Application Security Manager
Job Description
Copart is seeking an Application Security Manager to lead AppSec strategy, improve software delivery security, and support a globally distributed team.
Responsibilities
- Own the AppSec strategy, roadmap, day-to-day operations, and team objectives.
- Measure and report program maturity, risks, and trends to security and technology leadership.
- Recruit, lead, and mentor a globally distributed application security team; provide technical guidance to engineers.
- Partner with Development, DevOps, Architecture, Infrastructure, and other technology teams.
- Lead security reviews and threat modeling for AI-enabled applications, agents, models, APIs, data integrations, and supporting pipelines.
- Perform technical security assessments, code audits, and architectural design reviews.
- Support SDLC and agile teams with application security testing.
- Build security automation to reduce risk across the organization.
- Improve developer security enablement, secure-coding education, and Security Champion programming to increase engineering ownership of application risk.
- Provide AppSec support during security incidents and high-severity production events.
- Integrate and automate application security controls, findings, workflows, and reporting across the software delivery lifecycle.
Requirements
- BS in Computer Science, Cybersecurity, Engineering, or a related discipline (or equivalent practical experience).
- 5+ years progressive cybersecurity experience, including 3+ years focused on application or product security.
- 2+ years direct people-management experience.
- Relevant certification preferred: OSCP, CSSLP, CISSP, GIAC, or cloud-security certifications.
- Strong knowledge of OWASP Top 10 and ability to communicate secure methods and techniques to development teams.
- Proven experience leading application security professionals, technical programs, or cross-functional security initiatives.
- Experience implementing security automation in modern environments including source control, CI/CD, cloud-native, and infrastructure-as-code.
- Experience with Java, Python, and JavaScript.
- Experience with application security capabilities including SAST, DAST, IAST, SCA, secrets detection, ASPM, API security, container security, WAF/CDN controls, and penetration testing platforms.
- Hands-on experience with secure code review, threat modeling, architectural assessments, penetration testing, and application-security automation.
- Experience with threat modeling methodologies such as STRIDE.
Technology Stack
- Java
- Python
- JavaScript
- OWASP Top 10
- SAST, DAST, IAST, SCA
- Secrets detection
- ASPM
- API security
- Container security
- WAF/CDN
- STRIDE
- CI/CD
Benefits
- Medical/Dental/Vision
- 401k plus a company match
- ESPP - Employee Stock Purchase Plan
- EAP - Employee Assistance Program (no cost to you)
- Vacation & Sick pay
- Paid Company Holidays
- Life and AD&D Insurance
- Discounts
Location and Work Setup
- Dallas, TX
- Onsite
E-Verify
- Copart participates in the Department of Homeland Security U.S. Citizenship and Immigration Services' E-Verify program (for U.S. applicants and employees only).
- Right to Work
Similar Jobs
A