Lead and evolve DoubleVerify's Secure Software Development Lifecycle, application, API, and AI/LLM security programs. Manage security tooling (SAST, SCA, DAST, ASPM), OWASP ASVS adoption, SBOM and software supply chain security, cloud and container security (GCP, Kubernetes), and offensive security including penetration testing. Lead AI security governance and threat assessments for AI/ML systems. Develop security metrics, conduct threat modeling, and deliver secure coding training. Manage a team of security engineers, administer budgets, and collaborate cross-functionally with compliance and audit teams. Requires 10+ years in information security with 3+ years in technical management, expertise in multiple security domains, proficiency with security tools and cloud environments, scripting skills, and preferred industry certifications. Location: New York, NY.
What you'll do
Own and evolve application security program including SAST, SCA, DAST, ASPM tooling
Drive OWASP ASVS adoption across engineering repositories
Similar jobs
More roles worth a look
Related opportunities based on specialty and working model so candidates can keep momentum.
Manage SBOM, license compliance, and software supply chain security practices
Embed security across CI/CD pipeline and Secure SDLC
Develop and maintain application security metrics and reporting
Lead vulnerability remediation meetings and Application Security Leadership Forums
Oversee API security program and attack surface management
Assist with WAF configuration, deployment, and monitoring
Partner on cloud and container security to deliver code-to-cloud coverage
Lead AI security governance, engineering, and threat assessment across AI/ML ecosystem
Secure AI agents, LLM-based applications, and agentic SDLC workflows against threats
Evaluate and operationalize AI security platforms for detection, response, and governance
Build threat models and controls for AI/ML workloads including data pipelines and RAG architectures
Advance AI-assisted security testing to scale coverage
Lead offensive security and penetration testing programs
Build and maintain security automation capabilities
Partner with DevOps and CloudOps on cloud security and infrastructure-as-code security
Own and conduct threat modeling for products and infrastructure
Deliver secure coding training and developer enablement programs
Recruit, onboard, and manage security engineers and contractors
Set goals, track performance, and provide coaching and mentorship
Administer budgets, vendor relationships, and tool procurement
Collaborate cross-functionally with GRC, Security Operations, IT Security, Legal, and Privacy teams
Meet regularly with senior leadership and engineering managers to share security roadmap
Represent application and AI security programs to senior leadership and in audit/compliance contexts
Requirements
10+ years of progressive experience in information security, with at least 3 years in a technical management or lead role
Expertise in two or more domains: application security, AI/ML security, software supply chain security, penetration testing, cloud security
Hands-on experience with AppSec tooling such as SAST, SCA, DAST, ASPM platforms and API security
Experience securing AI/ML systems including OWASP Top 10 for LLMs, NIST AI RMF, agent architectures, and LLM attack vectors
Proficiency in cloud-native environments, particularly GCP; experience with Kubernetes and infrastructure-as-code (Terraform) highly desirable
Experience managing or executing penetration testing programs and bug bounty programs
Familiarity with DevSecOps principles and integrating security into CI/CD pipelines
Strong understanding of software supply chain security including SBOM, license compliance, OSV/CVE triage, dependency chain risk
Experience collaborating with compliance and audit programs (SOC 2, ISO 27001) from a security engineering perspective
Excellent written and verbal communication skills for technical and non-technical audiences
Proficiency in at least one scripting/programming language (e.g., Python) for security automation
Industry certification preferred (CISSP, CSSLP, GWAPT, OSCP, or equivalent)
Bachelor's degree or higher in Computer Science, Information Systems, or related field, or equivalent technical experience
Tech stack
SASTSCADASTASPMOx SecuritySnykVeracodeCheckmarxAPI securityOWASP ASVSOWASP API Security Top 10WAFWizAI/ML securityPromptFlowGCPKubernetesTerraformGitLabGitHubGitOpsArgoCDPython
Apply now
Ready to take the next step in your career? Click the button below to continue to the application process.