Manager, Application Security

Citizens Financial Group
Olympia, WA, United States
4 days ago
Apply on www.careerbuilder.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$133,000.0 - $190,000.0
Working hours
Regular working hours

Tech stack

Testing (Software) Application Programming Interfaces (APIs) Applications Architecture Application Integration Architecture Software System Penetration Testing User Authentication Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Information Systems Continuous Delivery
+18 more
Continuous Integration Software Design Patterns DevOps Web Development Internet Security Open Web Application Security Systems Development Life Cycle Secure Coding Information Technology Security Auditing Software Engineering Software Vulnerability Management Enterprise Software Applications Software Security Information Technology Devsecops Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

The Manager, Application Security is responsible for leading, scaling, and maturing enterprise application security capabilities across a complex technology environment. This role owns the application security program end to end, ensuring secure software development practices are embedded into the SDLC while balancing regulatory, risk, and business requirements.

As part of the cybersecurity organization, this role partners closely with engineering, platform, cloud, DevOps, and risk teams to drive measurable risk reduction without slowing delivery.

Key Responsibilities

  • Lead the enterprise application security program across web and mobile platforms
  • Define and execute the application security vision, strategy, and roadmap aligned to business and risk objectives
  • Establish and enforce application security standards, secure coding practices, and control requirements
  • Partner with engineering leadership to embed security into architecture, design, and delivery decisions
  • Oversee integration of application security testing tools, including SAST, DAST, and SCA, into CI CD pipelines
  • Lead application security assessments and risk based remediation planning
  • Provide threat informed guidance to engineering teams on high risk vulnerabilities and design patterns
  • Collaborate with vulnerability management, cloud security, and infrastructure teams to drive cohesive risk reduction
  • Establish governance, metrics, and reporting to measure application security maturity and effectiveness
  • Represent application security in audit, regulatory, and risk management engagements
  • Translate technical security risks into clear, business relevant insights for senior leaders
  • Build, mentor, and develop application security engineers and subject matter experts
  • Continuously improve tooling, automation, and processes to scale AppSec capabilities efficiently

Requirements

  • 10 plus years of cybersecurity experience with a strong focus on application security
  • 5 plus years of people or program leadership experience operating an application security program in an enterprise environment
  • Deep understanding of application security risks, including OWASP Top 10
  • Hands on experience with modern SDLC, CI CD, and DevSecOps practices
  • Experience implementing and managing application security testing tools and processes
  • Ability to assess application architecture, design patterns, and authentication and authorization models
  • Strong experience partnering with engineering teams to drive secure by design outcomes
  • Excellent written and verbal communication skills, including executive level reporting
  • Proven ability to influence engineering, product, risk, and compliance stakeholders

Preferred Experience

  • Experience in highly regulated industries such as financial services or healthcare
  • Familiarity with cloud native and microservices based architectures
  • Experience with API security platforms and runtime visibility tools
  • Background in penetration testing or threat modeling
  • Experience defining application security metrics, KPIs, and maturity models

Education and Certifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field
  • Preferred certifications include CISSP, CISM, CISA, GPEN, or equivalent, Application Integration, Application Programming Interface (API), Applications Security, Architectural Analysis, Architectural Design, Authentication, Automation, Cloud Computing, Communication Skills, Computer Science, Computer Security, Continuous Deployment/Delivery, Continuous Improvement, Continuous Integration, Design Patterns Programming Methodologies, Enterprise Protection, Equal Employment Opportunity (EEO), Finance, Financial Services, Genetics, Healthcare, Hubs, Information Technology & Information Systems, Internet Security, Leadership, Machine Tool, Medical Conditions, Mentoring, Metrics, Microservices, Military, Mobile Web Programming, Penetration Testing, Presentation/Verbal Skills, Quality Assurance Methodology, Regulations, Risk, Risk Analysis, Risk Management, Security Analysis, Security Auditing, Security Infrastructure, Security Monitoring, Software Design, Software Development, Software Engineering, Software Testing, State Laws and Regulations, Test Tools, Threat Modeling, Writing Skills

Benefits & conditions

The salary range for this position is from $133,000 to $190,000 per year, plus an opportunity to earn an annual discretionary bonus. Actual pay is based on various factors including but not limited to work location, relevant skills, and experience.

We offer competitive pay, comprehensive medical, dental, and vision coverage, retirement benefits, maternity and paternity leave, flexible work arrangements, education reimbursement, wellness programs, and more. Citizens’ paid time off policy exceeds the mandatory paid sick or paid time away policies of local and state jurisdictions in the United States. For an overview of our benefits, visit our Careers site - https://jobs.citizensbank.com/benefits.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:07 min

Transitioning architecture to microservices at Netflix

Steve Upton Steve Upton · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all