AVP, Application Security
$185,400–$375,950 year
RemoteUnited States or Rhode Island, United States
Job Summary
Define and own the enterprise application security strategy, roadmap, and policy framework aligned with business objectives and regulatory obligations. Establish technical standards for secure software development, including code scanning, vulnerability management, and secure-by-design principles. Lead integration of SAST, DAST, and SCA controls into CI/CD pipelines while managing an enterprise WAF platform and repository scanning for secrets and misconfigurations. Govern AI-assisted code generation security and oversee software composition analysis to protect the supply chain. Build and lead a high-performing team of security engineers and architects, partnering with Developer Experience to embed security seamlessly into agile practices. Serve as a trusted advisor to executive stakeholders on emerging risks and industry best practices. Drive continuous program improvement through metrics, benchmarking, and innovation to ensure security enables innovation rather than hindering it.
Required Qualifications
- 12+ years of progressive experience in information security
- At least 5 years in application security leadership roles
- Deep technical background in software development
- Hands-on coding experience in one or more modern programming languages (e.g., Java, Python, Go, JavaScript, or similar)
- Developer-level fluency to credibly engage with engineering teams, evaluate code-level risks, and drive meaningful secure coding practices
- Demonstrated expertise in application security engineering and secure software development lifecycle (SDLC) practices
- First-hand experience building or shipping software
- Strong understanding of software architecture patterns, CI/CD pipelines, containerization, and cloud-native development
- Ability to assess security implications at every layer of the stack
- Hands-on experience managing enterprise application security tooling, including SAST, DAST, SCA, WAF, and repository scanning platforms
- Deep knowledge of application security standards and frameworks, including OWASP Top 10, NIST SSDF, and relevant regulatory requirements (HIPAA, PCI-DSS, CCPA)
- Proven ability to influence engineering culture and drive security adoption at scale within agile development environments
- Strong leadership skills with experience building and managing cross-functional technical teams and influencing senior stakeholders
- Excellent communication and presentation skills
- Ability to translate complex security concepts for both technical and non-technical audiences
- Bachelor's Degree
Desired Qualifications
- Advanced degree in Computer Science, Information Security, or a related field
- Certifications such as CISSP, CSSLP, CISM, GWEB, or equivalent
- Experience in healthcare or other highly regulated industries
- Familiarity with AI/ML-driven security tooling and modern cloud-native application security architectures
- Experience implementing security programs within large-scale DevOps or platform engineering organizations
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.