Senior Manager, Application Security
Job Description
LiveView Technologies seeks a Senior Manager, Application Security to own product security end-to-end across its physical and digital architecture.
Responsibilities
- Directly manage and mentor current AppSec engineers; hire and onboard 1–2 additional security engineers.
- Launch and scale a cross-functional Security Champions program across engineering squads.
- Set architecture and standards for LVT’s full attack surface, spanning a multi-tenant cloud platform, partner APIs, mobile clients, computer vision pipelines, and solar-powered edge firmware.
- Hold a standing seat in product design and planning; convert security risks into prioritized backlog items owned and shipped by engineering teams.
- Make threat modeling a core practice for squads: train teams on fundamentals while staying hands-on for high-stakes system designs and edge or hardware boundaries.
- Define, enforce, and test tenant boundaries across platform services; deploy automated checks to prevent cross-tenant data leaks from reaching production.
- Embed security into CI/CD as code, including SAST, SCA, secrets detection, and IaC policy, with developer feedback in minutes, low noise, and clear build-break rules.
- Partner with hardware and embedded teams on device boot security, signed OTA update pipelines, edge credential management, and threat models assuming physical access.
- Protect AI vision models, prompt boundaries, and data pipelines against abuse with privacy-by-design in a regulated, publicly scrutinized environment.
- Define guardrails for AI coding agent usage so AI-generated code meets standards for safety, testing, and architecture.
- Translate product security controls into audit evidence for SOC 2, GovRAMP, FedRAMP, and CJIS using native engineering workflows instead of manual compliance work.
- Oversee external vulnerability intake, triage, and coordinated disclosure through VDP/bug bounty; lead engineering response to product security incidents.
- Partner with SecOps to instrument telemetry for authorization failures and edge abuse, turning incident learnings into root-cause controls.
Requirements
- 10+ years in AppSec or product security, including significant hands-on engineering time.
- 4+ years as a people manager or formal technical lead.
- Fluency in at least one language in the stack (e.g., Python, Go, TypeScript/Node, C/C++), with ability to build custom automation, tooling, and CI integrations.
- Deep technical grounding in multi-tenant authorization, zero-trust architectures, and API security at scale.
- Familiarity with IoT, embedded platforms, hardware security modules, or OTA update validation, or proven ability to quickly master physical attack surfaces.
- Understanding of model supply chain risks, data handling during inference, and security reviews for AI-augmented features.
- Measures success by coverage, adoption, defect recurrence, and remediation velocity.
- Based onsite at headquarters in American Fork, Utah.
Technologies
- Python, Go, TypeScript/Node, C/C++
- CI/CD, SAST, SCA, IaC
- OTA
- SOC 2, GovRAMP, FedRAMP, CJIS
Benefits
- Comprehensive health, dental and vision coverage
- Retirement benefits (401k match up to 4%)
- Flexible PTO
About this Role
- Application security at LVT is not a late-stage gate; it is built into product delivery.
- LVT operates a multi-tenant cloud platform, AI-driven video analytics, and license plate recognition pipelines.
- Thousands of solar-powered units are deployed across remote utility sites and retail parking lots.
- Reporting to the Director, Security Engineering, you will own product security end-to-end across physical and digital architecture.
- Player-coach scope: manage and mentor existing AppSec engineers, hire 1–2 additional security engineers, and launch a Security Champions program across product teams.
- This role is full-time and in-office out of headquarters in American Fork, Utah.
Ideal Candidate
- Player-coach mindset: 10+ years AppSec or product security with significant hands-on engineering time; 4+ years as a people manager or formal technical lead.
- Engineering empathy: understanding what it takes to ship software.
- Cross-functional influence: ability to drive releases or system architecture changes and secure buy-in without relying on hierarchy.
- Tooling and code fluency: able to write automation, tooling, and CI integrations using a language in the stack.
- AI/ML security literacy: familiarity with model supply chain risks and security reviews for AI-augmented features.
- Metrics-driven approach: distinguishes tools from programs and tracks success via coverage, adoption, defect recurrence, and remediation velocity.
- Bonus points: experience in video streaming, computer vision, or physical safety products; hands-on work in regulated spaces (FedRAMP, GovRAMP, StateRAMP, CJIS); track record scaling a Security Champions program or running a VDP/bug bounty.