Capital One is building security products that help protect applications at enterprise scale. In this onsite role in McLean, VA, you will own the Application Security (AppSec) product strategy, governance, and risk transformation, shaping how security capabilities align with the evolving threat landscape. You will also work across teams to evaluate tools, define AI-application security direction, and communicate risk clearly to stakeholders across the organization.
Salary: USD 229,900 - 262,400 per year (location-based). Incentives: performance-based incentive compensation may include cash bonus(es) and/or long term incentives (LTI).
Responsibilities
- Own the multi-year Application Security product roadmap, aligning deliverables with enterprise risk appetites and changing threat conditions.
- Serve as the primary liaison to Security Engineering Enablement and Architecture to translate security requirements into scalable, fix-first developer workflows.
- Lead the strategic evaluation of AppSec security tools (SAST/DAST/SCA) to maximize ROI and maintain a best-in-class toolset.
- Define the product strategy for AI-application security, including secure integration of AI agents into the SDLC, prompt engineering guardrails, and automated remediation pipelines.
- Drive AppSec adoption through Office Hours and community forums, simplifying complex technical risks for executive leadership to support informed decision-making.
- Establish the governance model for vulnerability disposition across SAST/DAST/OffSec, with clear SLAs, audit trails, and exception workflows that support velocity.
Requirements
- Bachelor's Degree
- 7+ years of experience in cybersecurity or information technology
- 6+ years evaluating, contributing to, or supporting development of cybersecurity capabilities
- 3+ years of application security experience
Preferred Qualifications
- 7+ years working on teams and presenting cybersecurity information (metrics, threat intelligence, controls, and/or requirements) to stakeholders
- 3+ years developing or interpreting cybersecurity metrics or dashboards
- 3+ years of people management experience
- 2+ years developing or overseeing cybersecurity or technology risk programs
- Familiarity with industry governance or financial governance processes
- Ability to perform security incident analysis and assist with resolution, translating technical findings into clear, actionable reports for technical and non-technical stakeholders
- 4+ years in Application or Product Security or Software Engineering with emphasis on AppSec and vulnerability management strategy
- 4+ years managing AppSec products in a large-scale enterprise
- 2+ years defining standards for AI-augmented development and ethical AI usage
- Professional certifications: CISSP, CISM, OSCP
- 2+ years experience in cloud-native environments (APIs, Web, Mobile, Containers, IaC, and CI/CD)
- Knowledge of OWASP Top 10 and software supply chain security
- Experience with automated DAST and manual Penetration Testing to build adversarial-based threat prevention roadmaps
Technologies
- SAST, DAST, SCA, OffSec, SDLC
Work Authorization Notice: Capital One will not sponsor a new applicant for employment authorization, or offer immigration-related support for this position (including H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-3, O-1, or any other forms of work authorization requiring employer immigration support).
Other Details: No agencies please. Capital One is an equal opportunity employer (EOE, including disability/veteran), committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Candidates should apply within a minimum of 5 business days. Capital One offers comprehensive, competitive, and inclusive health, financial, and other benefits to support your total well-being.