Lead AppSec Engineer

Gartner

Irving (TX)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive compensation
Limitless growth and learning opportunities
20+ PTO days
Extensive medical, dental, vision coverage
401(k) with corporate match

Job summary

Gartner is seeking a Lead Security Engineer to support its Application Security function, manage vulnerability assessments, and implement security tools. The ideal candidate will have 6–8 years of experience in Security Engineering, with expertise in DevSecOps, Cloud Security, and Application Security.

This role emphasizes collaboration, critical thinking, and mentoring of peers in secure application design. Benefits include competitive compensation, professional development opportunities, and flexible work options.

Qualifications

  • 6–8 years of experience in a Security Engineering role.
  • Expertise in DevSecOps, Cloud Security, and Application Security.
  • Strong problem-solving skills and critical thinking.

Responsibilities

  • Support the Application Security function and manage vulnerability assessments.
  • Collaborate with stakeholders to design secure applications.
  • Mentor engineers on threat modeling techniques.
  • Triage security risks and vulnerabilities.
  • Define and implement security control metrics.

Skills

Cloud Security
DevSecOps
Application Security
Vulnerability scanning
Threat modeling

Tools

AWS
Azure
GCP
AST platforms

Job description

About the Role

The Lead Security Engineer will support Gartner's Application Security (AppSec) function, collaborating with Information Security partners and technology stakeholders to manage vulnerability assessments, develop and track remediation, prioritize risk across business units, implement security tools, and engineer automation solutions to streamline AppSec responsibilities.

What You'll Do
  • Collaborate with stakeholders to design secure applications, test for security weaknesses, and remediate issues.
  • Mentor engineers and security champions on threat modeling techniques.
  • Triage and prioritize security risks, vulnerabilities, and exceptions in line with business impact and risk tolerance.
  • Coordinate orchestration, automation, and management of security technologies and platforms.
  • Own day‑to‑day lifecycle management, including threat assessment and risk avoidance.
  • Create actionable reports demonstrating impact on security posture.
  • Define and implement metrics to measure effectiveness of security controls via KRIs and scorecards.
  • Serve as subject‑matter expert for Application Security, acting as first point of contact for critical issues and triaging CI/CD security findings.
  • Evaluate requirements to select and deploy tools, processes, and technologies that strengthen security posture.
  • Use data to drive prioritization, highlight systemic issues, and influence roadmap decisions.
What You'll Need

Ideal candidates will have 6–8 years of experience in a Security Engineering role with proven expertise in DevSecOps, Cloud Security, and Application Security. Strong independent critical‑thinking and problem‑solving skills are essential.

Must Have
  • Experience with vulnerability scanning, AST platforms, and cloud security tooling.
  • Formal threat‑modeling experience.
  • Leadership of projects and initiatives, both direct and indirect.
  • Deep knowledge of risk assessment and prioritization, with ability to think like a bad actor.
  • Cloud experience with AWS, Azure, or GCP.
  • Understanding of IaC and PaC concepts.
Nice to Have
  • Familiarity with SOC 2, ISO 27001/27013, NIST 800‑53 frameworks.
  • Automation scripting or programming (Java, .NET, HTML, Ruby, PHP, Perl, C#, Python, JavaScript, PowerShell, Bash).
  • Experience with penetration testing and web application assessment.
Who You Are
  • Excellent communication, collaboration, and critical‑thinking skills.
  • Ability to build trusting relationships with peers, stakeholders, partners, and suppliers.
  • Skill in defining and communicating risk in business‑relevant language to both technical and non‑technical audiences.
  • Strategic problem‑solving knowledge to address complex business/technical issues.
  • Desire for lifelong learning and continuous development.
Benefits
  • Competitive compensation.
  • Limitless growth and learning opportunities.
  • Ongoing mentorship and apprenticeship; leadership courses, development programs, technical courses, certification opportunities and more.
  • Collaborative and positive culture.
  • Direct impact on strategy.
  • Flexibility: work from home and office collaboration.
  • 20+ PTO days plus holidays and floating holidays in first year.
  • Extensive medical, dental, vision coverage.
  • 401(k) with corporate match and immediate vesting.
  • Health‑and‑wellness allowance programs.
  • Parental leave.
  • Tuition reimbursement.
  • Employee Stock Purchase Plan.
  • Employee Assistance Program.
  • Gartner Gives Charity Match.
Equal Employment Opportunity

Gartner is an Equal Opportunity Employer. We do not discriminate based on race, color, creed, religion, sex, sexual orientation, gender identity, marital status, citizenship status, age, national origin, ancestry, disability, veteran status, or any other legally protected status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead AppSec Engineer
Lead AppSec Engineer

Gartner • Fort Myers (FL)

Hybrid
USD 116,000 - 170,000
Competitive compensation
Hybrid work environment
Mentorship programs
Engagement Manager, IT Strategy, Cyber
Engagement Manager, IT Strategy, Cyber

Gartner • Chicago (IL)

Hybrid
USD 168,000 - 199,000
Generous PTO
401(k) match
Stock purchase opportunities
+1
Engagement Manager, IT Strategy, Cyber
Engagement Manager, IT Strategy, Cyber

Gartner • Irving (TX)

Hybrid
USD 168,000 - 199,000
Generous PTO
401(k) match up to $7,200
Opportunity to purchase company stock at a discount
+1
Engagement Manager, IT Strategy, Cyber
Engagement Manager, IT Strategy, Cyber

Gartner • New York (NY)

Hybrid
USD 168,000 - 199,000
Generous PTO
401(k) matching up to $7,200 per year
Opportunity to purchase company stock at a discount
+1
Engagement Manager, IT Strategy, Cyber
Engagement Manager, IT Strategy, Cyber

Gartner • Georgia

Hybrid
USD 168,000 - 199,000
Generous PTO
401(k) match
Stock purchase opportunity
+1
Manager, Security Operations (Hands On/Technical)
Manager, Security Operations (Hands On/Technical)

Gartner • Dolphin Cove (CT)

Hybrid
USD 108,000 - 148,000
Unlimited PTO
401(k) with corporate match
Tuition reimbursement
+1
Manager, Security Operations (Hands On/Technical)
Manager, Security Operations (Hands On/Technical)

Gartner • Arlington (VA)

Hybrid
USD 108,000 - 148,000
Competitive compensation
Unlimited growth opportunities
Flexible working conditions
+3
Manager, Security Operations (Hands On/Technical)
Manager, Security Operations (Hands On/Technical)

Gartner • Stamford (CT)

Hybrid
USD 110,000 - 140,000
Competitive compensation
401(k) with corporate match
20+ PTO days
+2
Lead Security Analyst (DLP/DSPM)
Lead Security Analyst (DLP/DSPM)

Socket.dev • Connecticut

Hybrid
USD 94,000 - 134,000
Hybrid work environment
401k match
Stock purchase plan
+1
Senior Director Analyst – Cloud Native Security
Senior Director Analyst – Cloud Native Security

Gartner • Stamford (CT)

On-site
USD 150,000 - 200,000
Competitive salary
Generous paid time off
401K matching
+1