Sr. Application Security Manager
Job Description
Secure development, secure operations, and secure AI systems are built by bringing security into the code-to-cloud lifecycle. In this hybrid role in New York City, you will lead DoubleVerify’s Application and AI Security efforts, evolving core security programs across SSDLC, application and API security, software supply chain risk, and governance for AI/LLM workloads. You will also help scale security impact through automation, metrics, and team enablement, while collaborating with engineering, DevOps/SRE, GRC, Security Operations, IT Security, Legal, and Privacy.
Responsibilities
- Own and evolve the application security program, including SAST, SCA, DAST, and ASPM tooling (for example Ox Security), moving findings from non-blocking warnings toward enforced risk-based merge gates.
- Drive adoption of the OWASP Application Security Verification Standard (ASVS) across engineering repositories, with reporting, dashboards, and branch-level coverage.
- Lead SBOM management, license compliance, and software supply chain security practices across development teams.
- Partner with DevOps and engineering to embed security into CI/CD and the Secure SDLC (SSDLC).
- Develop application security metrics and reporting for leadership, including vulnerability burn-down and mean-time-remediate (MTTR).
- Facilitate bi-weekly vulnerability remediation touchpoints and monthly Application Security Leadership Forums with engineering organizations (Pinnacle, Measurement, Programmatic, Architecture, Publisher, Social, QA, TechOps/SRE, CorpIT, DevOps, and M&A) to drive progress and accountability.
- Oversee the API security program, including OWASP API Security Top 10 (for example Escape API Security) and attack surface management (ASM), including discovery of shadow or zombie APIs.
- Support Web Application Firewall (WAF) configuration, deployment, and monitoring.
- Partner with DevOps/SRE on cloud and container security (for example Wiz) to deliver code-to-cloud coverage.
- Lead AI security governance, engineering, and threat assessment across the AI/ML ecosystem.
- Secure AI agents, LLM-based applications, MCP gateway, and agentic SDLC workflows against threats such as prompt injection, jailbreaking, excessive agency, and supply chain compromise, including guardrails, telemetry, logging, and detections for developer AI tooling (Cursor, Claude Code, VS Code).
- Evaluate and operationalize AI security platforms to provide detection, response, and AI supply chain governance across teams building or operating AI systems (including AI security gateway, shadow-AI discovery/DLP, and AI identity and software management).
- Build threat models and controls for first- and third-party AI/ML workloads, including data pipelines, model provenance, and RAG architectures.
- Advance AI-assisted security testing (including PromptFlow-driven web/API security test generation) to scale security coverage.
- Lead offensive security and penetration testing, partnering with external vendors and conducting internal security assessments.
- Build and maintain security automation capabilities to reduce manual effort and increase detection coverage.
- Collaborate on cloud security execution (primarily GCP and Kubernetes) and infrastructure-as-code security, aligned with the shared responsibility model.
- Own and conduct threat modeling for DV products and infrastructure.
- Deliver secure coding training and developer enablement programs for global engineering teams.
- Recruit, onboard, and manage a team of security engineers and contractors, including software security developers and offensive security testers, with ongoing goals, performance tracking, coaching, and mentorship.
- Administer budgets, vendor relationships, and tool procurement within the security engineering function.
- Collaborate cross-functionally with GRC, Security Operations, IT Security, Legal, and Privacy.
- Present the application security and AI security roadmap and best practices to senior leadership and global engineering managers and developers, including in audit/compliance contexts (SOC 2, ISO 27001, NIST CSF 2.0).
Requirements
- 10+ years of progressive experience in information security, with at least 3 years in a technical management or lead role.
- Demonstrated expertise in two or more of: application security, AI/ML security, software supply chain security, penetration testing, cloud security.
- Hands-on experience with AppSec and application security platforms, including SAST, SCA, DAST, ASPM (for example Ox Security, Snyk, Veracode, Checkmarx), and API security.
- Experience securing AI/ML systems, including familiarity with OWASP Top 10 for LLMs, NIST AI RMF, agent architectures, and LLM attack vectors.
- Proficiency in cloud-native environments, particularly GCP; Kubernetes and infrastructure-as-code (for example Terraform) is highly desirable.
- Experience managing or executing penetration testing programs (web, API, cloud, AI) and bug bounty programs.
- Knowledge of DevSecOps principles and integrating security into CI/CD pipelines (GitLab/GitHub/GitOps/ArgoCD).
- Strong understanding of software supply chain security, including SBOM, license compliance, OSV/CVE triage, and dependency chain risk.
- Experience collaborating with compliance and audit programs (SOC 2, ISO 27001) from a security engineering perspective.
- Excellent written and verbal communication skills with the ability to present security topics to both technical and non-technical audiences.
- Proficiency in at least one scripting or programming language for security automation (for example Python).
Benefits
- Eligible for bonus/commission (as applicable)
- Equity
- Benefits
Work Model and Location
Full-time role based in New York City headquarters offices with a hybrid work model (office and remote).
Compensation
Estimated salary range: $153,000 to $260,000 per year. This role is also eligible for bonus/commission (as applicable), equity, and benefits.