Lead Application Security Engineer

Seek Careers
Detroit, MI, United States
2 months ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Agile Methodology User Authentication Cyber Security Continuous Integration Secure Coding Enterprise Software Applications Software Security Information Technology Devsecops Static Application Security Testing Dynamic Application Security Testing

Job description

The Lead Application Security Engineer provides enterprise-level technical leadership and strategic direction for application security across the organization. This role is a senior individual contributor responsible for defining, governing, and evolving application security architecture, standards, tooling, and DevSecOps practices to ensure security is built into applications by design.

This role does not include direct people management but serves as a technical leader, mentor, and escalation point for complex application security initiatives., * Define, own, and govern application security architecture standards, patterns, and requirements across development teams.

  • Provide senior-level technical leadership, including review and approval of designs for complex, high-risk, or business-critical applications.
  • Lead or co-own the design, implementation, and ongoing maturity of the enterprise DevSecOps program.
  • Evaluate, select, and govern application security tooling, including defining usage standards, coverage expectations, and success metrics.
  • Perform advanced threat modeling and security architecture reviews for externally exposed or high-impact applications.
  • Act as the primary application security subject matter expert for development and platform teams.
  • Define, track, and report application security metrics and KPIs to assess program effectiveness and inform leadership.
  • Serve as a technical mentor and final escalation point for complex application security issues.
  • Partner with Governance, Risk, and Compliance teams to support secure development training and awareness initiatives.

Requirements

  • Bachelor’s degree in computer science, Information Technology, Engineering, or a related technical field, or equivalent practical experience.
  • Minimum of five (5) to seven (7) years of professional experience in information technology, with at least three (3) years focused on application security or closely related cybersecurity work.
  • Experience applying application security principles, including secure coding, authentication, authorization, and data protection, in production software environments.
  • Experience leading or significantly influencing application security architecture decisions.
  • Experience integrating application security practices into modern software development methodologies, including Agile and CI/CD workflows.

Preferred Qualifications:

  • Experience leading or governing enterprise application security or DevSecOps initiatives.
  • Experience defining standards and operating models for application security tooling (e.g., SAST, DAST, IAST, SCA).
  • Ability to influence cross-functional teams without direct authority.
  • Security-related certifications (e.g., CISSP, GIAC, CSSLP, OSCP) are a plus.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · World Congress 2021

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

Videos

See all

Related articles

See all