Application Security Lead/Manager
Iru · Miami, United States
About The Role
Join Iru as an Application Security Lead/Manager, where you will own and mature our Application Security program. You will partner closely with Engineering, Product, and Security leadership to ensure security is embedded throughout the software development lifecycle. Your responsibilities will include managing the Application Security program, conducting technical security reviews, leading threat modeling initiatives, driving the vulnerability management lifecycle, and overseeing the implementation of application security tooling. This position is critical to strengthening our security posture and enabling engineering teams to deliver secure products at speed.
- Own and manage the Application Security program and secure software development lifecycle (SSDLC).
- Establish, maintain, and continuously improve application security standards, policies, and procedures.
- Drive the end-to-end vulnerability management lifecycle for applications and services, including remediation priorities and accountability.
- The ideal candidate combines strong technical application security expertise with the ability to influence engineering teams, drive remediation accountability, and scale security processes in a fast-moving environment
- Experience managing external penetration testing engagements
- Experience performing threat modeling, security assessments, and code review activities
- 7+ years of experience in Application Security, Product Security, or Security Engineering
- Hands-on experience with vulnerability management and remediation programs
- Strong understanding of secure software development practices and modern application architectures
- Deep familiarity with modern AppSec tooling and CI/CD security integration
- Strong communication skills with the ability to influence engineering and product stakeholders
- Experience leading or building AppSec programs in cloud-native environments
- Relevant security certifications such as CISSP, CSSLP, GWAPT, GWEB, or OSCP
- Knowledge of AWS, Azure, or GCP security best practices
- Experience with DevSecOps methodologies and automation
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring