Application Security Manager
External job listingat Alter Domus
Lead and scale Alter Domus’s Application Security program, embedding security into development through threat modeling, automation, and code reviews.
Salary
Not provided
Location
Chicago, United States
Employment type
Full time
Workplace
Not provided
Application Security Manager
Chicago, United States
Job description
About the role
Alter Domus is looking for an Application Security Manager to lead and scale its Application Security program. Reporting to the Global Head of Security, you will connect Engineering and Security by embedding security into how teams build.
The role calls for empathy for developers and an understanding of their tools and workflows. It emphasizes automation and actionable guidance, and includes threat modeling, code reviews, CI/CD integrations, and a Security Champions program.
Responsibilities
- Lead secure design reviews and threat modeling to surface risks early in the development lifecycle.
- Deploy and operationalize SAST, DAST, SCA, and secrets scanning across repositories and pipelines.
- Partner with the Platform DevOps team to build and maintain security automation that embeds inline checks into CI/CD pipelines.
- Help architect secure-by-default frameworks, workflows, and reusable patterns for engineering teams.
- Conduct application security code reviews and provide clear, developer-friendly remediation guidance aligned with secure coding practices.
Key facts
- The role leads and scales the Application Security program.
- It reports to the Global Head of Security.
- Responsibilities include threat modeling, security scanning, CI/CD automation, and application security code reviews.
Is this your job posting?
Claim it for free and receive video applications on CazVid.
Frequently asked questions
What does the Application Security Manager do?
The role leads and scales the Application Security program and embeds security into how teams build.
What security work is included in the role?
The responsibilities include secure design reviews, threat modeling, SAST, DAST, SCA, secrets scanning, CI/CD security automation, and application security code reviews.
Who does the role work with?
The role connects Engineering and Security and partners with the Platform DevOps team.