via Lever.co
$120K - 180K a year
Lead and develop a multi-manager security organization to define and execute a strategic roadmap for application security and architecture.
12+ years in information security with 5+ years leadership, strong technical foundation in security engineering, cloud security, and software development.
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Director, Application Security based in the United States. This senior security leadership role will shape the strategy, execution, and maturity of application security and security architecture across a large technology organization. You will lead multiple teams and managers while partnering closely with product, platform engineering, legal, privacy, and compliance stakeholders. The role combines strategic leadership with strong technical credibility, particularly across application security, cloud security, architecture, and secure software development. You will build security capabilities directly into developer workflows, CI/CD pipelines, platforms, and product design processes. The position offers significant ownership over technical roadmaps, organizational development, budgets, tooling, and security investment priorities. You will help establish a developer-first security culture where secure engineering practices accelerate delivery rather than create unnecessary friction. This is a fully remote U.S. leadership opportunity for an experienced security builder who can operate effectively across engineering, business, and executive environments. \n Accountabilities: Lead and develop a multi-manager security organization spanning Application Security and Security Architecture, establishing clear priorities, strong team culture, and high-performance expectations. Define and execute a 2–3-year strategic roadmap aligned with product and platform engineering priorities and the organization’s evolving security needs. Own workforce planning, organizational design, talent acquisition, succession planning, and development of future security leaders. Build and retain highly technical security teams, with an emphasis on engineers who can develop, automate, and integrate security capabilities into engineering environments. Manage operational budgets, security tooling portfolios, and vendor relationships, prioritizing automation, measurable return on investment, consolidation, and reduction of unnecessary tool complexity. Represent application security and architecture at executive and leadership levels, translating technical security risks into clear business and financial implications. Lead an Application Security program that partners with engineering teams and embeds security capabilities into CI/CD pipelines, development frameworks, and developer tooling. Develop security enablement programs, secure coding training, and internal tools that make secure development practices easier for engineers to adopt. Ensure broad application security coverage across secure design reviews, SAST/DAST, dependency management, API security, and related application protection capabilities. Establish product security practices that incorporate security considerations during product and feature design rather than relying primarily on end-of-development audits. Build and maintain a risk-based vulnerability management program with defined service-level agreements, prioritization processes, and executive reporting. Partner with Security Architecture and Platform Engineering to establish enterprise security patterns, reference architectures, and practical guardrails for cloud-native infrastructure. Advance Zero Trust and identity-driven access principles across the environment, integrating security into infrastructure-as-code and platform capabilities. Provide proactive, practical security guidance during product and platform design reviews to help engineering teams move quickly while managing risk. Monitor emerging threats and technology developments, including AI/ML-related attack surfaces and cloud configuration risks, and evolve security architecture accordingly. Requirements: 12+ years of progressive experience in information security, including at least 5 years leading managers and multi-functional security teams. Previous experience in a high-growth consumer technology, fintech, or similarly engineering-driven environment is strongly preferred. Professional foundation in security engineering, software development, platform engineering, or a closely related technical discipline. Demonstrated ability to lead multiple security domains simultaneously while maintaining strong organizational execution and technical standards. Proven experience building and scaling Application Security programs that integrate into software development lifecycles, CI/CD environments, and developer workflows. Deep knowledge of multi-cloud security, with strong experience in AWS preferred. Hands-on understanding of infrastructure-as-code security, including technologies such as Terraform or CloudFormation, as well as Kubernetes and container security. Strong understanding of Zero Trust architecture and identity-focused security patterns. Experience with modern detection engineering, including custom detection pipelines, SOAR automation, and threat-model-driven security coverage. Ability to quantify security risk and communicate its business and financial implications to executive stakeholders and, ideally, board-level audiences. Demonstrated ability to recruit, develop, and retain highly experienced security engineers and senior individual contributors. Familiarity with modern security technologies and tooling, including SIEM, SOAR, DLP, EDR, EPM, CSPM/CWPP, SAST/DAST, infrastructure-as-code security, and container security. Strong judgment when evaluating security tooling, with an ability to rationalize and consolidate technologies rather than unnecessarily expanding the tool portfolio. Proficiency in at least one scripting or programming language, such as Python or Go, with sufficient technical depth to review automation, detection logic, and security tooling developed by the team. Strong communication, leadership, organizational design, strategic planning, and stakeholder-management skills. Ability to operate effectively in a distributed, remote environment while maintaining close collaboration with engineering and business leadership. Benefits: Base salary of $220,200–$351,800 annually in California, Connecticut, Maryland, Massachusetts, New Jersey, New York, Washington State, and Washington, D.C. Base salary of $209,200–$334,200 annually in Colorado, Hawaii, Illinois, Maine, Minnesota, Nevada, Ohio, Rhode Island, Vermont, and Virginia. Compensation varies based on factors including location, experience, and performance, with applicable state salary requirements observed. Eligibility for equity awards, with actual awards determined based on factors such as experience, performance, and location. Fully remote work within the United States, with employees able to work from a physical location of their choice, subject to limited location exceptions. A distributed-work environment built around flexibility, trust, collaboration, and productivity. Opportunity to lead high-impact security initiatives across application security, cloud security, and security architecture. Significant ownership of organizational strategy, technical roadmaps, budgets, tooling, and talent development. Opportunity to work closely with senior engineering, product, legal, privacy, compliance, and executive stakeholders. An inclusive and collaborative environment focused on innovation, professional growth, and meaningful technical impact. Equal employment opportunity and reasonable accommodation support for qualified candidates. \n How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
This job posting was last updated on 9/23/2026