Director, Application Security Engineering — Hybrid & AI-Sec Lead

WWE

New York (NY)

Hybrid

USD 142,500 - 190,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

TKO Group Holdings, Inc. in New York area is seeking a hands-on Director, Application Security Engineering to strengthen our cybersecurity posture across web, mobile, data and AI-enabled workflows.

This role embeds security into delivery practices, matures SSDLC, and partners with engineering teams to implement scalable controls. The position requires collaboration with software engineering, DevOps, architecture, QA, and compliance, while focusing on risk-based remediation and secure AI-enabled

Qualifications

  • 5+ years of hands-on experience in application security, product security, DevSecOps, and security engineering or a closely related software security role.
  • Proven experience working directly with engineering teams in fast-moving delivery environments.
  • Hands-on experience configuring, tuning, and operationalizing SAST, SCA, and related tooling such as SonarQube, Dependabot, GitHub, GitHub Advanced Security, or comparable platforms.
  • Ability to interpret and reason about code, identify meaningful risk, and provide specific, implementable remediation guidance to engineers.
  • Practical experience with SSDLC and shift-left practices, including automated code review support, threat modeling, security design review, and vulnerability management.
  • Strong understanding of application and API security, including common software weaknesses, authN/authZ, secrets handling, dependency risk, injection, deserialization, and data protection.
  • Experience integrating reliable, scalable, and minimally disruptive security controls into CI/CD pipelines and developer workflows.
  • Hands-on familiarity with cloud and modern software delivery patterns, including containers, IaC, and Git-based workflows.
  • Strong judgment in vulnerability triage, balancing severity, exploitability, business impact, and engineering realities.
  • Ability to write clear guidance, standards, and technical documentation for technical and non-technical audiences.
  • Bias toward automation, simplification, and scalable solutions over manual heroics.
  • Broad DevSecOps mindset across code, pipelines, dependencies, platforms, deployment, and operations.
  • Experience using AI tools responsibly to improve engineering and security outcomes.

Responsibilities

  • Own and evolve application security practices across the SSDLC, emphasizing scalable, developer-aligned, shift-left controls
  • Operate and improve SAST, SCA, secret scanning, code scanning, repository protections, and related controls across repositories and CI/CD pipelines
  • Develop secure development enablement for citizen developers, vibe coding, and AI-assisted development, including practical guidance for tooling, code assurance, identity, observability, and enterprise standards
  • Review application and code-level vulnerabilities, validate findings, reduce noise, and drive risk-based remediation plans
  • Conduct threat modeling and security design reviews for new systems, major changes, integrations, APIs, and high-risk workflows
  • Advise teams on secure coding, authentication and authorization, session management, secrets handling, logging, encryption, dependency hygiene, and data protection
  • Improve security guardrails for build pipelines, containers, APIs, third-party components, and deployment practices across modern and legacy environments
  • Mature risk-based vulnerability management across intake, validation, prioritization, remediation guidance, exception handling, and reporting
  • Support secure adoption of AI-assisted development and agentic systems by assessing trust boundaries, data exposure paths, prompt and tool-invocation risks, and misuse scenarios
  • Develop pragmatic standards, playbooks, reference architectures, documentation, and office-hour support that improve consistency without slowing teams down unnecessarily
  • Track recurring weaknesses, recommend structural fixes, and help leadership understand where engineering investment will reduce risk most effectively
  • Use AI productively and responsibly to accelerate analysis, triage, documentation, coding support, and security review while maintaining strong human judgment

Skills

Application security
DevSecOps
Security engineering
SAST
SCA
CI/CD
Threat modeling
AI security
Vulnerability management
Cloud security
Containers
IaC
Code review
GitHub
SonarQube
Dependabot
GitHub Advanced Security

Tools

SonarQube
Dependabot
GitHub
GitHub Advanced Security

Job description

TKO Group Holdings, Inc. in New York area is seeking a hands-on Director, Application Security Engineering to strengthen our cybersecurity posture across web, mobile, data and AI-enabled workflows.

This role embeds security into delivery practices, matures SSDLC, and partners with engineering teams to implement scalable controls. The position requires collaboration with software engineering, DevOps, architecture, QA, and compliance, while focusing on risk-based remediation and secure AI-enabled

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, App Security Engineering – Hybrid
Director, App Security Engineering – Hybrid

World Wrestling Entertainment, Inc. • New York (NY)

Hybrid
USD 143,000 - 190,000
Director, Secure App Engineering & AI Security
Director, Secure App Engineering & AI Security

Ultimate Fighting Championship • New York (NY)

Hybrid
USD 143,000 - 190,000
Director, AI & Security Engineering (Remote)
Director, AI & Security Engineering (Remote)

Peloton • United States

On-site
USD 260,000 - 342,000
Director, AI & Cloud Security Engineering
Director, AI & Cloud Security Engineering

Talanto • New York (NY), Northern (KY)

Hybrid
USD 260,000 - 342,000
Director, Application Security & Secure SDLC
Director, Application Security & Secure SDLC

Imea • New York (NY)

On-site
USD 190,000 - 250,000
Outperform expectations
Challenge Convention
Champion Opportunity
+2
Application Security Architect
Application Security Architect

VRPRO IT • New York (NY)

Hybrid
USD 140,000 - 190,000
Director of AI-Native AppSec: Lead Secure AI & CI/CD
Director of AI-Native AppSec: Lead Secure AI & CI/CD

Sierra Ventures • San Francisco (CA)

On-site
USD 275,000 - 315,000
Unlimited PTO
Excellent medical, dental, and vision
Employee Equity
+1
Application Security Architect – AI / GenAI
Application Security Architect – AI / GenAI

Extend Information Systems Inc. • New York (NY)

Hybrid
USD 150,000 - 210,000
Director, Cyber Security Wanted!
Director, Cyber Security Wanted!

HealthCare Talent • Irvine (CA)

On-site
USD 130,000 - 160,000
Director, App Security
Director, App Security

WWE • New York (NY)

Hybrid
USD 142,000 - 190,000