Job brief
Seeking for an experienced Application Security Head to drive our secure development initiatives and lead a team of security professionals. The ideal candidate will have a strong technical background in application security, hands-on expertise with security testing tools, and proven leadership experience in building and managing security programs for modern application environments.
Responsibilities
- Lead the application security function, providing guidance and mentorship to the team.
- Design, implement, and oversee the application security program, including policies, standards, and best practices
- Manage and conduct application security testing (SAST, DAST, IAST, RASP) across multiple projects.
- Partner with engineering, DevOps, and product teams to embed secure coding practices throughout the software development lifecycle (SDLC).
- Evaluate, implement, and maintain application security tools such as Veracode, Checkmarx, Burp Suite, Fortify , and others.
- Collaborate with developers and architects to secure modern application architectures, including microservices, containers, and APIs .
- Provide expert guidance on the OWASP Top 10 and other common vulnerabilities.
- Monitor emerging threats, vulnerabilities, and security trends to continuously enhance the security posture.
Drive remediation and risk mitigation efforts, ensuring compliance
with internal and external standards.
Report on application security metrics and program effectiveness to senior leadership.Requirements
10+ years of experience in application security , with at least 3+ years in a leadership role .Strong knowledge of application security testing methodologies and tools (SAST, DAST, IAST, RASP).Deep understanding of OWASP Top 10 , secure coding practices, and software security standards.Proven experience with application security tools (e.g., Veracode, Checkmarx, Burp Suite, Fortify).Familiarity with modern architectures such as microservices, containers, APIs.Experience collaborating across engineering, DevOps, and product teams to drive secure development practices.Excellent communication, leadership, and stakeholder management skills.For FILIPINO CITIZEN WHO IS CURRENTLY in the PHILIPPINES ONLY