CybersecurityJobs.io
← Back to all jobs

Job Description

The Sr. Manager, DevSecOps and Application Security leads Imprivata’s unified DevSecOps and application security function, embedding security across the software and infrastructure lifecycle from design through retirement. This hybrid role is based in Saint Petersburg, FL and spans cloud, on-premises, and agentic AI environments.

Role Overview

In this position, you will manage the DevSecOps and Application Security team and partner across Engineering, Product, IT, Cloud and Infrastructure, Quality, SecOps, GRC, and Architecture. The role supports secure development and delivery across cloud, on-premises, hybrid, API, traditional software, and agentic AI contexts.

Key Responsibilities

  • Lead, coach, and develop the DevSecOps and Application Security team by setting clear goals, performance expectations, and growth opportunities.
  • Drive the transition of DevSecOps and Application Security into the Security organization, covering operating model, staffing, governance, processes, tools, and stakeholder communications.
  • Own the program strategy and roadmap, including staffing plan, vendor relationships, tooling decisions, budget recommendations, intake processes, service expectations, and escalation paths.
  • Establish security-by-design practices, including threat modeling, architecture reviews, policy-as-code, reusable engineering patterns, developer guidance, and security training across the development lifecycle.
  • Advance application security through secure design and code reviews, security testing, penetration testing, bug bounty intake, vulnerability management, and risk-based remediation.
  • Implement and govern security controls such as SAST, DAST, SCA, secrets detection, container and image scanning, infrastructure-as-code scanning, API testing, and license analysis with risk-based pipeline controls.
  • Strengthen software supply-chain and platform security by protecting repositories, build systems, deployment identities, credentials, release artifacts, cloud services, and on-premises infrastructure.
  • Address security risks tied to agentic AI and Model Context Protocol servers and clients, partnering with SecOps on monitoring, incident response, tabletop exercises, and post-incident reviews.
  • Set ownership, severity criteria, remediation expectations, exception processes, executive reporting, and metrics for security findings and program performance.
  • Perform other duties as assigned and required.

Minimum Requirements

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent practical experience.
  • 7+ years of experience in DevOps, cloud engineering, software engineering, application security, infrastructure security, or a related discipline.
  • 3+ years leading, managing, or mentoring security engineering, DevSecOps, or AppSec professionals, including experience building or maturing programs across multiple products or engineering organizations.
  • Experience embedding security into CI/CD pipelines and software development workflows across cloud platforms and infrastructure as code, containers, Kubernetes, Git-based source control, and CI/CD platforms such as GitHub Actions, GitLab, or Jenkins.
  • Experience with SAST, DAST, SCA, secrets detection, container security, IaC security, vulnerability management, threat modeling, and secure software supply-chain practices.
  • Strong scripting or programming experience, and working knowledge of IAM, least privilege, authentication, authorization, encryption, certificates, logging, and secure network design.
  • Ability to recruit, develop, motivate, and retain technical talent, and translate technical risk for engineers, architects, executives, auditors, and nontechnical stakeholders.

Tools and Technologies

  • CI/CD, Infrastructure as code, containers, Kubernetes
  • GitHub Actions, GitLab, Jenkins
  • SAST, DAST, SCA, secrets detection
  • infrastructure-as-code scanning, API testing, license analysis
  • policy-as-code
  • Model Context Protocol

Desired Qualifications

  • Experience securing healthcare, financial services, government, or other regulated-industry products, including SaaS, on-premises, hybrid, virtualized, or customer-managed deployments.
  • Experience with identity security, zero trust, SBOMs, SLSA, Sigstore, artifact signing, provenance, policy-as-code, APIs, microservices, serverless, mobile, endpoint software, or agentic AI security.
  • Experience integrating security tools with Jira, ServiceNow, GitHub, GitLab, SIEM, CNAPP, vulnerability management, or GRC platforms.
  • Familiarity with STRIDE, PASTA, attack trees, or other threat-modeling methods; relevant certifications such as CISSP, CCSP, CSSLP, AWS Security Specialty, or equivalent.

Compensation

This position offers a total compensation range of $184,000.00 to $227,700.00 per year, inclusive of base salary and variable compensation such as bonuses and incentives.

Similar Jobs