> Markdown version of [/jobs/ext/2989106-application-security-assurance-manager](https://www.wearedevelopers.com/jobs/ext/2989106-application-security-assurance-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Assurance Manager - **Company:** The Depository Trust & Clearing Corporation - **Location:** Jersey City, NJ, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing, Intrusion Detection and Prevention, Software Vulnerability Management, Policy as Code, Software Security, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 18, 2026 - **Apply:** https://ebxr.fa.us2.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/requisitions/preview/214510 ## About the Role * Minimum of 8 years of related experience * Bachelor's degree preferred or equivalent experience ## Description As a member of the CISO organization, this role provides strategic leadership for application security governance across DTCC's container platforms by unifying container security and vulnerability management into a cohesive, risk-driven control framework. The leader owns the design, delivery, and continuous improvement of platform-native AppSec controls-spanning build, deployment, and runtime-ensuring security is embedded through automation, policy-as-code, and standardized guardrails. By partnering closely with Cloud, Platform, and Application teams, this role enables secure scaling of containerized workloads while reducing material risk, improving vulnerability signal quality, and ensuring controls are audit-ready, measurable, and aligned to DTCC's regulatory and risk management expectations. Your Primary Responsibilities: * Lead SCA, SAST, and DAST programmes to provide scalable application security coverage across DTCC. * Manage application security risk by driving vulnerability identification, prioritisation, remediation, and escalation. * Partner with engineering teams to improve security outcomes and reduce application risk. * Own AppSec platforms and services ensuring reliability, optimisation, adoption, and effective integration. * Establish security standards and governance for secure development and testing practices. * Drive programme maturity through metrics, reporting, automation, and continuous improvement. * Advance detection capabilities by evaluating emerging technologies, tooling, and AI-driven security solutions. * Maintain strong risk and control oversight through compliance with policies, standards, and regulatory expectations., * Highlights the expected benefits of new actions and strategies to help others overcome fears of change. * Fosters a culture where honesty and transparency are expected. * Proactively seeks feedback from others on his/her own performance. * Ensures that regular feedback is given in a constructive and behaviorally oriented manner. * Supports an environment where individuals are respected for their contributions. ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Policy as [versioned] code - you're doing it wrong](https://www.wearedevelopers.com/videos/532-policy-as-versioned-code-you-re-doing-it-wrong) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) ## Related Articles - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix)