Sr. Manager, Application Security
Manager
Senior
Application Security
Cybersecurity Tools
DevSecOps
Dynamic Application Security Testing
Enterprise Risk
Information Security
Information Technology (IT)
InfoSec
Management
Owasp
Risk Governance
Risk Management
Security Automation
Security Compliance
Security Operations
Security Testing
Software Security
Strategic Advisory
Vulnerability Management
Job Description
The Senior Manager of Application Security leads AppSec operations and programs, partnering with the Director to scale delivery, align with Security Architecture, and advance AppSec priorities across the organization.
Responsibilities
- Oversee day-to-day operations of AppSec programs
- Collaborate on strategy formulation and implementation
- Strengthen integration between Security Engineering and AppSec
- Drive prioritization frameworks aligned with enterprise objectives
- Establish repeatable, automated AppSec processes
- Represent AppSec in cross-functional governance forums
- Increase automation and repeatability; shift tooling integration left
- Establish clear metrics and reporting across operational, security, and strategic perspectives
- Lead initiatives for secure open source usage and artifact management
Requirements
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science or related field, or equivalent experience/certification
- 7+ years in Information Technology or Security, including:
- 4+ years in information security leadership
- 2+ years as a security team lead or manager responsible for security assessments, risk management, and compliance for production systems
- 2+ years in software or system release management with a focus on security validation
- Expertise across AppSec testing modalities such as SAST, DAST, and IAST
- Experience with SCA SDLC tooling and repository integration
- Proficiency with GitHub, JIRA, ServiceNow, Jenkins, and Harness
- Strong understanding of OWASP and MITRE CVE/CWE
- Ability to drive cross-functional workflow integration and prioritization
Technologies
- GitHub, JIRA, ServiceNow, Jenkins, Harness
- SAST, DAST, IAST
- SCA tooling, OWASP, MITRE CVE/CWE
Benefits
- 401(k) plan
- Stock purchase plan
- Discounts at Marriott properties
- Commuter benefits
- Employee assistance plan
- Childcare discounts
- Medical insurance
- Dental insurance
- Vision coverage
- Health care flexible spending account
- Dependent care flexible spending account
- Life insurance
- Disability insurance
- Accident insurance
- Adoption expense reimbursements
- Paid parental leave
- Educational assistance
Additional Information
- Bethesda, MD Pay Range: $110,400-$190,000 annually
- Remote Pay Range: $100,400-$173,000 annually
- Job Number: 26088361
- Job Category: Information Technology
- Location: 7750 Wisconsin Ave, Bethesda, Maryland, United States, 20814
- Schedule: Full Time
- Located Remotely?: Y
- Position Type: Management
- Bonus Eligible: Y
- Expiration Date: 08/13/2026
Technical Oversight
- Monitor and assess application security risks
- Develop and track security metrics
- Recommend mitigation strategies
- Provide technical leadership regarding tooling integration, process definition, and execution
Stakeholder Alignment & Communication
- Ensure AppSec work is well communicated and visible
- Deliver concise reporting to stakeholders
- Mentor AppSec team members
- Translate complex technical concepts for non-technical audiences
Managing Work, Projects, and Policies
- Coordinate and implement work and projects as assigned
- Provide accurate and timely results through reports and presentations
- Analyze information and evaluate results to identify best solutions
- Develop goals and plans to prioritize, organize, and complete work
- Set and track progress for self and others
- Monitor the work of others to ensure timely delivery and quality
- Guide other units on policies and procedures and optimize resource use
Success Measures (First 12 Months)
- Improved Security Architecture and AppSec workflow integration
- Increased automation and repeatability
- Clear metrics for operational, security and strategic reporting
- Clear work prioritization
- Enhanced visibility and transparency of AppSec processes, execution and deliverables