Manager, Application Security

Simpson Thacher & Bartlett LLP
New York, NY, United States
8 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$190,000.0 - $220,000.0
Working hours
Regular working hours

Tech stack

Testing (Software) Kubernetes Security Application Programming Interfaces (APIs) Artificial Intelligence Applications Architecture Application Integration Architecture Application Services User Authentication Software as a Service Cloud Computing Cloud Engineering Code Coverage
+32 more
Cyber Security Databases Continuous Delivery Continuous Integration Data Security DevOps Issue Tracking Systems Information Systems Security Architecture Professional Python (Programming Language) Windows PowerShell Systems Development Life Cycle Server Administration Software Engineering Systems Integration Software Vulnerability Management Web Applications Scripting Enterprise Software Applications Software Security Model Validation Multi-Cloud Generative AI Build Management Containerization Kubernetes Devsecops Api Management Security Orchestration, Automation & Response Static Application Security Testing Vulnerability Analysis Microservices Dynamic Application Security Testing

Job description

JOB SUMMARYThe Senior Manager, Application Security is responsible for defining, leading, and operationalizing the firm’s application security program across internally developed applications, SaaS platforms, APIs, databases, generative AI platforms, and emerging application architectures. This role partners closely with application engineering, cloud, and platform teams to embed security into the software development lifecycle while enabling teams to deliver securely at scale.

The ideal candidate is a highly skilled, hands-on technical leader who can translate security requirements into practical developer workflows while enabling rapid and reliable software delivery., * Develop, execute, and continuously mature the enterprise application security strategy in alignment with industry best practices, regulatory requirements, and client contractual obligations.

  • Define and maintain secure application development standards for internally developed software, third-party applications, APIs, SaaS platforms and containerized workloads.
  • Establish minimum security requirements for application authentication, authorization, encryption, secrets handling, and data protection.
  • Define, maintain, and enforce secure SDLC and DevSecOps standards across all development teams.
  • Integrate application security controls into CI/CD pipelines, developer platforms, and engineering workflows with a focus on automation and scalability.
  • Partner with Application Engineering and DevOps teams to embed automated security testing and preventive controls while maintaining security ownership of policy and enforcement.
  • Evaluate, select, implement, and manage the full lifecycle of application security tooling including:
  • SAST, DAST, SCA, and API security testing platforms
  • Container image scanning and registry security tooling
  • Kubernetes security and runtime protection solutions
  • Software supply chain security tooling
  • Design and implement integrations between application security tooling and developer workflows to minimize friction and maximize adoption.
  • Design and build automation to support application security processes including:
  • Orchestrated automated security testing.
  • Vulnerability triage and prioritization workflows
  • Developer feedback loops and ticketing system integrations
  • Exception handling, risk acceptance, and policy waiver workflows
  • Security metrics and pipeline telemetry
  • Identify and assess application security risks including vulnerable dependencies, insecure authentication patterns, data exposure risks, and insecure configuration.
  • Perform and support threat modeling, architecture reviews, and secure design assessments for high-risk, or business critical applications.
  • Support the security review, onboarding, and ongoing risk management of third-party and SaaS applications.
  • Develop and maintain metrics, dashboards, and reporting to measure application security posture, testing coverage, and vulnerability remediation effectiveness.
  • Provide application security subject matter expertise during security incidents, investigations, and post-incident remediation efforts.
  • Lead, mentor, and develop a team of application security engineers, fostering strong technical depth and career growth.
  • Partner with engineering leadership to drive secure-by-design development practices and shared accountability for risk reduction.
  • Communicate application security risks, tradeoffs, and recommendations clearly to both technical and executive stakeholders.
  • Promote a developer-friendly security culture focused on automation, guardrails, measurable risk reduction, and engineering velocity.
  • Stay current on emerging application threats, attack techniques, and defensive technologies, and apply this knowledge to continuously improve program effectiveness.

Requirements

  • Bachelor’s degree in information security, IT, risk management, related discipline, or equivalent experience

Preferred

  • Professional certifications such as CISSP, CISM, or similar, * 10+ years of progressive experience in application security, product security, or software security engineering roles
  • Hands-on experience securing modern application ecosystems, including web applications, APIs, microservices, cloud-native workloads, container, and Kubernetes platforms
  • Demonstrated success building, scaling, and operating enterprise-grade Application Security programs within large, complex organizations, preferably in hybrid environments (on-premises, multi-cloud, Kubernetes, and SaaS).
  • Experience partnering with application, DevOps, and platform engineering teams to design and implement security controls that scale without impeding developer velocity.
  • Hands-on experience implementing and operationalizing enterprise application security tooling and integrating controls into CI/CD pipelines and developer workflows.
  • Technical Skills & Knowledge:
  • Secure SDLC principles and DevSecOps integration patterns
  • Application security testing methodologies and tooling (SAST, DAST, SCA, API testing)
  • Container security concepts, including image hardening, vulnerability scanning, secure registries, and container lifecycle management.
  • Cloud-native application security concepts
  • Software supply chain security principles
  • Security automation and scripting (Python, PowerShell, or similar)
  • CI/CD security integration patterns
  • Demonstrated ability to lead, mentor, and develop high-performing application security or product security engineering teams.
  • Strong program and project management capabilities, with a track record of delivering complex, cross-functional initiatives on time and within budget.
  • Experience operating within global organizations and collaborating effectively across diverse geographies, cultures, and business units.
  • Proven ability to manage third-party vendors and security technology providers, including evaluation, onboarding, delivery oversight, and performance management.
  • Strong interpersonal and collaboration skills, with comfort engaging regularly with senior leadership and key internal and external stakeholders.
  • Excellent executive communication and presentation skills, with the ability to clearly articulate risk, strategy, and technical concepts to both technical and non-technical audiences.
  • Strong ability to manage multiple concurrent priorities, exercise sound judgment, and effectively allocate time and resources in a fast-paced environment.
  • Proven ability to execute effectively amid ambiguity and incomplete information, applying risk-based decision-making.
  • Demonstrated continuous learning mindset, staying current on emerging technologies, security threats, vulnerabilities, and attack vectors.
  • Passion for innovation, automation, and driving continuous improvement in application security processes., The actual salary offered will depend on a variety of factors, including without limitation, the qualifications of the individual applicant for the position, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location in which the applicant lives and/or from which they will be performing the job. This role is exempt meaning it is not overtime pay eligible., Application Integration, Application Programming Interface (API), Applications Security, Artificial Intelligence (AI), Authentication, Automation, Autonomous Driving Systems, Best Practices, Budget Management, Business Solutions, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Cloud Computing, Communication Skills, Compensation and Benefits, Computer Security, Continuous Deployment/Delivery, Continuous Improvement, Continuous Integration, Contract Requirements, DevOps, Enterprise Protection, Error Handling, Information/Data Security (InfoSec), Leadership, Machine Tool, Mentoring, Metrics, Model Review, Multitasking, Onboarding, Performance Analysis, Performance Management, Presentation/Verbal Skills, Process Improvement, Product Engineering, Program Evaluation, Project/Program Management, Python Programming/Scripting Language, Quality Assurance Methodology, Regulatory Requirements, Reporting Dashboards, Resource Management, Risk, Risk Analysis, Risk Management, Scripting (Scripting Languages), Security Analysis, Software Administration, Software Development, Software Development Lifecycle (SDLC), Software Engineering, Software Testing, Software as a Service (SaaS), Standards Development, Supply Chain, System Integration (SI), Technical Leadership, Technical Strategy, Test Tools, Testing, Threat Modeling, Time Management, Training/Teaching, Vulnerability Scanners, Windows PowerShell

Benefits & conditions

NY Only: The estimated base salary range for this position is $190,000 to $220,000 at the time of posting.

About the company

Simpson Thacher & Bartlett

Simpson Thacher is one of the world’s most respected law firms. But for us, this has never simply been a matter of size or rankings. It’s the direct result of our commitment to one founding principle. Since 1884, many of the world’s largest organizations have turned to us for smart solutions to critical commercial challenges. Today, more than 900 lawyers in 11 global offices put the collective experience of the Firm to work for every client we serve. Our teams start with a deep understanding of our clients’ business objectives. We share knowledge across practices and regions. We help our clients not only mitigate risk, but also discover opportunity. And each success begins with the same simple question… How can we help you?

Company Size: 1,500 to 1,999 employees

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all