Role Summary
Prosper is seeking an experienced Application Security Senior Manager to lead our Application Security program. Reporting to the Head of Information Security, this role drives the strategy, implementation, and optimization of application security controls across the organization. The position requires deep technical proficiency and leadership skills to influence technology and product teams, and is suited for self‑driven candidates interested in FinTech improving financial well‑being.
How You’ll Make An Impact
- Program Leadership: Define and execute a multi‑year Application Security roadmap aligned with business goals and industry best practices.
- Security Engineering & Automation: Integrate threat modeling, security tools & testing (SAST, SCA, DAST, IAST, RASP, etc.) and secure‑by‑design processes into the SDLC (CI/CD pipeline).
- Architecture Reviews: Perform security architecture reviews for major product changes.
- Vulnerability Management: Oversee the end‑to‑end AppSec vulnerability lifecycle (identification, prioritization, and remediation based on business risk, exploitability, and threat intelligence).
- Incident Response: Direct and manage incident response for application security alerts/incidents.
- Offensive Security & Testing: Lead the strategy for third‑party penetration tests.
- Reporting & Metrics: Deliver executive‑level dashboards and reports on application security posture and risk trends.
- Team Leadership: Manage and mentor a high‑performing team of AppSec engineers, fostering a vision for excellence.
- Continuous Improvement: Drive continuous improvement activities and deepen leadership awareness of product and application security risks.
- Strategic Partnership & Collaboration: Collaborate with Engineering and Product leads to embed security into the SDLC and scale the Security Champions program.
Skills That Will Help You Thrive
- 10+ years of progressive application security experience (prior software development experience preferred).
- Prior people leadership experience (3+ years) with the ability to lead, manage, and develop a technical Application Security Engineering team.
- Great interpersonal skills, ability to foster constructive dialogue.
- Deep technical knowledge with a track record of successful execution in application security (secure SDLC, penetration testing, and security tooling—SAST, DAST, IAST, RASP, SCA).
- Strong knowledge of CI/CD pipelines, cloud‑native security (GCP), and container security.
- Bachelor’s degree in Computer Science or a related field, or its equivalent in work experience.
- Strong working knowledge of at least two programming or scripting languages.
Benefits
- A connected experience: high‑touch collaboration and flexibility, remote or in‑office options, digital‑first tools, and intentional culture.
- Competitive salary and a 401(k) with a 5% company match.
- Holistic well‑being: flexible time off, paid parental leave, annual wellness allowance, and comprehensive health coverage.
- Professional & personal growth: premium perks including Udemy access, childcare assistance, pet insurance, and savings through Beneplace.
Compensation $226,000 - $270,000 a year plus bonus and generous benefits. Salary will be considered based on location, experience, and job‑related factors.
Equal Opportunity Statement
- Applicants have rights under Federal Employment Laws.
- Family & Medical Leave Act (FMLA).
- Equal Employment Opportunity (EEO).
- Employee Polygraph Protection Act (EPPA).