Director Application Security

Vibehackers

Austin, Northern (TX, KY)

Hybrid

USD 180,000 - 250,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical Insurance
Dental Insurance
Life Insurance
Parental Leave
Tuition Reimbursement
Development Platforms

Job summary

Western Union seeks a Director-level leader to mature an enterprise Application Security program, embedding secure-by-design principles across the SDLC and partnering with engineering, product, DevOps, and cloud teams to enable secure, rapid delivery of products.

You will lead development and execution of a scalable AppSec strategy, drive a multi-year transformation, and champion security as an engineering quality function across major ecosystems.

Qualifications

  • Bachelor's degree in CS, cybersecurity, engineering, or related field.
  • 10+ years progressive experience in AppSec or related cybersecurity disciplines.
  • 5+ years leading Application Security teams in enterprise organizations.
  • Experience partnering with software engineering in Agile and DevSecOps environments.
  • Strong understanding of SSDLC, OWASP Top 10, secure coding principles, threat modeling, API security, cloud-native and container security, CI/CD security, DevSecOps, software supply chain security, and app vulnerability management.
  • Knowledge of AI-assisted software development governance and secure use.
  • Possesses at least one certification (or comparable) CISSP, CSSLP, GIAC GSSP, or GIAC GCSA.

Responsibilities

  • Develop and execute enterprise AppSec strategy and multi-year transformation roadmap.
  • Build and mature a scalable AppSec program for cloud, web, mobile, APIs, containers, and emerging technologies.
  • Lead SSDLC implementation and define security standards and requirements for development.
  • Integrate security early into CI/CD pipelines and promote developer-friendly security practices.
  • Oversee application security testing and assurance: SAST, DAST, SCA, IAST, API security testing, container security, IaC security, secure code review, and coordinate penetration testing and bug bounty programs.
  • Partner with DevOps and engineering teams to automate security controls, streamline vulnerability management, and reduce developer burden.
  • Operationalize Continuous Threat & Exposure Management (CTEM) across critical applications and services; establish taxonomy and risk model.
  • Provide guidance for cloud-native architectures, microservices, APIs, containers, Kubernetes, serverless, AI/ML applications, and third-party integrations.
  • Build trusted relationships with engineering leadership and develop security champions programs.
  • Lead, mentor, and grow an Application Security team; manage vendors and technologies; set performance metrics.

Skills

AppSec Leadership
SSDLC
Threat Modeling
Vulnerability Management
CI/CD Security
Cloud Security
Kubernetes
Security Testing
Threat Intelligence
AI/ML Governance

Education

Bachelor's degree (CS/Cybersecurity/Engineering)
Advanced degree preferred
Certifications (CISSP/CSSLP/GIAC)

Tools

N/A

Job description

Mentions AI-assisted ('vibe coding') software development governance — role involves securing and governing vibe coding practices.

About the Role

Lead and mature Western Union's enterprise Application Security program, embedding secure-by-design principles across the software development lifecycle and partnering with engineering, product, DevOps, and cloud teams to enable secure, rapid delivery of products.

Job Description
Role

Director-level leader responsible for developing and executing an enterprise Application Security strategy, maturing a scalable AppSec program, and integrating security into the SDLC to enable secure-by-design engineering practices.

Key Responsibilities
  • Develop and execute enterprise application security strategy and multi-year transformation roadmap.
  • Build and mature a scalable Application Security program for cloud, web, mobile, APIs, containers, and emerging technologies.
  • Lead implementation and continuous improvement of a Secure Software Development Lifecycle (SSDLC) and define security standards and requirements for development.
  • Integrate security early into CI/CD pipelines and promote developer-friendly security practices.
  • Oversee application security testing and assurance: SAST, DAST, SCA, IAST, API security testing, container security, IaC security, secure code review, and coordinate penetration testing and bug bounty programs.
  • Partner with DevOps and engineering teams to automate security controls, streamline vulnerability management, and reduce developer burden.
  • Operationalize Continuous Threat & Exposure Management (CTEM) across critical applications and services; consolidate exposure signals and establish a common exposure taxonomy and risk model.
  • Provide guidance for cloud-native architectures, microservices, APIs, containers, Kubernetes, serverless, AI/ML applications, and third-party integrations.
  • Build trusted relationships with engineering leadership, champion security as an engineering quality function, and develop security champions programs.
  • Lead, mentor, and grow an Application Security team; manage vendors and technologies; set performance metrics and operational objectives.
Requirements
  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related field required; advanced degree preferred.
  • 10+ years progressive experience in Application Security, Software/Product Security, or related cybersecurity disciplines.
  • 5+ years leading Application Security teams and demonstrated success building or transforming AppSec programs in enterprise organizations.
  • Experience partnering with software engineering organizations in Agile and DevSecOps environments.
  • Strong understanding of SSDLC, OWASP Top 10, secure coding principles, threat modeling, API security, cloud-native and container security, CI/CD security, DevSecOps, software supply chain security, and application vulnerability management.
  • Knowledge of AI-assisted software development governance and secure use.
  • Possesses at least one certification (or comparable alternative): CISSP, CSSLP, GIAC GSSP, or GIAC GCSA.
What Success Looks Like (12–18 months)
  • Complete an Application Security maturity assessment and deliver a multi-year transformation roadmap.
  • Fully integrate security into CI/CD across major engineering organizations and implement risk-based application security metrics and dashboards.
  • Reduce remediation times while maintaining or improving developer satisfaction; standardize threat modeling, secure code review, and testing practices.
Benefits (US-specific highlights)
  • Base salary plus variable target incentive; short-term incentives.
  • Medical, dental, and life insurance; accident insurance; multiple health insurance options.
  • Parental leave; Family First Programs.
  • Tuition repayment assistance program.
  • Access to best-in-class development platforms.

SAST DAST SCA IAST API Security Container Security Infrastructure-as-Code (IaC) Security Kubernetes Serverless CI/CD Microservices Cloud-native Penetration testing Bug bounty Attack-surface management Threat intelligence Artificial Intelligence and Machine Learning applications OWASP Top 10

Skills

Application Security Secure Software Development Lifecycle (SSDLC) DevSecOps Threat Modeling Vulnerability Management Security Testing Oversight CI/CD Integration Cloud Security Container Security Cross-functional Collaboration Leadership Program Management Vendor Management Mentoring Risk Management Automation Communication Stakeholder Influence

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager Application Security
Manager Application Security

Citizens • Woodbridge Township (NJ)

On-site
USD 133,000 - 190,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Principal Application Security Engineer
Principal Application Security Engineer

CDW • United States

On-site
USD 180,000 - 240,000
Application Security (DevSecOps) Senior Engineer
Application Security (DevSecOps) Senior Engineer

Recru • Spring (TX)

On-site
USD 180,000 - 240,000
Senior Application Security Engineer
Senior Application Security Engineer

AgileEngine • United States

Hybrid
USD 120,000 - 180,000
Flextime
Professional growth
Competitive compensation
+2
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

Hybrid
USD 100,000 - 130,000
Director, Cyber Security Wanted!
Director, Cyber Security Wanted!

HealthCare Talent • Irvine (CA)

On-site
USD 130,000 - 160,000
Engineering Manager, Application Security
Engineering Manager, Application Security

Qualia • Austin (TX)

On-site
USD 180,000 - 240,000
Medical, Dental & Vision health plans
Competitive salary & equity
Flexible schedules
+3
Application Security Analyst
Application Security Analyst

Stellantis • Auburn (AL)

On-site
USD 90,000 - 120,000