Director, Application Security (Cybersecurity Defense)
Api Security
Application Security
Cloud Platforms
Cybersecurity Tools
DevSecOps
Dynamic Application Security Testing
Enterprise Risk
Information Security
Risk Governance
Risk Management
Secure By Design
Security
Security Automation
Security Compliance
Security Testing
Solution Architecture
Static Application Security Testing
Strategic Advisory
Web Application Firewall
Job Description
Lead the enterprise application security strategy across Pharma, Medical, and Commercial Technology segments, embedding security into the SDLC and reducing application risk.
Responsibilities
- Direct the enterprise application security program to align with cybersecurity priorities, risk governance, and business goals.
- Create governance structures to weave security into the software development lifecycle across all app domains.
- Partner with enterprise architecture, engineering, and product teams to synchronize security with technology roadmaps and transformation efforts.
- Provide executive and business leadership with guidance on application security risks, priorities, and funding decisions.
- Foster a secure-by-design mindset across development and engineering groups.
- Oversee application security capabilities across all segments to ensure consistent security practice implementation.
- Define segment-specific requirements and approaches to address regulatory, operational, and risk considerations.
- Maintain alignment of security practices across segments while allowing flexibility for business-specific needs.
- Standardize processes, tooling, and reporting across segment app security teams.
- Manage the organization’s application security testing program, including SAST, DAST, SCA, and IAST across all environments.
- Ensure vulnerabilities are identified, assessed, prioritized, and remediated within the development lifecycle before deployment.
- Establish secure coding standards and integrate security controls into CI/CD pipelines and development workflows.
- Partner with development teams to reduce security technical debt and improve code quality.
- Oversee runtime security controls for applications and APIs, including WAFs, API gateways, and runtime monitoring solutions.
- Embed security requirements into application and API design, deployment, and operations.
- Collaborate with engineering and infrastructure to enforce runtime protections aligned with enterprise architecture.
- Monitor runtime risks and coordinate remediation across application environments.
- Lead development and integration of application security tooling, including configuration, onboarding, and ongoing management.
- Define use cases, policies, and detection logic for app security tools to ensure coverage and scalability.
- Drive integration of application security tools into CI/CD pipelines and DevSecOps workflows.
- Ensure tooling aligns with enterprise security architecture and standards.
- Partner with Security Architecture to establish secure design patterns, reference architectures, and app security standards.
- Incorporate application security requirements into solution design and architecture reviews.
- Work with engineering to implement secure development lifecycle practices and controls.
- Support evaluation of new technologies and architectures to ensure security alignment.
- Ensure app security practices meet regulatory, compliance, and enterprise risk management standards.
- Provide oversight for audits, regulatory assessments, and compliance reporting.
- Collaborate with risk and compliance to translate app security risks into enterprise risk insights.
- Support remediation of identified risks and align with risk tolerance and governance processes.
- Define and track KPIs and KRIs related to app security posture, vulnerability management, and SDLC integration.
- Deliver regular updates to executives on security risks, trends, and program effectiveness.
- Use data analytics to drive ongoing improvement in application security practices and outcomes.
- Identify opportunities to automate, streamline, and scale app security processes.
- Partner with development, product, IT, security operations, and business teams to integrate app security into core enterprise processes.
- Collaborate with Cyber Detection & Response to embed app security findings into monitoring and incident response workflows.
- Coordinate with segment leaders to align app security initiatives with business priorities and risk considerations.
- Support M&A activities by assessing and integrating app security controls for acquired applications.
- Build and lead a high-performing app security organization with expertise in secure development, testing, and runtime protection.
- Ensure the team’s capabilities stay aligned with evolving technologies, threats, and business needs.
Requirements
- 10+ years of cybersecurity experience with emphasis on application security, secure development, or DevSecOps.
- Extensive expertise in SAST, DAST, SCA, and IAST testing methods and secure development practices.
- Solid understanding of application and API security, cloud-native architectures, and modern development frameworks.
- Experience leading enterprise-scale application security programs within large, complex organizations.
- Knowledge of cybersecurity frameworks such as NIST CSF, OWASP, ISO 27001, and relevant regulatory requirements.
- Proven ability to collaborate with cross-functional teams and influence executive leadership.
- Strong leadership, communication, and problem-solving abilities.
Technologies
- SAST
- DAST
- SCA
- IAST
- WAF
- API gateways
- CI/CD pipelines
- DevSecOps workflows
- Runtime monitoring solutions
Benefits
- Medical, dental and vision coverage
- Paid time off plan
- Health savings account (HSA)
- 401k savings plan
- Access to wages before pay day with myFlexPay
- Flexible spending accounts (FSAs)
- Short- and long-term disability coverage
- Work-Life resources
- Paid parental leave
- Healthy lifestyle programs
Location
Cardinal, VA, remote. Open to candidates nationwide with fully remote work; preference for candidates near Central Ohio, with willingness to travel to the Dublin, OH corporate HQ as needed.
Posted
Posted date: 6/03/2026
Salary
135,400.00 - 208,100.00 Annual
Anticipated salary range
$135,400 - $208,100
Bonus eligible
Yes
Application window
Anticipated to close on 07/01/2026; applications encouraged as soon as possible.
Type
Full-time