Application Security Manager

The Smart
Boston, MA, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Cyber Security Federal Information Processing Standards (FIPS) Security Software Software Vulnerability Management Enterprise Data Management IT General Controls (ITGC) Information Technology Static Application Security Testing BIG‑IP Application Security Manager (ASM) Dynamic Application Security Testing

Job description

The Information Security Manager / Security Architect is responsible for leading and implementing enterprise data security, compliance, and risk management programs across complex IT environments. This role focuses on establishing security standards, managing vulnerability programs, and ensuring adherence to regulatory frameworks. The position collaborates with security, infrastructure, and application teams to strengthen security posture and support continuous compliance and operational resilience., Security Architecture & Governance

  • Design and implement enterprise data security management and operational models
  • Establish and enforce security standards aligned with frameworks such as NIST, FIPS, and FedRAMP
  • Provide architectural and configuration guidance to ensure secure, compliant environments
  • Evaluate and recommend security tools, technologies, and controls

Compliance, Risk & Audit Management

  • Partner with privacy, security, and compliance teams to manage regulatory requirements
  • Coordinate and respond to internal and external audits, including remediation planning
  • Maintain compliance with frameworks such as HIPAA, HITRUST, GDPR, and related standards
  • Develop and maintain reporting for compliance and security posture

Vulnerability & Threat Management

  • Implement and manage application security testing processes including SAST and DAST
  • Establish and oversee vulnerability management programs including penetration testing
  • Coordinate remediation efforts and track vulnerabilities through resolution
  • Conduct infrastructure security assessments and audits

Operations, Monitoring & Incident Response

  • Maintain system security and integrity by implementing industry-standard IT controls
  • Monitor environments and troubleshoot security issues across systems and applications
  • Participate in incident response and support 24/7 on-call rotations as required
  • Ensure timely resolution of security incidents and operational challenges

Automation & Continuous Improvement

  • Implement automation for system administration, security processes, and deployment activities
  • Drive continuous improvement of security processes, controls, and operational efficiency
  • Support migration and deployment processes for QA and production environments

Collaboration & Stakeholder Support

  • Work closely with application, QA, and infrastructure teams to ensure security compliance
  • Provide technical guidance and support to internal stakeholders and agency users
  • Translate technical risks into business context for leadership decision-making
  • Deliver training and awareness programs related to security and compliance

Requirements

Do you have a Bachelor’s degree?, * Bachelor’s degree in Information Technology, Computer Science, or related field, or equivalent work experience

  • 10 or more years of IT experience, including 5 or more years in security leadership roles
  • Strong experience with security and compliance frameworks such as NIST, HIPAA, HITRUST, GDPR, and FedRAMP
  • Experience designing and implementing enterprise security controls across applications, infrastructure, and networks
  • Experience with vulnerability management tools and processes including SAST, DAST, and penetration testing
  • Strong understanding of risk management, audit processes, and compliance reporting
  • Experience troubleshooting complex security issues across environments
  • Strong written and verbal communication skills, * Experience with AWS security architecture and compliance practices
  • Professional certifications such as CISSP, CISA, CISM, or CCSP
  • Experience working in highly regulated or government environments
  • Experience implementing automated security and compliance solutions

Core Skills & Attributes

  • Strong analytical and problem-solving skills
  • Ability to identify and mitigate security risks across complex environments
  • Strong leadership and decision-making capabilities
  • Effective communication with technical and executive stakeholders
  • Detail-oriented with a focus on compliance and quality
  • Ability to work in high-pressure and on-call environments
  • Collaborative mindset with cross-functional teams
  • Continuous improvement and security-focused mindset

Benefits & conditions

  • Competitive salary

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · WWC 2025

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

2:46 min

Missing equipment retrieval processes for departing employees

Jasmin Azemović Jasmin Azemović · WWC Europe 2026

3:55 min

Establishing blameless dialogue surrounding critical software security vulnerabilities

Chris Heilmann +2 · LIVE

Videos

See all

Related articles

See all