Full job description
Lead and evolve DoubleVerify's Secure Software Development Lifecycle (SSDLC), application security, API security, and AI/LLM security programs. Manage security tooling (SAST, SCA, DAST, ASPM), drive OWASP ASVS adoption, SBOM management, and software supply chain security. Partner with DevOps and engineering to embed security in CI/CD pipelines and cloud workloads (GCP, Kubernetes). Lead AI security governance and threat assessment for AI/ML systems, including securing LLM-based applications and AI supply chain. Manage offensive security and penetration testing programs. Recruit and manage a security engineering team, administer budgets, and collaborate cross-functionally with compliance and leadership. Requires 10+ years in information security with 3+ years in management, expertise in application and AI security, cloud security, penetration testing, and proficiency in security automation with Python. Industry certifications preferred. Location: New York City, NY. Salary range: $153,000 - $260,000 plus bonus, equity, and benefits.
What you'll do
- Own and evolve DV's application security program, including SAST, SCA, DAST, and Application Security Posture Management (ASPM) tooling
- Drive OWASP Application Security Verification Standard (ASVS) adoption program across engineering repositories
- Drive SBOM management, license compliance, and software supply chain security practices across development teams
- Partner with DevOps and engineering to embed security across the CI/CD pipeline and Secure SDLC (SSDLC)
- Develop and maintain application security metrics and reporting for engineering leadership
- Lead bi-weekly vulnerability remediation touchpoints and monthly Application Security Leadership Forums
- Oversee DV's API security program and attack surface management capabilities
- Assist with Web Application Firewall (WAF) configuration, deployment, and monitoring
- Partner with DevOps/SRE on cloud and container security to deliver code-to-cloud coverage
- Lead AI security governance, engineering, and threat assessment functions across DV's AI/ML ecosystem
- Secure AI agents, LLM-based applications, MCP gateway, and agentic SDLC workflows against threats
- Evaluate and operationalize AI security platforms for detection, response, and AI supply chain governance
- Build threat models and controls for first- and third-party AI/ML workloads
- Advance AI-assisted security testing to scale coverage across teams
- Lead DV's offensive security and penetration testing program
- Build and maintain security automation capabilities
- Partner with DevOps and CloudOps on cloud security, shared responsibility model, and infrastructure-as-code security
- Own and conduct threat modeling for DV products and infrastructure
- Deliver secure coding training and developer enablement programs across global engineering teams
- Recruit, onboard, and manage a team of security engineers and contractors
- Set goals, track performance, and provide ongoing coaching and mentorship
- Administer budgets, vendor relationships, and tool procurement within the security engineering function
- Collaborate cross-functionally with GRC, Security Operations, IT Security, Legal, and Privacy teams
- Meet regularly with senior leadership, engineering managers, and developers to share security roadmap and best practices
- Represent application security and AI security programs to senior leadership and in audit/compliance contexts
Requirements
- 10+ years of progressive experience in information security, with at least 3 years in a technical management or lead role
- Demonstrated expertise in two or more of the following domains: application security, AI/ML security, software supply chain security, penetration testing, cloud security
- Hands-on experience with AppSec tooling such as SAST, SCA, DAST, ASPM platforms (e.g., Ox Security, Snyk, Veracode, Checkmarx) and API security
- Experience securing AI/ML systems, including familiarity with the OWASP Top 10 for LLMs, NIST AI RMF, agent architectures, and LLM attack vectors
- Proficiency in cloud-native environments, particularly GCP; experience with Kubernetes and infrastructure-as-code (e.g., Terraform) is highly desirable
- Experience managing or directly executing penetration testing programs (web, API, cloud, AI) and bug bounty programs
- Familiarity with DevSecOps principles and integrating security into CI/CD pipelines (GitLab/GitHub/GitOps/ArgoCD)
- Strong understanding of software supply chain security: SBOM, license compliance, OSV/CVE triage, and dependency chain risk
- Experience collaborating with compliance and audit programs (SOC 2, ISO 27001) from a security engineering perspective
- Excellent written and verbal communication skills with demonstrated ability to present complex security topics to both technical and non-technical audiences
- Proficiency in at least one scripting/programming language (e.g., Python) for security automation
- Industry certification preferred (CISSP, CSSLP, GWAPT, OSCP, or equivalent)
- Bachelor's degree or higher in Computer Science, Information Systems, or a related field, or equivalent technical experience
Tech stack
SASTSCADASTASPMOx SecuritySnykVeracodeCheckmarxAPI securityAI/ML securityGCPKubernetesTerraformGitLabGitHubGitOpsArgoCDPython
Benefits
Bonus/commission (as applicable)EquityBenefits (unspecified)