Application Security and Infrastructure Protection Administrator

Venu-

Orlando (FL)

On-site

USD 140,000 - 190,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible Time Off
Health & Wellness Coverage
401(k) plan with company match

Job summary

VENU+ is seeking a Senior Application Security and Infrastructure Protection Manager to lead a comprehensive security function across software development, infrastructure, and governance. The role focuses on embedding security, protecting critical systems, and ensuring compliance across mobility, smart lockers, and photo services.

The candidate will coordinate with software development, DevOps, IT, cybersecurity leadership, and vendors to maintain secure, resilient, and compliant platforms while

Qualifications

  • Bachelor's degree in Cybersecurity, IT, CS, or related field or equivalent experience.
  • 7+ years of progressive cybersecurity roles including application security and DevSecOps.
  • Strong knowledge of OWASP Top 10 and secure software development lifecycle.

Responsibilities

  • Advise on secure software development across SDLC, including threat modelling and secure design reviews.
  • Embed DevSecOps controls into delivery pipelines (SAST/DAST/containers).
  • Lead security operations, incident response, and vulnerability management activities.
  • Develop and enforce cybersecurity policies, governance, and risk-based controls.
  • Promote security-first culture among developers, IT teams, and vendors.

Skills

Application security
DevSecOps
Vulnerability management
Incident response
Cloud security

Education

Bachelor's degree in Cybersecurity/related field

Tools

SAST
DAST
SCA
SIEM
EDR

Job description

At VENU+, work feels like play — but with purpose.As the global leader in creating unforgettable guest experiences, we combine entertainment, gaming, souvenirs, mobility, and storage solutions to bring more excitement, engagement, and convenience to the world’s top destinations. From ScooterPals Fur-Wheelers and claw machines to photo capture, arcade games, and smart lockers, our creative programs help venues operate more efficiently, elevate guest satisfaction, and increase revenue — all with ease. Guided by collaboration, innovation, and a passion for excellence, we empower our team members to grow, contribute, and make a meaningful impact.If you’re seeking a career that’s dynamic, rewarding, and full of opportunity, you’ll find it at VENU+.At VENU+, we believe great work deserves meaningful rewards. Our benefits are designed to support your health, financial security, and overall well-being — so you can thrive both personally and professionally:Benefits Available to Qualifying Full-Time and Part-Time Employees:Flexible Time Off – Paid time off that allows you to take the time off you need, along with paid holidays.Health & Wellness Coverage – Comprehensive medical, dental, and vision plans.Retirement Planning – 401(k) plan with 50% company match on the first 6% contributed, including Roth optionsAnd more!!Grow your career with great benefits—and even better people!Job Summary:The Senior Application Security and Infrastructure Protection Manager is responsible for leading a comprehensive security function that embeds security into software development, protects critical infrastructure, strengthens security operations, and supports compliance and risk management across VENU+ technology platforms and business lines, including Mobility Services, Smart Lockers, and Photo Services. This role combines secure software development, application security engineering, DevSecOps enablement, infrastructure security, vulnerability management, incident response, policy governance, and audit readiness into one integrated position. The role works closely with software development, DevOps, IT operations, cybersecurity, executive leadership, vendors, finance, and business stakeholders to ensure applications, systems, cloud services, networks, endpoints, identities, data, and third-party platforms are designed, deployed, monitored, and maintained in a secure, resilient, compliant, and risk-aware manner.Key Responsibilities:Advise on application security engineering practices across the software development lifecycle, including secure design reviews, threat modelling, secure coding standards, architecture input, code review guidance, and release security validation.Embed DevSecOps controls into development and delivery pipelines, including SAST, DAST, dependency scanning, secret scanning, container scanning, infrastructure-as-code review, security gates, and remediation workflows.Partner with software, DevOps, product, and QA teams to identify application risks early, validate security requirements, prioritize vulnerabilities, and ensure secure-by-design outcomes for web, mobile, API, cloud, SaaS, and integration platforms.Protect infrastructure, cloud services, networks, endpoints, servers, databases, identities, privileged access, and business-critical systems through secure configuration baselines, hardening standards, monitoring, patching, and control validation.Manage vulnerability, patch, and remediation programs across applications and infrastructure, including risk ranking, ownership assignment, exception handling, reporting, verification, and executive escalation where required.Lead security operations activities, including alert triage, incident response coordination, investigation support, root cause analysis, containment, recovery, post-incident reviews, and improvement actions.Maintain and improve security monitoring, logging, endpoint protection, identity protection, email security, backup resilience, disaster recovery readiness, and business continuity controls.Develop, maintain, and enforce cybersecurity policies, secure software development standards, infrastructure protection procedures, risk registers, control evidence, security documentation, and operational runbooks.Support compliance, audit readiness, and governance activities aligned with applicable internal policies, customer requirements, contractual obligations, privacy requirements, and recognized security frameworks.Assess and manage technology, application, infrastructure, cloud, vendor, and third-party security risks, including due diligence, control reviews, risk acceptance, remediation tracking, and security recommendations.Provide security guidance to leadership and stakeholders through clear reporting on security posture, vulnerabilities, incidents, compliance status, control gaps, residual risks, and improvement priorities.Promote a security-first culture by coaching developers, IT teams, business users, and vendors on secure practices, risk awareness, incident prevention, and practical control adoption.Qualifications Required:Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Software Engineering, Information Systems, or a related field, or equivalent practical experience.7+ years of progressive experience across cybersecurity, application security, secure software development, DevSecOps, infrastructure security, security operations, or related technology roles.Strong understanding of secure software development practices, OWASP Top 10, secure coding principles, threat modelling, API security, authentication, authorization, session management, encryption, and data protection.Hands-on experience with security tools and practices such as SAST, DAST, SCA, dependency scanning, container scanning, secret scanning, vulnerability scanning, SIEM, EDR, log analysis, and incident response workflows.Experience protecting infrastructure, cloud platforms, SaaS systems, networks, endpoints, servers, databases, identity platforms, privileged access, backups, and disaster recovery capabilities.Working knowledge of risk management, control frameworks, audit evidence, compliance obligations, privacy requirements, third-party risk management, security policies, and governance processes.Familiarity with frameworks and standards such as NIST, ISO 27001, CIS Controls, SOC 2, PCI DSS, OWASP ASVS, ITIL, and secure software development lifecycle practices is preferred.Relevant certifications such as CISSP, CSSLP, CISM, CCSP, GIAC, Security+, Azure Security Engineer, AWS Security Specialty, or equivalent credentials are desirable.Strong leadership, analytical thinking, risk judgement, documentation, communication, stakeholder engagement, incident coordination, prioritization, and problem-solving skills.Work Environment:In-office.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security and Infrastructure Protection Administrator
Application Security and Infrastructure Protection Administrator

VENUplus Inc. • Orlando (FL), Northern (KY)

Hybrid
USD 90,000 - 130,000
Senior IT Manager
Senior IT Manager

Venu- • Orlando (FL)

On-site
USD 110,000 - 160,000
Quality Assurance Engineer
Quality Assurance Engineer

Venu- • Orlando (FL)

On-site
USD 70,000 - 110,000
Flexible time off
Health, dental and vision coverage
401(k) with company match (Roth option
Senior AppSec & Infrastructure Protection Leader
Senior AppSec & Infrastructure Protection Leader

Venu- • Orlando (FL)

On-site
USD 140,000 - 190,000
Flexible Time Off
Health & Wellness Coverage
401(k) plan with company match
Quality Assurance Engineer
Quality Assurance Engineer

VENUplus Inc. • Orlando (FL)

On-site
USD 70,000 - 100,000
Cyber Security Specialist
Cyber Security Specialist

Vensure Employer Solutions • Duluth (GA)

On-site
USD 80,000 - 100,000
Health Insurance
401(k) Retirement Plan
Paid Time Off
Senior Application Security Engineer – Vulnerability Operations
Senior Application Security Engineer – Vulnerability Operations

Veriipro • Jersey City (NJ)

On-site
USD 120,000 - 150,000
Application Security & VIPR Expert
Application Security & VIPR Expert

Armis • Town of Poland (NY)

On-site
USD 140,000 - 170,000
16267 Senior Cyber Security Specialist
16267 Senior Cyber Security Specialist

Socket.dev • Duluth (GA)

On-site
USD 110,000 - 150,000
Health Insurance
401(k) Plan
Paid Time Off
+1
16267 Senior Cyber Security Specialist
16267 Senior Cyber Security Specialist

Roman Health Pharmacy LLC • Duluth (GA), Northern (KY)

On-site
USD 110,000 - 160,000
Health Insurance
401(k) with company match
Paid Time Off
+5