Lead AppSec Engineer
Application Security
Automation
Cloud Infrastructure
Cloud Platform
Cloud Platforms
Cloud Technology
Data Security
DevOps
DevSecOps
Engineer
Engineering
Facilities Management
Information Security
Information Technology (IT)
InfoSec
Infrastructure As Code
Management
NIST
Policy As Code
Product Security
Project Management
Risk Management
Security
Security As Code
Security Automation
Security Compliance
Security Operations
Security Standards
Security Testing
Software Security
Technical Lead
Threat Modeling
Vulnerability Management
Job Description
Gartner is seeking a Lead AppSec Engineer to support the organization’s Application Security (AppSec) function. In this hybrid role based in Irving, TX, you will lead day-to-day vulnerability assessment operations, drive risk remediation tracking, and orchestrate security tooling and automation across application and CI/CD workflows.
Key Responsibilities
- Partner with business stakeholders to design secure applications, test for security weaknesses, and coordinate remediation for issues identified through assessment activities.
- Mentor engineers and security champions on practical threat modeling methods.
- Triages and prioritizes security risks, vulnerabilities, and exceptions based on business impact and risk tolerance.
- Coordinate the orchestration, automation, and management of security technologies and platforms used in Gartner environments.
- Own day-to-day life cycle management activities, including identification, threat assessment, threat modeling, and risk avoidance.
- Create clear, reasonable, and actionable reports that demonstrate direct impact to Gartner’s security posture.
- Define and implement meaningful metrics to measure security control effectiveness using KRIs and security scorecards.
- Act as a subject-matter-expert for Application Security and serve as the first point of contact for critical AppSec issues, security risk assessments, and triaging CI/CD security issues with partners and stakeholders.
- Evaluate business and technical requirements to identify and implement tools, processes, and technologies that strengthen security posture in Gartner environments.
- Use data to drive prioritization, highlight systemic security issues, and influence roadmap decisions.
Required Qualifications
- 6-8 years of experience in a Security Engineering role with proven experience in DevSecOps, Cloud Security, and Application Security.
- Strong independent critical thinking and problem-solving skills, with the ability to evaluate and pivot based on current organizational priorities.
- Experience using vulnerability scanning technologies, AST platforms, and cloud security tooling.
- Formal experience with threat modeling.
- Experience leading projects, initiatives, and resources using direct and indirect leadership.
- Deep knowledge of assessing and prioritizing risk, including the ability to think like a bad actor to inform threat models.
- Cloud experience with AWS, Azure, and GCP.
- Familiarity with Infrastructure as Code (IaC) and Policy as Code (PaC) concepts.
- Experience with technical security controls, guidelines, and frameworks such as SOC2, ISO 27001/27013, and NIST 800-53.
- Ability to automate tasks and build code solutions to repetitive problems.
- Scripting or programming experience, including one or more of: Java, .NET, HTML, Ruby, PHP, Perl, C#, Python, JavaScript, PowerShell, Bash.
- Experience with penetration testing and web application assessment.
- Proven communication, collaboration, and critical thinking skills.
- Ability to establish trusting, meaningful relationships with peers, stakeholders, partners, and suppliers.
- Ability to define and communicate risk in business-relevant language to both non-technical and technical audiences.
- Ability to apply expert knowledge to solve complex business and technical issues strategically.
- Desire for life-long learning and continuous personal and professional development.
Tools and Technologies
- DevSecOps; Cloud Security; Application Security
- Vulnerability scanning technologies; AST platforms
- AWS, Azure, GCP
- Infrastructure as Code (IaC); Policy as Code (PaC)
- SOC2; ISO 27001/27013; NIST 800-53
- Java, .NET, HTML, Ruby, PHP, Perl, C#, Python, JavaScript, PowerShell, Bash
Compensation and Work Model
Location: Irving, TX (hybrid). Compensation: USD 116,000 to 170,000 per year. Minimum Experience: 6 years.
Benefits
- Competitive compensation.
- Limitless growth and learning opportunities.
- Ongoing mentorship and apprenticeship, including leadership courses, development programs, technical courses, and certification opportunities.
- A collaborative and positive culture with a diverse team of professionals.
- Opportunity to make an impact that contributes directly to strategy.
- Flexibility to work from home and collaborate in dynamic offices.
- 20+ PTO days plus holidays and floating holidays in your first year.
- Extensive medical, dental insurance, and vision plan.
- 401K with corporate match and immediate vesting.
- Health-and-wellness-related allowance programs.
- Parental leave.
- Tuition reimbursement.
- Employee Stock Purchase Plan.
- Employee Assistance Program.
- Gartner Gives Charity Match.