Sr. Application Security Manager

DoubleVerify
New York, NY, United States
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$153,000.0 - $260,000.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Artificial Intelligence Application Firewall Software System Penetration Testing Cloud Computing Cloud Computing Security Cyber Security Information Systems Continuous Integration Cursor (Graphical User Interface Elements) DevOps
+31 more
Github Information Security Management Python (Programming Language) Automation of Marketing Open Web Application Security Systems Development Life Cycle Cloud Services Secure Coding Software Project Management Systems Integration Software Vulnerability Management Data Logging Large Language Models Sonatype Software Security Mttr Veracode Gitlab GWAPT Kubernetes Information Technology Machine Learning Operations Checkmarx Terraform Data Pipelines Devsecops Security Orchestration, Automation & Response Static Application Security Testing Vulnerability Analysis BIG‑IP Application Security Manager (ASM) Dynamic Application Security Testing

Job description

As Application & AI Security leadership within DV InfoSec, you will own and evolve DoubleVerify’s Secure Software Development Lifecycle (SSDLC), application security, API security, and AI/LLM security. You will lead the people, processes, and tooling that keep DV’s code, pipelines, cloud workloads, APIs, and AI systems secure, partnering across the engineering organization. (This role replaces and expands the scope of DV’s Senior Application Security Manager position to formally include AI security ownership.), * Own and evolve DV’s application security program, including SAST, SCA, DAST, and Application Security Posture Management (ASPM) tooling (e.g., Ox Security) - advancing findings from non-blocking warnings toward enforced, risk-based merge gates.

  • Drive the OWASP Application Security Verification Standard (ASVS) adoption program across engineering repositories, including reporting, dashboards, and branch-level coverage.
  • Drive SBOM management, license compliance, and software supply chain security practices across development teams.
  • Partner with DevOps and engineering to embed security across the CI/CD pipeline and Secure SDLC (SSDLC).
  • Develop and maintain application security metrics and reporting for engineering leadership, including vulnerability burn-down and mean-time-to-remediate (MTTR).
  • Lead the bi-weekly vulnerability remediation touchpoints and the monthly Application Security Leadership Forums with engineering organizations (Pinnacle, Measurement, Programmatic, Architecture, Publisher, Social, QA, TechOps/SRE, CorpIT, DevOps, and M&A) to drive progress and accountability.
  • Oversee DV’s API security program (OWASP API Security Top 10, e.g., Escape API Security) and attack surface management (ASM) capabilities, including discovery of shadow/zombie APIs.
  • Assist with Web Application Firewall (WAF) configuration, deployment, and monitoring.
  • Partner with DevOps/SRE on cloud and container security (e.g., Wiz) to deliver code-to-cloud coverage.

AI & Emerging Technology Security

  • Lead AI security governance, engineering, and threat assessment functions across DV’s AI/ML ecosystem.
  • Secure AI agents, LLM-based applications, MCP gateway, and agentic SDLC workflows against threats such as prompt injection, jailbreaking, excessive agency, and supply chain compromise - including guardrails, telemetry, logging, and detections for developer AI tooling (Cursor, Claude Code, VS Code).
  • Evaluate and operationalize AI security platforms to provide detection, response, and AI supply chain governance across teams building or operating AI systems (e.g., AI security gateway, shadow-AI discovery/DLP, AI identity and software management).
  • Build threat models and controls for first- and third-party AI/ML workloads, including data pipelines, model provenance, and RAG architectures.
  • Advance AI-assisted security testing (e.g., DV’s PromptFlow-driven web/API security test generation) to scale coverage across teams., * Lead DV’s offensive security and penetration testing program, working with external vendors and conducting internal security assessments.
  • Build and maintain security automation capabilities to reduce manual effort and increase detection coverage.
  • Partner with the DevOps and CloudOps organizations on cloud security (primarily GCP/Kubernetes), shared responsibility model execution, and infrastructure-as-code security.
  • Own and conduct threat modeling for DV products and infrastructure.
  • Deliver secure coding training and developer enablement programs across global engineering teams., * Recruit, onboard, and manage a team of security engineers and contractors, including software security developers and offensive security testers.
  • Set goals, track performance, and provide ongoing coaching and mentorship to team members.
  • Administer budgets, vendor relationships, and tool procurement within the security engineering function.
  • Collaborate cross-functionally with GRC, Security Operations, IT Security, Legal, and Privacy teams.
  • Meet with senior leadership, engineering managers, and developers across DV’s global engineering departments on a regularly scheduled basis to share the security roadmap and best practices.
  • Represent the application security and AI security programs to senior leadership and in audit/compliance contexts (SOC 2, ISO 27001, NIST CSF 2.0).

Requirements

  • 10+ years of progressive experience in information security, with at least 3 years in a technical management or lead role.
  • Demonstrated expertise in two or more of the following domains: application security, AI/ML security, software supply chain security, penetration testing, cloud security.
  • Hands-on experience with AppSec tooling such as SAST, SCA, DAST, ASPM platforms (e.g., Ox Security, Snyk, Veracode, Checkmarx) and API security.
  • Experience securing AI/ML systems, including familiarity with the OWASP Top 10 for LLMs, NIST AI RMF, agent architectures, and LLM attack vectors.
  • Proficiency in cloud-native environments, particularly GCP; experience with Kubernetes and infrastructure-as-code (e.g., Terraform) is highly desirable.
  • Experience managing or directly executing penetration testing programs (web, API, cloud, AI) and bug bounty programs.
  • Familiarity with DevSecOps principles and integrating security into CI/CD pipelines (GitLab/GitHub/GitOps/ArgoCD).
  • Strong understanding of software supply chain security: SBOM, license compliance, OSV/CVE triage, and dependency chain risk.
  • Experience collaborating with compliance and audit programs (SOC 2, ISO 27001) from a security engineering perspective.
  • Excellent written and verbal communication skills with demonstrated ability to present complex security topics to both technical and non-technical audiences.
  • Proficiency in at least one scripting/programming language (e.g., Python) for security automation.
  • Industry certification preferred (CISSP, CSSLP, GWAPT, OSCP, or equivalent). Bachelor’s degree or higher in Computer Science, Information Systems, or a related field, or equivalent technical experience.

Benefits & conditions

The estimated salary range for this role based on the qualifications set forth in the job description is between [$153,000 - $260,000]. This role will also be eligible for bonus/commission (as applicable), equity, and benefits. The range above is for the expectations as laid out in the job description; however, we are often open to a wide variety of profiles, and recognize that the person we hire may be more or less experienced than this job description as posted.

About the company

DoubleVerify is the leading independent provider of marketing measurement software, data, and analytics that authenticates the quality and effectiveness of digital media for the world’s largest brands and media platforms. DV provides media transparency and accountability to deliver the highest level of impression quality for maximum advertising performance. Since 2008, DV has helped hundreds of Fortune 500 companies gain the most from their media spend by delivering best-in-class solutions across the digital ecosystem, helping to build a better industry. Learn more at www.doubleverify.com.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:08 min

Aligning engineering processes with core business impact metrics

Chris Riley · WWC 2021

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

3:07 min

Establishing service level agreements directly for internal platforms

Pawel Piwosz · LIVE

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

Videos

See all

Related articles

See all