Simpson Thacher & Bartlett is seeking a Senior Manager, Application Security to define, lead, and operationalize the application security program across internally developed applications, SaaS platforms, APIs, databases, generative AI platforms, and emerging architectures. This role partners closely with engineering, cloud, and platform teams to embed security into the software development lifecycle and support secure delivery at scale.
Location: New York, NY (onsite)
Compensation: USD 190,000 - 220,000 per year (NY only). Base salary may vary based on qualifications, experience, education, certifications, and other factors.
What you will do
- Develop, execute, and continuously mature the enterprise application security strategy aligned to industry best practices, regulatory requirements, and client contractual obligations.
- Define and maintain secure application development standards for internally developed software, third-party applications, APIs, SaaS platforms, and containerized workloads.
- Set minimum security requirements for authentication, authorization, encryption, secrets handling, and data protection.
- Define, maintain, and enforce secure SDLC and DevSecOps standards across development teams.
- Integrate application security controls into CI/CD pipelines, developer platforms, and engineering workflows with an emphasis on automation and scalability.
- Work with Application Engineering and DevOps teams to embed automated security testing and preventive controls while maintaining security ownership of policy and enforcement.
- Evaluate, select, implement, and manage the application security tooling lifecycle, including SAST, DAST, SCA, API security testing, container image scanning and registry security, Kubernetes security and runtime protection, and software supply chain security tooling.
- Design integrations between security tools and developer workflows to reduce friction and improve adoption.
- Build automation for security operations such as orchestrated automated security testing, vulnerability triage and prioritization workflows, developer feedback loops with ticketing integrations, exception handling and risk acceptance workflows, and security metrics with pipeline telemetry.
- Identify and assess application security risks, including vulnerable dependencies, insecure authentication patterns, data exposure risks, and insecure configuration.
- Support threat modeling, architecture reviews, and secure design assessments for high-risk or business-critical applications.
- Support security review, onboarding, and ongoing risk management for third-party and SaaS applications.
- Develop metrics, dashboards, and reporting to measure application security posture, testing coverage, and vulnerability remediation effectiveness.
- Provide application security subject matter expertise during security incidents, investigations, and post-incident remediation.
- Lead, mentor, and develop a team of application security engineers, fostering technical depth and career growth.
- Partner with engineering leadership to drive secure-by-design development practices and shared accountability for risk reduction.
- Communicate security risks, tradeoffs, and recommendations to technical and executive stakeholders, and promote a developer-friendly security culture focused on automation, guardrails, measurable risk reduction, and engineering velocity.
- Stay current on emerging application threats, attack techniques, and defensive technologies to continuously improve program effectiveness.
What you bring
- Bachelor’s degree in information security, IT, risk management, related discipline, or equivalent experience.
- Professional certifications such as CISSP, CISM, or similar.
- 10+ years of progressive experience in application security, product security, or software security engineering roles.
- Hands-on experience securing modern application ecosystems, including web applications, APIs, microservices, cloud-native workloads, containers, and Kubernetes platforms.
- Demonstrated success building, scaling, and operating enterprise-grade application security programs within large, complex organizations, preferably in hybrid environments (on-premises, multi-cloud, Kubernetes, and SaaS).
- Experience partnering with application, DevOps, and platform engineering teams to design and implement security controls that scale without slowing developer velocity.
- Hands-on experience implementing and operationalizing enterprise application security tooling and integrating controls into CI/CD pipelines and developer workflows.
- Secure SDLC principles and DevSecOps integration patterns.
- Application security testing methodologies and tooling (SAST, DAST, SCA, API testing).
- Container security concepts, including image hardening, vulnerability scanning, secure registries, and container lifecycle management.
- Cloud-native application security concepts and software supply chain security principles.
- Security automation and scripting (Python, PowerShell, or similar) plus CI/CD security integration patterns.
- Ability to lead, mentor, and develop high-performing application security or product security engineering teams.
- Strong program and project management capabilities with a track record of delivering complex cross-functional initiatives on time and within budget.
- Experience operating within global organizations and collaborating across diverse geographies, cultures, and business units.
- Proven ability to manage third-party vendors and security technology providers, including evaluation, onboarding, delivery oversight, and performance management.
- Strong interpersonal and collaboration skills, including regular engagement with senior leadership and key internal and external stakeholders.
- Excellent executive communication and presentation skills to articulate risk, strategy, and technical concepts to technical and non-technical audiences.
- Ability to manage multiple concurrent priorities, exercise sound judgment, and allocate time and resources in a fast-paced environment, including working effectively amid ambiguity and incomplete information.
- Continuous learning mindset and passion for innovation, automation, and continuous improvement in application security processes.
Tools and technologies you may work with
CISSP, CISM, SAST, DAST, SCA, API testing, Python, PowerShell, Kubernetes
Notes
- Simpson Thacher will not sponsor applicants for work visas for this position.
- This role is exempt and not overtime pay eligible.
For information about how Simpson Thacher & Bartlett LLP collects and processes your personal information, please refer to their Privacy Notice available at https://www.stblaw.com/other/privacy-notice.