your interview process or in an offer of employment.
For residents of Colorado, California, Connecticut, Delaware, Minnesota, and Pennsylvania: Please do not respond to any questions on this initial application that may seek age-identifying information such as age, date of birth, or dates of school attendance or graduation. You may also redact this information from any materials you submit during the application process. You will not be penalized for redacting or removing this information.
The base salary range is $200,000 - $215,000 USD per year, total on target compensation includes a base salary plus a variable target incentive that aligns with individual and company performance.
As part of the application process, all applicants are required to take assessments. Western Union has partnered with a 3rd party provider to administer these tests. Applicants need to provide name and email address in order to process the assessments. If you have any questions, you may reach out to careers@westernunion.com.
We are passionate about honoring our employee's identity and fostering a feeling of belonging. Our commitment is to provide an inclusive culture that celebrates the unique backgrounds and perspectives of our global teams while reflecting the communities we serve. We do not discriminate based on race, color, national origin, religion, political affiliation, sex (including pregnancy), sexual orientation, gender identity, age, disability, marital status, or veteran status. The company will provide accommodation to applicants, including those with disabilities, during the recruitment process, following applicable laws.
09-14-2026
This application window is a good‑faith estimate of the time that this posting will remain open. This posting will be promptly updated if the deadline is extended or the role is filled. At Western Union, we're more than a trusted name in global payments. We're moving beyond remittances, beyond cash, and beyond the expectations of our customers. Our talented teams enable us to transform into a digital-first company, built on the strength of our retail foundation and powered by next-generation payments. All this with the goal of helping people prosper. Our customers inspire us to push boundaries and create services that make life easier and communities stronger. Wherever you are in the world, we're committed to shaping the next generation of financial experiences. Join us as we go beyond and be part of a team that's redefining what's possible.