TG IT Application Security Manager

Terumo Blood and Cell Technologies

Lakewood (CO)

Hybrid

USD 121,000 - 152,000

Full time

26 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical, dental & vision plans
Wellness program
Life insurance

Job summary

Terumo Blood and Cell Technologies is seeking an Application Security Manager to lead the organization?s AppSec program across the application lifecycle. You will collaborate with software, cloud, and product teams to identify and mitigate security risks while enabling secure software delivery.

The role focuses on building secure development standards, running testing programs (SAST/DAST/IAST), threat modeling, and vulnerability management in a hybrid Americas environment.

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field.
  • Master's degree preferred.
  • 8–10+ years of cybersecurity experience.
  • 5+ years in Application Security.
  • 3+ years leading security teams.
  • Experience implementing enterprise DevSecOps programs.
  • Experience working with Agile and CI/CD environments.
  • Experience with cloud-native application security.

Responsibilities

  • Lead the organizations Application Security program across the Application Cycle (SDLC).
  • Develop enterprise application security strategy with global and regional leaders.
  • Mentor Application Security Analysts and oversee testing programs (SAST/DAST/IAST, SCA).
  • Perform threat modeling sessions and risk assessments for high-risk apps.
  • Manage vulnerability management processes and remediation prioritization.
  • Support cloud security across AWS, Azure, and GCP.

Education

Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field
Master's degree preferred

Job description

  • Secrets Detection
  • Review high-risk applications

Requisition ID: 35487

At Terumo Blood and Cell Technologies, our 8,000+ global associates proud to come to work each day, knowing that what we do impacts the lives of patients around the world.

For Terumo, for Everyone, Everywhere.

We make medical devices and related products that are used to collect, separate, manufacture and process various components of blood and cells. With our innovative technologies and service offerings, we touch a patient’s life every second of every day and are committed to continuing to increase the number of patients we serve.

Advancing healthcare with heart.

With some of the best and brightest minds in the industry, an unmatched global footprint, comprehensive benefits and a distinct culture, Terumo Blood and Cell Technologies is a great place to work, grow and be part of a team that is focused on making a difference.

Join us and help shape wherever we go next. You create your future and ours.
Application Security Manager
Job Summary

Enterprise Application Portfolio - The Application Security Manager is responsible for leading the organization's Application Security program, ensuring that security is integrated throughout the Application Cycle (SDLC). This role partners closely with the software teams, cloud, architecture, infrastructure, and potentially product teams to identify, assess, and mitigate application security risks while enabling secure software delivery.

The successful candidate will lead a team of application security analysts, establish secure development standards, oversee security testing programs, and drive adoption of security best practices aligned with industry standards such as NIST SP 800-218 (Secure Software Development Framework), NIST Cybersecurity Framework (CSF) 2.0, OWASP, and CIS Controls.

Employment Type: Full-time

Department: Global Cybersecurity

Role Reports to: Security Operations Leader

Location: Americas

Work Arrangement: Hybrid

Scope: Regional

ESSENTIAL DUTIES (or Key Responsibilities)
Application Security Leadership
  • Collaborate with other global and regional leaders within to develop the enterprise Application Security strategy.
  • Lead, mentor, and develop Application Security Analysts.
  • Define AppSec metrics, KPIs, and maturity goals in collaboration with regional and global security leaders.
Secure Software Lifecycle
  • Integrate security into all phases of the enterprise application portfolio.
  • Ensure security requirements are incorporated during design and architecture reviews.
  • Promote security-by-design principles across application teams.
Security Testing

Manage and oversee:

  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Software Composition Analysis (SCA)
  • Interactive Application Security Testing (IAST)
  • API Security Testing
  • Container Security
  • Infrastructure as Code (IaC) Security
  • Mobile Application Security Testing
  • Secrets Detection
  • Review findings, prioritize remediation, and validate fixes.
  • Assist in Supply Chain Security
Threat Modeling
  • Facilitate threat modeling sessions with development teams.
  • Identify abuse cases and attack paths.
  • Recommend architectural improvements.
  • Ensure high-risk applications undergo formal security architecture reviews.
Vulnerability Management
  • Establish application vulnerability management processes
  • Prioritize remediation using risk-based methodologies
  • Track remediation SLAs
  • Report vulnerability metrics to executive leadership
  • Coordinate penetration testing remediation activities
  • Threat Intelligence
Cloud Application Security

Support secure development within cloud platforms including:

  • AWS
  • Microsoft Azure
  • Google Cloud Platform
Secure Code Reviews
  • Conduct manual secure code reviews
  • Review high-risk applications
  • Provide secure coding guidance
  • Coach development teams on remediation
API Security
  • Establish and set-up safe rules
  • Find weak spots through testing
  • Monitor logs to spot shadow APIs and strange traffic patterns
Security Awareness

Collaboration on training programs covering:

  • OWASP Top 10
  • Secure Coding
  • API Security
  • Cloud Security
  • Common software vulnerabilities
  • Secure design principles
Application Risk Management
  • Perform application security risk assessments.
  • Support enterprise application risk management initiatives.
Incident Response

Support cyber incident response by:

  • Investigating application security incidents.
  • Supporting forensic analysis.
  • Identifying root causes.
  • Leading post-incident reviews.
  • Developing preventive controls.
Compliance

Support compliance initiatives including:

  • NIST CSF 2.0
  • NIST SP 800-218 (SSDF)
  • NIST SP 800-53
  • OWASP ASVS
  • PCI DSS
  • HIPAA
  • SOX
  • ISO/IEC 27001
  • SOC 2
MINIMUM QUALIFICATION REQUIREMENTS
Education
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field.
  • Master's degree preferred.
Experience
  • 8–10+ years of cybersecurity experience.
  • 5+ years in Application Security.
  • 3+ years leading security teams.
  • Experience implementing enterprise DevSecOps programs.
  • Experience working with Agile and CI/CD environments.
  • Experience with cloud-native application security.

-Or-

Certificates, Licences, Registrations
  • CISSP
  • CSSLP
  • GIAC Web Application Penetration Tester (GWAPT)
  • GIAC Secure Software Programmer (GSSP)
  • Certified Cloud Security Professional (CCSP)
  • Certified Information Security Manager (CISM)
  • Microsoft Certified: Cybersecurity Architect Expert
  • Microsoft Certified: Azure Security Engineer Associate
Leadership Competencies
  • Strong people leadership
  • Strategic planning
  • Executive communication
  • Stakeholder management
  • Cross-functional collaboration
  • Risk-based decision making
  • Program management
  • Coaching and mentoring
  • Conflict resolution
  • Continuous improvement mindset
Key Performance Indicators (KPIs)
  • Critical vulnerability remediation SLA compliance
  • Mean time to remediate (MTTR)
  • Percentage of applications covered by SAST, DAST, and SCA
  • Security defects identified pre-production
  • Reduction in high-risk application vulnerabilities
  • CI/CD pipeline security coverage
  • Secure code review completion rate
  • Threat model completion rate
  • Developer secure coding training completion
  • Penetration test remediation completion
  • Application security maturity score
  • Audit and compliance findings related to application security
PHYSICAL REQUIREMENTS (for US Only)

Typical Office Environment requirements include: reading, speaking, hearing, close vision, traverse, bending, sitting, and occasional lifting up to 20 pounds.

Target Pay Range: $121,400.00 to $151,800.00 - Salary to be determined by the education, experience, knowledge, skills, and abilities of the applicant, internal equity, and alignment with market data

Target Bonus on Base: 15.0

At Terumo Blood and Cell Technologies, we provide competitive total reward offerings that consist of compensation, benefits, recognition, along with a wealth of other well-being, work-life and recognition programs which support in unlocking the potential for you and your family. Included in our expansive list of benefits offerings are multiple group medical, dental and vision plans, a robust wellness program, life insurance and disability coverages, also a variety of voluntary

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

TG IT Application Security Manager
TG IT Application Security Manager

Terumo BCT, Inc. • Lakewood (CO)

Hybrid
USD 121,000 - 152,000
Product Security Associate Analyst
Product Security Associate Analyst

Socket.dev • Lakewood (IL)

On-site
USD 78,000 - 97,000
401(k) plan with matching
Comprehensive medical/dental/vision
Product Security Associate Analyst
Product Security Associate Analyst

Terumo BCT, Inc. • Lakewood (CO)

On-site
USD 78,000 - 97,000
Medical, dental, vision plans
Wellness program
Life insurance
+3
TG IT Application Security Manager
TG IT Application Security Manager

TERUMO BCT, INC • Lakewood (CO), Northern (KY)

On-site
USD 120,000 - 160,000
Product Security Associate Analyst
Product Security Associate Analyst

TERUMO BCT, INC • Lakewood (CO), Northern (KY)

Hybrid
USD 78,000 - 97,000
Sr. Software Engineer - Embedded Security
Sr. Software Engineer - Embedded Security

Terumo Blood and Cell Technologies • Lakewood (CO)

Hybrid
USD 136,000 - 170,000
401(k) with matching
Health, dental, vision plans
Wellness program
+1
Senior Applications Manager, SAP ERP
Senior Applications Manager, SAP ERP

Terumo BCT, Inc. • Lakewood (CO)

On-site
USD 161,000 - 201,000
Medical, dental, vision plans
401(k) with matching
Paid time off
VP Global Software Development
VP Global Software Development

Terumo BCT, Inc. • Lakewood (CO)

On-site
USD 269,000 - 337,000
Senior Applications Manager, SAP ERP
Senior Applications Manager, SAP ERP

Terumo Blood and Cell Technologies • Lakewood (CO)

On-site
USD 160,000 - 201,000
VP Global Software Development
VP Global Software Development

Terumo Blood and Cell Technologies • Lakewood (CO)

On-site
USD 269,000 - 337,000