CybersecurityJobs.io
← Back to all jobs

Job Description

Terumo is seeking an IT Application Security Manager to help build a secure software delivery program across the enterprise. This hybrid role in Lakewood, CO sits within Global Cybersecurity and partners with software, cloud, architecture, and infrastructure teams to reduce application security risk while enabling application teams to deliver with confidence.

In this position, you will lead Application Security Analysts, strengthen secure development standards across the SDLC, and oversee testing programs including SAST, DAST, and SCA. Success is measured through security outcomes such as remediation SLA compliance, threat model coverage, and improvements in high-risk application vulnerability reduction.

Responsibilities

  • Collaborate with global and regional leaders to develop and evolve the enterprise Application Security strategy.
  • Lead, mentor, and develop Application Security Analysts.
  • Define AppSec metrics, KPIs, and maturity goals with regional and global security stakeholders.
  • Integrate security throughout the enterprise application portfolio and ensure requirements are included during design and architecture reviews.
  • Promote security-by-design principles across application teams.
  • Manage and oversee security testing and analysis activities, including SAST, DAST, SCA, IAST, API Security Testing, Container Security, Infrastructure as Code (IaC) Security, Mobile Application Security Testing, and Secrets Detection.
  • Review findings, prioritize remediation, and validate fixes; use risk-based methodologies to guide remediation decisions.
  • Track remediation SLAs, coordinate penetration testing remediation activities, and report vulnerability metrics to executive leadership.
  • Assist with Supply Chain Security and facilitate threat modeling sessions with development teams.
  • Identify abuse cases and attack paths, recommend architectural improvements, and ensure high-risk applications receive formal security architecture reviews.
  • Establish and run application vulnerability management processes, including processes for monitoring, coaching, and secure standards.
  • Support secure development in cloud platforms including AWS, Microsoft Azure, and Google Cloud Platform.
  • Conduct manual secure code reviews and provide secure coding guidance; coach teams on remediation and establish secure rules.
  • Find weak spots through testing and monitor logs to spot shadow APIs and strange traffic patterns.
  • Support training collaboration for OWASP Top 10, Secure Coding, API Security, Cloud Security, common software vulnerabilities, and secure design principles.
  • Perform application security risk assessments and support enterprise application risk management initiatives.
  • Investigate application security incidents, support forensic analysis, identify root causes, lead post-incident reviews, and develop preventive controls to reduce recurrence.
  • Support compliance initiatives aligned to NIST CSF 2.0, NIST SP 800-218 (SSDF), NIST SP 800-53, OWASP ASVS, PCI DSS, HIPAA, SOX, ISO/IEC 27001, and SOC 2.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or related field.
  • Master’s degree preferred.
  • 8–10+ years of cybersecurity experience.
  • 5+ years in Application Security.
  • 3+ years leading security teams.
  • Experience implementing enterprise DevSecOps programs.
  • Experience working with Agile and CI/CD environments.
  • Experience with cloud-native application security.

Tech & Tools

Key frameworks and standards include NIST SP 800-218 (Secure Software Development Framework), NIST Cybersecurity Framework (CSF) 2.0, OWASP, CIS Controls, NIST SP 800-53, OWASP ASVS, OWASP Top 10, as well as compliance considerations such as PCI DSS, HIPAA, SOX, ISO/IEC 27001, and SOC 2. Testing and security disciplines include SAST, DAST, SCA, IAST, IaC, and DevSecOps, with cloud environments across AWS, Microsoft Azure, and Google Cloud Platform.

Benefits

  • 401(k) plan with matching contribution
  • Multiple group medical, dental, and vision plans
  • Robust wellness program
  • Life insurance and disability coverages
  • Vacation and sick time programs
  • Voluntary programs such as group accident, hospital indemnity, critical illness, and pet insurance

Additional Information

  • Employment type: Full-time
  • Department: Global Cybersecurity
  • Role reports to: Security Operations Leader
  • Work arrangement: Hybrid
  • Location: Lakewood, CO (Americas scope, regional)
  • Target pay range: USD 121,400 - 151,800 per year (salary determined based on education, experience, knowledge, skills, abilities, internal equity, and alignment with market data)
  • Target bonus on base: 15.0

Certificates, licenses, registrations: CISSP, CSSLP, GIAC Web Application Penetration Tester (GWAPT), GIAC Secure Software Programmer (GSSP), CCSP, CISM, Microsoft Certified: Cybersecurity Architect Expert, Microsoft Certified: Azure Security Engineer Associate.

Job segments: Testing, Cloud, Developer, Military Intelligence, Computer Science, Technology, Government.

Similar Jobs