Sr. Application Security Manager
DoubleVerifyUSA2w ago
Job description
About the role
In this position at DoubleVerify, you will take charge of enhancing and managing the Secure Software Development Lifecycle (SSDLC) alongside application security, API security, and AI/LLM security. As a leader within the InfoSec team, your role will involve collaborating closely with engineering teams to ensure the security of code, pipelines, cloud workloads, APIs, and AI systems. This position expands the responsibilities of the previous Senior Application Security Manager role to formally include oversight of AI security.
Key facts
What you'll do
- Lead the evolution of DoubleVerify's application security program, which encompasses SAST, SCA, DAST, and Application Security Posture Management (ASPM) tools, ensuring that findings transition from non-blocking warnings to enforced, risk-based merge gates.
- Spearhead the adoption of the OWASP Application Security Verification Standard (ASVS) across engineering repositories, including the development of reporting mechanisms, dashboards, and branch-level coverage.
- Manage Software Bill of Materials (SBOM), ensure license compliance, and implement software supply chain security practices across development teams.
- Collaborate with DevOps and engineering teams to integrate security measures throughout the CI/CD pipeline and the Secure Software Development Lifecycle (SSDLC).
- Create and maintain metrics and reports on application security for engineering leadership, focusing on vulnerability resolution rates and mean-time-to-remediate (MTTR).
- Facilitate bi-weekly vulnerability remediation meetings and monthly Application Security Leadership Forums with various engineering teams to promote accountability and progress.
- Oversee the API security program, addressing the OWASP API Security Top 10 and managing attack surface capabilities, including the identification of shadow and zombie APIs.
- Assist in the configuration, deployment, and monitoring of Web Application Firewalls (WAF).
- Partner with DevOps/SRE teams to enhance cloud and container security, ensuring comprehensive code-to-cloud coverage.
- Lead the governance, engineering, and threat assessment functions related to AI security across DoubleVerify's AI/ML ecosystem.
- Secure AI agents and LLM-based applications against various threats, implementing guardrails, telemetry, logging, and detection mechanisms for developer AI tools.
- Evaluate and operationalize AI security platforms to enhance detection and response capabilities across teams working with AI systems.
- Develop threat models and controls for AI/ML workloads, focusing on data pipelines and model provenance.
- Advance AI-assisted security testing initiatives to broaden coverage across teams.
- Manage the offensive security and penetration testing program, collaborating with external vendors and conducting internal assessments.
- Build and maintain automation capabilities to streamline security processes and enhance detection coverage.
- Collaborate with DevOps and CloudOps on cloud security, particularly within GCP/Kubernetes environments, and ensure adherence to shared responsibility models.
- Conduct threat modeling for DoubleVerify's products and infrastructure, delivering secure coding training and developer enablement programs to global engineering teams.
- Recruit, onboard, and lead a team of security engineers and contractors, providing mentorship and performance tracking.
- Manage budgets, vendor relationships, and tool procurement within the security engineering function.
- Work cross-functionally with Governance, Risk, and Compliance (GRC), Security Operations, IT Security, Legal, and Privacy teams to ensure comprehensive security practices.
- Regularly meet with senior leadership and engineering managers to communicate the security roadmap and best practices, representing application security and AI security programs in audit and compliance contexts.
Requirements
- A minimum of 10 years of progressive experience in information security, with at least 3 years in a technical management or leadership role.
- Proven expertise in two or more domains such as application security, AI/ML security, or software supply chain security.
- Strong understanding of security frameworks and standards, including OWASP, SOC 2, ISO 27001, and NIST CSF 2.0.
- Experience with security tools and technologies related to application security, API security, and cloud security.
- Demonstrated ability to lead cross-functional teams and drive security initiatives effectively.
- Excellent communication skills, capable of conveying complex security concepts to technical and non-technical stakeholders.
Nice to have
- Familiarity with security automation tools and practices.
- Experience in conducting security assessments and penetration testing.
- Knowledge of regulatory compliance requirements relevant to information security.
- Background in software development or engineering.
- Certifications in relevant security domains (e.g., CISSP, CISM, CEH).
Skills & tools
- Proficient in security tools such as SAST, DAST, SCA, and ASPM.
- Familiarity with programming languages and development frameworks.
- Experience with cloud platforms, particularly Google Cloud Platform (GCP) and Kubernetes.
- Knowledge of AI security practices and tools.
Practical notes
- This position is based at DoubleVerify's NYC Global HQ.
- The role offers a competitive salary, commensurate with experience.
- Visa sponsorship may be available for qualified candidates.
META
Company: DoubleVerify
Title: Sr. Application Security Manager
Listed
location: NYC Global HQ