Overview
We are looking for a hands-on Director, Application Security Engineering to strengthen our cybersecurity posture and partner directly with teams building software across web, mobile, data, and AI-enabled workflows. This role will embed security into delivery practices, improve how we prevent and remediate risk, and communicate clearly with both technical and non-technical stakeholders.
This Director will work across software engineering, platform, DevOps, architecture, QA, infrastructure, compliance, and security teams to mature secure SDLC (i.e., SSDLC) practices, expand developer-friendly guardrails, and improve application and agent security. They should be comfortable moving between code review, tooling configuration, threat modeling, vulnerability management, automation, security enablement, and emerging AI security considerations. This is a hybrid role (3 days/week in-office). Preference given to candidates near a TKO office, including NYC, Stamford, Orlando, Austin, or Las Vegas.
The Role and What You’ll Do
The Director, Application Security Engineering will:
- Own and evolve application security practices across the SSDLC, emphasizing scalable, developer-aligned, shift-left controls
- Operate and improve SAST, SCA, secret scanning, code scanning, repository protections, and related controls across repositories and CI/CD pipelines
- Develop secure development enablement for citizen developers, vibe coding, and AI-assisted development, including practical guidance for tooling, code assurance, identity, observability, and enterprise standards
- Review application and code-level vulnerabilities, validate findings, reduce noise, and drive risk-based remediation plans
- Conduct threat modeling and security design reviews for new systems, major changes, integrations, APIs, and high-risk workflows
- Advise teams on secure coding, authentication and authorization, session management, secrets handling, logging, encryption, dependency hygiene, and data protection
- Improve security guardrails for build pipelines, containers, APIs, third-party components, and deployment practices across modern and legacy environments
- Mature risk-based vulnerability management across intake, validation, prioritization, remediation guidance, exception handling, and reporting
- Support secure adoption of AI-assisted development and agentic systems by assessing trust boundaries, data exposure paths, prompt and tool-invocation risks, and misuse scenarios
- Develop pragmatic standards, playbooks, reference architectures, documentation, and office-hour support that improve consistency without slowing teams down unnecessarily
- Track recurring weaknesses, recommend structural fixes, and help leadership understand where engineering investment will reduce risk most effectively