> Markdown version of [/jobs/ext/2735829-application-security-manager](https://www.wearedevelopers.com/jobs/ext/2735829-application-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Manager - **Company:** Cornerstone Barricades - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Information Systems, Continuous Integration, Open Web Application Security, Systems Development Life Cycle, Software Engineering, Software Security, Information Technology, Devsecops - **Published:** September 5, 2026 - **Apply:** https://dhlinternational.betterteam.com/senior-application-security-manager-(m-f-d)/apply/standard ## About the Role * 8+ years in Application Security. * Strong experience in AppSec testing, Threat Modelling, DevSecOps, CI/CD security. * Experience implementing Secure SDLC controls using OWASP standards within DevSecOps and CI/CD environments. * University degree in Computer Science / Information Systems or equivalent. * Security certifications preferred (e.g. OSCP, CISSP, CISM, CISA, CRISC). * Fluent English (German a plus). ## Description You will play a key role in identifying, assessing, and mitigating application-level cyber risks, ensuring security is embedded by design across the software development lifecycle. Responsible for strengthening DHL Express' application security posture through penetration testing, red teaming, threat modelling, and DevSecOps integration. The role combines hands-on security assessments with enterprise risk, reporting, and stakeholder advisory responsibilities., * Conduct application penetration tests and red teaming to identify high-risk vulnerabilities. * Perform Threat Modelling and provide security guidance during design and development. * Support DevSecOps and CI/CD security automation initiatives. * Ensure appropriate security countermeasures are implemented by IT and suppliers. * Report cyber risks and mitigation status to technical asset owners. * Support Risk, Compliance, Audit, and Corporate Security teams. * Collaborate with global, regional, and country stakeholders on security reviews. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)