Director, Application Security
Job Description
Intercontinental Exchange Holdings, Inc. is seeking a Director, Application Security to lead an enterprise AppSec program at scale. This onsite role in Atlanta, GA focuses on building assurance through education, continuous testing, and consultative security guidance across application and cloud environments. You will help shape practical policies, secure design practices, tooling strategy, and a responsible bug bounty program, while guiding two teams and the broader development community.
What you’ll do
- Differentiate legitimate business risk from fear, uncertainty, and doubt, and assign practical severity ratings to vulnerabilities and weaknesses.
- Demonstrate compromise paths for detected vulnerabilities to educate and motivate development teams.
- Adopt and continuously improve an education, testing, and remediation methodology.
- Innovate to ensure program areas operate effectively and distill results into meaningful metrics.
- Codify and communicate Application Security and Cloud Security expectations through writing and discussion.
- Recruit, retain, and motivate a talented staff, balancing efficient task allocation with development, challenge, and growth.
- Run an established enterprise AppSec program supporting 2,000+ applications and a large developer pool.
- Coach and develop team leaders, including newer leadership hires, within a high-performing, well-structured team.
- Maintain commitment to continuous education and serve as a recognized industry leader in Application and Cloud Security.
How the program is managed
- Application Identification and Review: Maintain, execute, and report AppSec assurance activities from design review through operation of a bug bounty program.
- Standards and Policies: Own the Application Development Security Policy, ensuring timely, practical updates, communication, and education.
- Secure Design: Establish security requirements early in the SDLC and provide security subject matter expertise for new projects and releases.
- Tool Management: Implement and maintain cutting-edge technology to assess and protect applications and cloud environments throughout the SDLC and after deployment.
- AI in AppSec: Evaluate and apply AI and machine learning capabilities, including AI-assisted vulnerability detection, AI-powered code review and testing tooling, and securing AI-integrated development pipelines.
- Developer Education: Keep software engineers current on secure coding practices and build strong rapport with ICE’s application development community.
- Cloud Practitioner: Provide security leadership and solutions for business and technical teams building or buying products in the cloud.
- Bug Bounty Program: Operate a responsible disclosure program that incentivizes and supports positive relationships with security researchers.
Requirements
- Bachelor’s degree in Computer Science, Engineering, MIS, CIS, or a related discipline.
- Hands-on or program-level experience applying AI in the AppSec space.
- Software engineering experience in Java, C++, Python, and/or related languages.
- Hands-on experience with information security and related technologies.
Helpful background
- Background in financial services or a comparable regulated enterprise environment.
- Technical expertise and understanding of AWS and/or Azure cloud platforms.
- Participation and leadership in Application Security consortia such as OWASP.
Skills and tools you’ll use
AI, machine learning, Java, C++, Python, AWS, Azure
Similar Jobs
A