Application security program (cybersecurity)
Quick Overview
Job Description
Key Responsibilities:
· Lead end-to-end engagement for the AppSOC program, ensuring alignment with customer’s cybersecurity and business objectives
· Act as the primary point of contact for senior client stakeholders, building strong executive relationships
· Oversee program governance, including planning, execution, risk management, and reporting
· Drive delivery excellence across application security services such as SAST, DAST, SCA, and vulnerability management
· Provide hands-on technical direction and escalation support to AppSOC platform engineers - tool configuration, integration design reviews, and remediation prioritization
· Own the application log on boarding and detection engineering work streams -guiding normalization and standardization of application-layer logs into OCSF format for downstream consumption, and reviewing custom detection use cases with the client
· Collaborate with cross-functional teams (security, engineering) to ensure seamless integration of AppSec practices
· Monitor KPIs, SLAs, and overall program health, ensuring timely and high-quality deliverables
· Identify opportunities for expansion, optimization, and continuous improvement within the engagement
· Manage financials including budgeting, forecasting, and revenue assurance
Required Qualifications:
· 8+ years of experience in IT services, cybersecurity, or application security programs
· Proven experience managing large-scale client engagements, preferably in North America
· Hands-on experience with application security tooling across SAST, DAST, SCA, and API security (e.g., Checkmarx, Veracode, Snyk, Burp Suite)
· Hands-on experience building or operating an AppSOC, including integration of AppSec tools with SIEM/SOAR platforms overall (e.g., Microsoft Sentinel, Splunk, Google SecOps/Chronicle, Elastic)
· Working knowledge of application-layer log sources able to distinguish different app-layer log types including parsing logs in BigQuery and AWS S3 and normalization/standardization to OCSF, with solid grounding in detection engineering able to shape and validate custom detection use cases and the logic behind them
· Proven ability to define and drive vulnerability management workflows, remediation SLAs, and AppSec metrics (MTTR, coverage, risk reduction)
· Excellent stakeholder management and communication skills, including C-level interaction
· Experience in program management methodologies (Agile, Waterfall, Hybrid)
· Strong commercial acumen and experience managing P&L or large program budgets
Preferred Qualifications:
· Prior experience in Automotive or Manufacturing sector engagements
· Certifications such as CISSP, CISM, PMP, or equivalent
· Scripting/automation familiarity (Python, PowerShell) and exposure to cloud security across Azure/AWS/Google Cloud Platform, containers, and Kubernetes
Skills
Similar jobs
Senior Principal Software Engineer with Test Equipment with Security Clearance
RTX · Tucson, United States
13 minutes ago$132.4k - $251.6k/yrSystems Engineer Level 5 with Security Clearance
Markon · Fort Meade, United States
13 minutes ago$200k - $210k/yrGhostEye Radar Lead Systems Engineer with Security Clearance
RTX · Tewksbury, United States
13 minutes ago$132.4k - $251.6k/yrRadar Systems Engineer I - Modeling & Simulation OSI with Security Clearance
RTX · Huntsville, United States
13 minutes ago$57.2k - $108.8k/yrCyber Security Analyst with Security Clearance
CACI · High Point, United States
13 minutes ago$63.3k - $129.7k/yrData Software Engineer (Hybrid Schedule) with Security Clearance
TEKsystems c/o Allegis Group · Fort Meade, United States
13 minutes ago