Sr. Application Security Manager

DoubleVerify Inc.

New York (NY)

Hybrid

USD 153,000 - 260,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Bonus/Commission
Equity
Benefits

Job summary

DoubleVerify is seeking an Application, AI, and Security Engineering Leader to own and evolve DV's SSDLC, application security, API security, and AI/LLM security. You will lead security engineers, drive SBOM, OSS/License compliance, and threat modeling across cloud-native environments.

The role requires deep AppSec tooling expertise, cloud security (GCP/Kubernetes), and experience delivering secure coding training while collaborating with multiple engineering teams.

Qualifications

  • Progressive information security experience with leadership roles.

Responsibilities

  • Own and evolve DV's application security program across CI/CD and SSDLC.
  • Lead AI security governance across DV's AI/ML ecosystem.
  • Enable offensive security and DevSecOps enablement with external vendors.

Skills

Security leadership
AppSec tooling
Cloud security
Threat modeling
Python or scripting

Education

Bachelor's degree in CS/IS or related

Tools

SAST/SCA/DAST/ASPM tooling
OWASP Top 10 for APIs/LLMs
Kubernetes/Terraform

Job description

Who We Are DV is the leader in digital performance solutions, helping our advertiser and agency partners Verify the quality of their digital campaigns, Optimise to improve performance and Prove that they’re achieving their business outcomes, through unbiased 3rd party data and analytics. DV’s mission is to be the definitive source of transparency and data-driven insights into the quality and effectiveness of digital advertising for the world’s largest brands, agencies, publishers, and digital ad platforms. Since 2008, DV has helped hundreds of Fortune 500 companies gain the most from their media spend by delivering best-in-class solutions across the digital advertising ecosystem, helping to build a better industry. Learn more at www.doubleverify.com.

About the Role

Role Summary As Application & AI Security leadership within DV InfoSec, you will own and evolve DoubleVerify's Secure Software Development Lifecycle (SSDLC), application security, API security, and AI/LLM security. You will lead the people, processes, and tooling that keep DV's code, pipelines, cloud workloads, APIs, and AI systems secure, partnering across the engineering organization. DV protects the integrity of digital advertising for the world's biggest brands. Securing the applications, APIs, pipelines, and AI systems behind that mission directly protects DV's customers, revenue, and reputation. You'll have executive support, real budget, modern tooling, and the mandate to build a best-in-class Application, AI, and Security Engineering program.

Key Responsibilities
Application & Product Security

Own and evolve DV's application security program, including SAST, SCA, DAST, and Application Security Posture Management (ASPM) tooling (e.g., Ox Security) — advancing findings from non-blocking warnings toward enforced, risk-based merge gates. Drive the OWASP Application Security Verification Standard (ASVS) adoption program across engineering repositories, including reporting, dashboards, and branch-level coverage. Drive SBOM management, license compliance, and software supply chain security practices across development teams. Partner with DevOps and engineering to embed security across the CI/CD pipeline and Secure SDLC (SSDLC). Develop and maintain application security metrics and reporting for engineering leadership, including vulnerability burn-down and mean-time-to-remediate (MTTR). Lead the bi-weekly vulnerability remediation touchpoints and the monthly Application Security Leadership Forums with engineering organizations (Pinnacle, Measurement, Programmatic, Architecture, Publisher, Social, QA, TechOps/SRE, CorpIT, DevOps, and M&A) to drive progress and accountability. Oversee DV's API security program (OWASP API Security Top 10, e.g., Escape API Security) and attack surface management (ASM) capabilities, including discovery of shadow/zombie APIs. Assist with Web Application Firewall (WAF) configuration, deployment, and monitoring. Partner with DevOps/SRE on cloud and container security (e.g., Wiz) to deliver code-to-cloud coverage.

AI & Emerging Technology Security Lead

Lead AI security governance, engineering, and threat assessment functions across DV's AI/ML ecosystem. Secure AI agents, LLM-based applications, MCP gateway, and agentic SDLC workflows against threats such as prompt injection, jailbreaking, excessive agency, and supply chain compromise — including guardrails, telemetry, logging, and detections for developer AI tooling (Cursor, Claude Code, VS Code). Evaluate and operationalize AI security platforms to provide detection, response, and AI supply chain governance across teams building or operating AI systems (e.g., AI security gateway, shadow-AI discovery/DLP, AI identity and software management). Build threat models and controls for first- and third-party AI/ML workloads, including data pipelines, model provenance, and RAG architectures. Advance AI-assisted security testing (e.g., DV's PromptFlow-driven web/API security test generation) to scale coverage across teams.

Security Engineering, Offensive Security & DevSecOps Enablement Lead

Enable DV's offensive security and penetration testing program, working with external vendors and conducting internal security assessments. Build and maintain security automation capabilities to reduce manual effort and increase detection coverage. Partner with the DevOps and CloudOps organizations on cloud security (primarily GCP/Kubernetes), shared responsibility model execution, and infrastructure-as-code security. Own and conduct threat modeling for DV products and infrastructure. Deliver secure coding training and developer enablement programs across global engineering teams.

Team Leadership & Management

Recruit, onboard, and manage a team of security engineers and contractors, including software security developers and offensive security testers. Set goals, track performance, and provide ongoing coaching and mentorship to team members. Administer budgets, vendor relationships, and tool procurement within the security engineering function. Collaborate cross-functionally with GRC, Security Operations, IT Security, Legal, and Privacy teams. Meet with senior leadership, engineering managers, and developers across DV's global engineering departments on a regularly scheduled basis to share the security roadmap and best practices. Represent the application security and AI security programs to senior leadership and in audit/compliance contexts (SOC 2, ISO 27001, NIST CSF 2.0).

About You
Required Experience & Qualifications

10+ years of progressive experience in information security, with at least 3 years in a technical management or lead role. Demonstrated expertise in two or more of the following domains: application security, AI/ML security, software supply chain security, penetration testing, cloud security. Hands-on experience with AppSec tooling such as SAST, SCA, DAST, ASPM platforms (e.g., Ox Security, Snyk, Veracode, Checkmarx) and API security. Experience securing AI/ML systems, including familiarity with the OWASP Top 10 for LLMs, NIST AI RMF, agent architectures, and LLM attack vectors. Proficiency in cloud-native environments, particularly GCP; experience with Kubernetes and infrastructure-as-code (e.g., Terraform) is highly desirable. Experience managing or directly executing penetration testing programs (web, API, cloud, AI) and bug bounty programs. Familiarity with DevSecOps principles and integrating security into CI/CD pipelines (GitLab/GitHub/GitOps/ArgoCD). Strong understanding of software supply chain security: SBOM, license compliance, OSV/CVE triage, and dependency chain risk. Experience collaborating with compliance and audit programs (SOC 2, ISO 27001) from a security engineering perspective. Excellent written and verbal communication skills with demonstrated ability to present complex security topics to both technical and non-technical audiences. Proficiency in at least one scripting/programming language (e.g., Python) for security automation.

Preferred Experience & Qualifications

Industry certification preferred (CISSP, CSSLP, GWAPT, OSCP, or equivalent). Bachelor's degree or higher in Computer Science, Information Systems, or a related field, or equivalent technical experience.

This position is full-time and located in our New York City headquarters offices offering a hybrid work model from office and remote.

The successful candidate’s starting salary will be determined by a number of non-discriminatory factors, including qualifications for the role, level, skills, experience, location, and internal equity relative to peers at DV. The estimated salary range for this role, based on the qualifications set forth in the job description, is between $153,000 $260,000. This role will also be eligible for bonus/commission (as applicable), equity, and benefits. The range above is for the expectations as laid out in the job description; however, we are often open to a wide variety of profiles and recognize that the person we hire may be more or less experienced than this job description as posted.

Benefits
  • bonus/commission (as applicable), equity, and benefits.
Why us

DV provides the industry’s leading Media Effectiveness Platform. Utilizing trusted measurement data and dynamic AI optimization, DV maximizes campaign effectiveness and drives tangible business outcomes for advertisers wherever they run their digital media. DV powers performance for the world's largest brands, platforms and publishers. We believe this is important work. Why? Because when an ad-supported ecosystem hums, it preserves a free internet for us all. We're looking for the best and the brightest talent, those who stand for one another and meet challenges with a spirit of ingenuity and invention.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Manager, DevSecOps
Sr. Manager, DevSecOps

DoubleVerify Inc. • New York (NY)

On-site
USD 153,000 - 260,000
Sr. Application Security Manager
Sr. Application Security Manager

DoubleVerify • New York (NY)

On-site
USD 153,000 - 260,000
Sr. DevOps Engineer II, AI Platforms
Sr. DevOps Engineer II, AI Platforms

DoubleVerify Inc. • New York (NY)

Hybrid
USD 153,000 - 260,000
Sr. Software Engineer II
Sr. Software Engineer II

DoubleVerify Inc. • New York (NY)

Hybrid
USD 107,000 - 212,000
Sr. Site Reliability Engineer I
Sr. Site Reliability Engineer I

DoubleVerify Inc. • New York (NY)

On-site
USD 104,000 - 178,000
Corporate Systems Engineer, Collaboration Platforms
Corporate Systems Engineer, Collaboration Platforms

DoubleVerify Inc. • New York (NY)

Hybrid
USD 94,000 - 160,000
Hybrid work model
Bonus/commission where applicable
Equity
+1
Sr. Data Engineer I
Sr. Data Engineer I

DoubleVerify Inc. • New York (NY)

Hybrid
USD 89,000 - 178,000
Sr. Engineering Manager - Social
Sr. Engineering Manager - Social

DoubleVerify Inc. • New York (NY)

Hybrid
USD 180,000 - 240,000
Client Analytics Lead
Client Analytics Lead

DoubleVerify Inc. • New York (NY)

On-site
USD 100,000 - 163,000
Bonus/commission (as applicable)
Equity
Benefits
Sr. Analytics Data Platform Engineer
Sr. Analytics Data Platform Engineer

DoubleVerify Inc. • New York (NY)

On-site
USD 107,000 - 212,000