wagey.ggwagey.gg
30,534  jobs30,534  jobs
Browse Tech JobsCompaniesFeaturesPricingFAQs
Log InGet Started Free
Jobs(30,534)/Security Management Specialist Role(71)/DoubleVerify (17) - Sr. Application Security Manager
DoubleVerify

DoubleVerify - Sr. Application Security Manager

NYC Global HQ$153k - $260k1w ago
In OfficeSeniorWWCybersecurityCloud ComputingSecurity Management SpecialistApplication Security EngineerPythonTeam ManagementGoal SettingTraining DevelopmentKubernetesGCPTerraformReportingPhoenixClaudeVS CodeTeam LeadershipCursorWagmiCPCCoachingGovernanceProcurement

Requirements

• 10+ years of progressive experience in information security, with at least 3 years in a technical management or lead role. • Demonstrated expertise in two or more of the following domains: application security, AI/ML security, software supply chain security, penetration testing, cloud security. • Hands-on experience with AppSec tooling such as SAST, SCA, DAST, ASPM platforms (e.g., Ox Security, Snyk, Veracode, Checkmarx) and API security. • Experience securing AI/ML systems, including familiarity with the OWASP Top 10 for LLMs, NIST AI RMF, agent architectures, and LLM attack vectors. • Proficiency in cloud-native environments, particularly GCP; experience with Kubernetes and infrastructure-as-code (e.g., Terraform) is highly desirable. • Experience managing or directly executing penetration testing programs (web, API, cloud, AI) and bug bounty programs. • Familiarity with DevSecOps principles and integrating security into CI/CD pipelines (GitLab/GitHub/GitOps/ArgoCD). • Strong understanding of software supply chain security: SBOM, license compliance, OSV/CVE triage, and dependency chain risk. • Experience collaborating with compliance and audit programs (SOC 2, ISO 27001) from a security engineering perspective. • Excellent written and verbal communication skills with demonstrated ability to present complex security topics to both technical and non-technical audiences. • Proficiency in at least one scripting/programming language (e.g., Python) for security automation. • Industry certification preferred (CISSP, CSSLP, GWAPT, OSCP, or equivalent). • Bachelor's degree or higher in Computer Science, Information Systems, or a related field, or equivalent technical experience.

Responsibilities

• Application & Product Security • Own and evolve DV's application security program, including SAST, SCA, DAST, and Application Security Posture Management (ASPM) tooling (e.g., Ox Security) — advancing findings from non-blocking warnings toward enforced, risk-based merge gates. • Drive the OWASP Application Security Verification Standard (ASVS) adoption program across engineering repositories, including reporting, dashboards, and branch-level coverage. • Drive SBOM management, license compliance, and software supply chain security practices across development teams. • Partner with DevOps and engineering to embed security across the CI/CD pipeline and Secure SDLC (SSDLC). • Develop and maintain application security metrics and reporting for engineering leadership, including vulnerability burn-down and mean-time-to-remediate (MTTR). • Lead the bi-weekly vulnerability remediation touchpoints and the monthly Application Security Leadership Forums with engineering organizations (Pinnacle, Measurement, Programmatic, Architecture, Publisher, Social, QA, TechOps/SRE, CorpIT, DevOps, and M&A) to drive progress and accountability. • Oversee DV's API security program (OWASP API Security Top 10, e.g., Escape API Security) and attack surface management (ASM) capabilities, including discovery of shadow/zombie APIs. • Assist with Web Application Firewall (WAF) configuration, deployment, and monitoring. • Partner with DevOps/SRE on cloud and container security (e.g., Wiz) to deliver code-to-cloud coverage. • AI & Emerging Technology Security • Lead AI security governance, engineering, and threat assessment functions across DV's AI/ML ecosystem. • Secure AI agents, LLM-based applications, MCP gateway, and agentic SDLC workflows against threats such as prompt injection, jailbreaking, excessive agency, and supply chain compromise — including guardrails, telemetry, logging, and detections for developer AI tooling (Cursor, Claude Code, VS Code). • Evaluate and operationalize AI security platforms to provide detection, response, and AI supply chain governance across teams building or operating AI systems (e.g., AI security gateway, shadow-AI discovery/DLP, AI identity and software management). • Build threat models and controls for first- and third-party AI/ML workloads, including data pipelines, model provenance, and RAG architectures. • Advance AI-assisted security testing (e.g., DV's PromptFlow-driven web/API security test generation) to scale coverage across teams. • Security Engineering, Offensive Security & DevSecOps Enablement • Lead DV's offensive security and penetration testing program, working with external vendors and conducting internal security assessments. • Build and maintain security automation capabilities to reduce manual effort and increase detection coverage. • Partner with the DevOps and CloudOps organizations on cloud security (primarily GCP/Kubernetes), shared responsibility model execution, and infrastructure-as-code security. • Own and conduct threat modeling for DV products and infrastructure. • Deliver secure coding training and developer enablement programs across global engineering teams. • Team Leadership & Management • Recruit, onboard, and manage a team of security engineers and contractors, including software security developers and offensive security testers. • Set goals, track performance, and provide ongoing coaching and mentorship to team members. • Administer budgets, vendor relationships, and tool procurement within the security engineering function. • Collaborate cross-functionally with GRC, Security Operations, IT Security, Legal, and Privacy teams. • Meet with senior leadership, engineering managers, and developers across DV's global engineering departments on a regularly scheduled basis to share the security roadmap and best practices. • Represent the application security and AI security programs to senior leadership and in audit/compliance contexts (SOC 2, ISO 27001, NIST CSF 2.0).

Benefits

• DV protects the integrity of digital advertising for the world's biggest brands. Securing the applications, APIs, pipelines, and AI systems behind that mission directly protects DV's customers, revenue, and reputation. You'll have executive support, real budget, modern tooling, and the mandate to build a best-in-class Application, AI, and Security Engineering program.

Apply in one click

Upload My Resume

Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT

Apply in One Click
Apply in One Click

Similar roles

ProsperProsper - Sr. Manager, Application Security3mo ago
·Remote - United States·$226k - $270k/year + Equity
RemoteNASeniorInsuranceCybersecurityFintechApplication Security EngineerSecurity Management SpecialistHead of Information SecurityTeam ManagementPerformance ReviewsGCPPhoenixReporting
horizon3aihorizon3ai - Manager, Security Engineering, Cloud & AppSec2mo ago
·United States - Hybrid·$150k - $185k/year + Equity
In OfficeNASeniorCybersecurityCloud ComputingApplication Security EngineerReportingAWSTerraformAzureGCP
ClickHouseClickHouse - Manager, Information Security1w ago
·United States·$208k - $208k/year + Equity
In OfficeNASeniorCybersecurityCloud ComputingSecurity Management SpecialistAWSGCPAzureProcurement
Zeta GlobalZeta Global - Lead Application Security Engineer1w ago
·Remote - USA·$140k - $180k/year + Equity
RemoteNAStaffCybersecurityCloud ComputingApplication Security EngineerReactDjangoNode.jsFastAPIAWSGCPAzureDockerKubernetesGovernanceWagmiDocumentationCPC
QualiaQualia - Senior Application Security Engineer2mo ago
·Remote - United States of America·$180k - $210k/year + Equity
RemoteNASeniorFintechCloud ComputingApplication Security EngineerReportingAWSDockerKubernetesTerraform
Temporal TechnologiesTemporal Technologies - Senior Application Security Engineer3mo ago
·Remote - United States or Canada - Remote Opportunity·$180k - $225k/year + Equity
RemoteNASeniorCybersecurityArtificial IntelligenceApplication Security EngineerGoPythonKubernetesPlane
Apollo.ioApollo.io - Senior Application Security Engineer1mo ago
·Remote - Canada·$273k - $273k/year + Equity
RemoteNASeniorInsuranceCloud ComputingApplication Security EngineerRubyPythonLinuxGCPPerformance Reviews
ZocdocZocdoc - Application Security Engineer1w ago
·Remote - USA Remote·$100k - $100k/year + Equity
RemoteNASeniorCybersecurityCloud ComputingApplication Security EngineerRecruiterGoJavaPythonJavaScriptTraining DevelopmentMilestone TrackingReportingDocumentationGovernanceAWSGCPAzureGitAppDynamicsBase
Spring HealthSpring Health - Senior Application Security Engineer II1w ago
·Remote - USA·$180k - $206k/year
RemoteNASeniorDigital HealthCloud ComputingApplication Security EngineerGoRubyPythonJavaScriptDocumentationPerformance ReviewsRisk ManagementAWSAzureGCPCross-functional CollaborationPhoenixVector

Browse more by category

Show 71 moreSecurity Management SpecialistShow 50 moreApplication Security EngineerShow 4,717 morePythonShow 2,701 moreTeam ManagementShow 203 moreGoal SettingShow 574 moreTraining DevelopmentShow 1,507 moreKubernetesShow 1,138 moreGCPShow 820 moreTerraformShow 6,420 moreReporting
Privacy·Terms··Contact·FAQ·Wagey on X