CP Axtra logo
CP AxtraPosted 3 weeks ago

Department Manager - Application Security

On-siteBangkok, Bangkok, Thailand

Full TimeLarge

Job Summary

Lead CP Axtra's Application Security program end-to-end, defining secure SDLC policies and managing the SAST, SCA, DAST, and secrets scanning platforms integrated into CI/CD pipelines. Own the toolchain optimization to reduce alert fatigue while driving threat modeling and secure design reviews for high-risk applications. Consult with development teams on vulnerability remediation and enforce security quality gates that balance enforcement with enablement. Manage the Security Manager team and report posture metrics to leadership, while evaluating emerging technologies like AI-assisted code review. Coordinate with the Offensive Security team to align penetration testing priorities with application risk profiles.

Required Qualifications

  • 5+ years in application security — secure SDLC, code review, vulnerability management, or AppSec tooling management
  • Hands-on experience with at least 2 of: SAST, SCA, DAST, or secrets scanning tools (Checkmarx, SonarQube, Snyk, Qualys WAS, or equivalent)
  • Strong understanding of CI/CD pipelines and how to integrate security checks without breaking developer velocity (GitHub Actions, Azure DevOps, Jenkins)
  • Ability to review code for security issues in at least 2 programming languages (Java, Python, JavaScript/TypeScript, Go, or C#)
  • Experience leading or mentoring a team — you'll manage at least one direct report and influence a broader developer community
  • Excellent communication skills — you'll spend significant time consulting with developers who may not have security backgrounds
  • Understanding of OWASP Top 10, SANS Top 25, and modern application attack patterns

Desired Qualifications

  • Experience with container security scanning (Trivy, Prisma Cloud, Aqua) and IaC security (Checkov, tfsec)
  • Background in software development — candidates who've written production code understand developer pain points better
  • Familiarity with AI/LLM security risks and secure development practices for AI-integrated applications
  • CSSLP, GWEB, or CASE certification
  • Experience in retail or e-commerce application security, especially PCI DSS-relevant environments
  • Thai language proficiency for developer training and stakeholder communication

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce