> Markdown version of [/jobs/ext/537842-application-security-manager](https://www.wearedevelopers.com/jobs/ext/537842-application-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Manager - **Company:** The Smart - **Location:** Boston, MA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Federal Information Processing Standards (FIPS), Security Software, Software Vulnerability Management, Enterprise Data Management, IT General Controls (ITGC), Information Technology, Static Application Security Testing, BIG‑IP Application Security Manager (ASM), Dynamic Application Security Testing - **Published:** June 13, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b9494d162ce03737 ## About the Role Do you have a Bachelor's degree?, * Bachelor's degree in Information Technology, Computer Science, or related field, or equivalent work experience * 10 or more years of IT experience, including 5 or more years in security leadership roles * Strong experience with security and compliance frameworks such as NIST, HIPAA, HITRUST, GDPR, and FedRAMP * Experience designing and implementing enterprise security controls across applications, infrastructure, and networks * Experience with vulnerability management tools and processes including SAST, DAST, and penetration testing * Strong understanding of risk management, audit processes, and compliance reporting * Experience troubleshooting complex security issues across environments * Strong written and verbal communication skills, * Experience with AWS security architecture and compliance practices * Professional certifications such as CISSP, CISA, CISM, or CCSP * Experience working in highly regulated or government environments * Experience implementing automated security and compliance solutions Core Skills & Attributes * Strong analytical and problem-solving skills * Ability to identify and mitigate security risks across complex environments * Strong leadership and decision-making capabilities * Effective communication with technical and executive stakeholders * Detail-oriented with a focus on compliance and quality * Ability to work in high-pressure and on-call environments * Collaborative mindset with cross-functional teams * Continuous improvement and security-focused mindset ## Description The Information Security Manager / Security Architect is responsible for leading and implementing enterprise data security, compliance, and risk management programs across complex IT environments. This role focuses on establishing security standards, managing vulnerability programs, and ensuring adherence to regulatory frameworks. The position collaborates with security, infrastructure, and application teams to strengthen security posture and support continuous compliance and operational resilience., Security Architecture & Governance * Design and implement enterprise data security management and operational models * Establish and enforce security standards aligned with frameworks such as NIST, FIPS, and FedRAMP * Provide architectural and configuration guidance to ensure secure, compliant environments * Evaluate and recommend security tools, technologies, and controls Compliance, Risk & Audit Management * Partner with privacy, security, and compliance teams to manage regulatory requirements * Coordinate and respond to internal and external audits, including remediation planning * Maintain compliance with frameworks such as HIPAA, HITRUST, GDPR, and related standards * Develop and maintain reporting for compliance and security posture Vulnerability & Threat Management * Implement and manage application security testing processes including SAST and DAST * Establish and oversee vulnerability management programs including penetration testing * Coordinate remediation efforts and track vulnerabilities through resolution * Conduct infrastructure security assessments and audits Operations, Monitoring & Incident Response * Maintain system security and integrity by implementing industry-standard IT controls * Monitor environments and troubleshoot security issues across systems and applications * Participate in incident response and support 24/7 on-call rotations as required * Ensure timely resolution of security incidents and operational challenges Automation & Continuous Improvement * Implement automation for system administration, security processes, and deployment activities * Drive continuous improvement of security processes, controls, and operational efficiency * Support migration and deployment processes for QA and production environments Collaboration & Stakeholder Support * Work closely with application, QA, and infrastructure teams to ensure security compliance * Provide technical guidance and support to internal stakeholders and agency users * Translate technical risks into business context for leadership decision-making * Deliver training and awareness programs related to security and compliance ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)