IT Application Security Manager

Cybersecurity Jobs

Lakewood (CO)

Hybrid

USD 130,000 - 190,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

401(k) plan with matching
Medical, dental, and vision plans
Wellness program
Life insurance and disability
Vacation and sick time

Job summary

Terumo seeks an IT Application Security Manager to build a secure software delivery program. This hybrid role in Lakewood, CO partners with software, cloud, architecture, and infrastructure teams to reduce application security risk while enabling teams to deliver with confidence.

You will lead Application Security Analysts, strengthen secure development standards across the SDLC, and oversee testing programs including SAST, DAST, SCA, IAST, API security, container security, IaC security, mobile

Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or related field.
  • Master’s degree preferred.
  • 8–10+ years of cybersecurity experience.
  • 5+ years in Application Security.
  • 3+ years leading security teams.
  • Experience implementing enterprise DevSecOps programs.
  • Experience with Agile and CI/CD environments.
  • Experience with cloud-native application security.

Responsibilities

  • Develop and evolve the enterprise Application Security strategy.
  • Lead, mentor, and develop Application Security Analysts.
  • Define AppSec metrics, KPIs, and maturity goals with stakeholders.
  • Integrate security throughout the enterprise application portfolio.
  • Promote security-by-design principles across teams.
  • Oversee security testing: SAST, DAST, SCA, IAST, API security, container security, IaC security, mobile testing, secrets detection.
  • Review findings, prioritize remediation, and guide risk-based remediation decisions.
  • Track remediation SLAs and coordinate penetration testing remediation activities.
  • Support supply chain security and threat modeling sessions.

Skills

Leadership
Mentoring
Security governance
DevSecOps
Agile
CI/CD
Cloud-native security
Threat modeling
Risk-based remediation

Education

Bachelor's degree
Master's degree preferred

Tools

AWS
Microsoft Azure
Google Cloud Platform

Job description

Terumo is seeking an IT Application Security Manager to help build a secure software delivery program across the enterprise. This hybrid role in Lakewood, CO sits within Global Cybersecurity and partners with software, cloud, architecture, and infrastructure teams to reduce application security risk while enabling application teams to deliver with confidence.

In this position, you will lead Application Security Analysts, strengthen secure development standards across the SDLC, and oversee testing programs including SAST, DAST, and SCA. Success is measured through security outcomes such as remediation SLA compliance, threat model coverage, and improvements in high-risk application vulnerability reduction.

Responsibilities
  • Collaborate with global and regional leaders to develop and evolve the enterprise Application Security strategy.
  • Lead, mentor, and develop Application Security Analysts.
  • Define AppSec metrics, KPIs, and maturity goals with regional and global security stakeholders.
  • Integrate security throughout the enterprise application portfolio and ensure requirements are included during design and architecture reviews.
  • Promote security-by-design principles across application teams.
  • Manage and oversee security testing and analysis activities, including SAST, DAST, SCA, IAST, API Security Testing, Container Security, Infrastructure as Code (IaC) Security, Mobile Application Security Testing, and Secrets Detection.
  • Review findings, prioritize remediation, and validate fixes; use risk-based methodologies to guide remediation decisions.
  • Track remediation SLAs, coordinate penetration testing remediation activities, and report vulnerability metrics to executive leadership.
  • Assist with Supply Chain Security and facilitate threat modeling sessions with development teams.
  • Identify abuse cases and attack paths, recommend architectural improvements, and ensure high-risk applications receive formal security architecture reviews.
  • Establish and run application vulnerability management processes, including processes for monitoring, coaching, and secure standards.
  • Support secure development in cloud platforms including AWS, Microsoft Azure, and Google Cloud Platform.
  • Conduct manual secure code reviews and provide secure coding guidance; coach teams on remediation and establish secure rules.
  • Find weak spots through testing and monitor logs to spot shadow APIs and strange traffic patterns.
  • Support training collaboration for OWASP Top 10, Secure Coding, API Security, Cloud Security, common software vulnerabilities, and secure design principles.
  • Perform application security risk assessments and support enterprise application risk management initiatives.
  • Investigate application security incidents, support forensic analysis, identify root causes, lead post-incident reviews, and develop preventive controls to reduce recurrence.
  • Support compliance initiatives aligned to NIST CSF 2.0, NIST SP 800-218 (SSDF), NIST SP 800-53, OWASP ASVS, PCI DSS, HIPAA, SOX, ISO/IEC 27001, and SOC 2.
Requirements
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or related field.
  • Master’s degree preferred.
  • 8–10+ years of cybersecurity experience.
  • 5+ years in Application Security.
  • 3+ years leading security teams.
  • Experience implementing enterprise DevSecOps programs.
  • Experience working with Agile and CI/CD environments.
  • Experience with cloud-native application security.
Tech & Tools

Key frameworks and standards include NIST SP 800-218 (Secure Software Development Framework), NIST Cybersecurity Framework (CSF) 2.0, OWASP, CIS Controls, NIST SP 800-53, OWASP ASVS, OWASP Top 10, as well as compliance considerations such as PCI DSS, HIPAA, SOX, ISO/IEC 27001, and SOC 2. Testing and security disciplines include SAST, DAST, SCA, IAST, IaC, and DevSecOps, with cloud environments across AWS, Microsoft Azure, and Google Cloud Platform.

Benefits
  • 401(k) plan with matching contribution
  • Multiple group medical, dental, and vision plans
  • Robust wellness program
  • Life insurance and disability coverages
  • Vacation and sick time programs
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Application Security Specialist
Senior Application Security Specialist

A-Line Staffing Solutions • Charlotte (NC)

Hybrid
USD 56,000 - 94,000
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

On-site
USD 100,000 - 130,000
Application Security Engineer
Application Security Engineer

Tential Solutions • United States

On-site
USD 120,000 - 180,000
PTO
Benefits package
Career growth
TG IT Application Security Manager
TG IT Application Security Manager

TERUMO BCT, INC • Lakewood (CO), Northern (KY)

On-site
USD 120,000 - 160,000
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Orlando (FL)

On-site
USD 150,000 - 210,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Head of Application Security & Secure Software Delivery
Head of Application Security & Secure Software Delivery

TERUMO BCT, INC • Lakewood (CO), Northern (KY)

Hybrid
USD 120,000 - 160,000
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Miami (FL)

On-site
USD 120,000 - 180,000
Professional growth
Competitive compensation
Fortune 500 projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • New York (NY)

On-site
USD 140,000 - 190,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Application Security & DevSecOps Architect
Application Security & DevSecOps Architect

Superior Dental Care, Inc. • Dublin (OH)

On-site
USD 100,000 - 130,000
Fitness center access
Tuition reimbursement
Employee bonus program
Manager Application Security
Manager Application Security

Citizens • Woodbridge Township (NJ)

On-site
USD 133,000 - 190,000