Manager Application Security

Citizens

Woodbridge Township (NJ)

On-site

USD 133,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Citizens is seeking a Manager of Application Security responsible for leading enterprise application security capabilities in a complex tech environment. This role involves ensuring secure software development practices in the SDLC, partnering closely with various teams to enhance security while balancing regulatory and business requirements.

The ideal candidate has over 10 years of experience in cybersecurity with a strong focus on application security, leadership experience, and excellent communication skills. The expected salary range for this position is $133,000 to $190,000 per year.

Qualifications

  • 10+ years of cybersecurity experience with a strong focus on application security.
  • 5+ years of people or program leadership experience.
  • Deep understanding of application security risks.
  • Hands-on experience with modern SDLC and DevSecOps practices.
  • Proven ability to influence engineering and product stakeholders.

Responsibilities

  • Lead the enterprise application security program across platforms.
  • Define and execute application security vision aligned to business objectives.
  • Oversee integration of application security testing tools into CI/CD pipelines.
  • Establish governance, metrics, and reporting for application security.
  • Build and mentor application security engineers.

Skills

Cybersecurity experience
Application security
Leadership experience
SDLC
CI/CD practices
DevSecOps
Communication skills

Education

Bachelor’s degree in Computer Science, Cybersecurity, or related field

Tools

Application security testing tools
OWASP Top 10 knowledge

Job description

The Manager, Application Security is responsible for leading, scaling, and maturing enterprise application security capabilities across a complex technology environment. This role owns the application security program end to end, ensuring secure software development practices are embedded into the SDLC while balancing regulatory, risk, and business requirements. As part of the cybersecurity organization, this role partners closely with engineering, platform, cloud, DevOps, and risk teams to drive measurable risk reduction without slowing delivery.

Key Responsibilities
  • Lead the enterprise application security program across web, API, and mobile platforms
  • Define and execute the application security vision, strategy, and roadmap aligned to business and risk objectives
  • Establish and enforce application security standards, secure coding practices, and control requirements
  • Partner with engineering leadership to embed security into architecture, design, and delivery decisions
  • Oversee integration of application security testing tools, including SAST, DAST, and SCA, into CI CD pipelines
  • Lead application security assessments and risk based remediation planning
  • Provide threat informed guidance to engineering teams on high risk vulnerabilities and design patterns
  • Collaborate with vulnerability management, cloud security, and infrastructure teams to drive cohesive risk reduction
  • Establish governance, metrics, and reporting to measure application security maturity and effectiveness
  • Represent application security in audit, regulatory, and risk management engagements
  • Translate technical security risks into clear, business relevant insights for senior leaders
  • Build, mentor, and develop application security engineers and subject matter experts
  • Continuously improve tooling, automation, and processes to scale AppSec capabilities efficiently
Required Experience and Skills
  • 10 plus years of cybersecurity experience with a strong focus on application security
  • 5 plus years of people or program leadership experience operating an application security program in an enterprise environment
  • Deep understanding of application security risks, including OWASP Top 10 and API security threats
  • Hands on experience with modern SDLC, CI CD, and DevSecOps practices
  • Experience implementing and managing application security testing tools and processes
  • Ability to assess application architecture, design patterns, and authentication and authorization models
  • Strong experience partnering with engineering teams to drive secure by design outcomes
  • Excellent written and verbal communication skills, including executive level reporting
  • Proven ability to influence engineering, product, risk, and compliance stakeholders
Preferred Experience
  • Experience in highly regulated industries such as financial services or healthcare
  • Familiarity with cloud native and microservices based architectures
  • Experience with API security platforms and runtime visibility tools
  • Background in penetration testing or threat modeling
  • Experience defining application security metrics, KPIs, and maturity models
Education and Certifications
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field
  • Preferred certifications include CISSP, CISM, CISA, GPEN, or equivalent

The salary range for this position is from $133,000 to $190,000 per year.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Application Security Architect
Staff Application Security Architect

Rocket Homes Real Estate LLC • Seattle (WA)

On-site
USD 149,000 - 318,000
Application Security (DevSecOps) Senior Engineer
Application Security (DevSecOps) Senior Engineer

Recru • Spring (TX)

On-site
USD 180,000 - 240,000
Senior Manager, Cybersecurity – Application and Cloud Security
Senior Manager, Cybersecurity – Application and Cloud Security

Jobtailor • California (MO)

On-site
USD 150,000 - 210,000
AppSec Program Leader: Secure SDLC & Risk
AppSec Program Leader: Secure SDLC & Risk

Citizens • Woodbridge Township (NJ)

On-site
USD 133,000 - 190,000
Senior Application Security Engineer – Vulnerability Operations
Senior Application Security Engineer – Vulnerability Operations

Veriipro • Jersey City (NJ)

On-site
USD 120,000 - 150,000
Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

inmar • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Application Security (AppSec) Engineer/Architect
Application Security (AppSec) Engineer/Architect

TechDigital Group • Maryland Heights (MO)

On-site
USD 120,000 - 160,000
Architect, Information Security - DevSecOps/Application Security
Architect, Information Security - DevSecOps/Application Security

Jobgether • United States

On-site
USD 72,000 - 157,000
Competitive compensation
US-based role
Enterprise security exposure
Application Security Engineer
Application Security Engineer

IPolarity LLC • Whippany (NJ)

On-site
USD 146,136,000 - 197,713,000
Senior Application Security Engineer
Senior Application Security Engineer

FTS, Inc. • Atlanta (GA)

On-site
USD 100,000 - 130,000