Manager - AppSec/DevSecOps Security Engineer
NewBe an early applicantLeadership & Programme Management
- Own and evolve the application security strategy, testing roadmap, and service catalogue aligned to business and regulatory requirements.
- Lead, and mentor a team of AppSec engineers and penetration testers; manage workload, quality, and career development.
- Act as the primary escalation point for application security risk decisions across engineering and product leadership.
- Drive continuous improvement in AppSec tooling, methodologies, and coverage metrics.
- Represent the AppSec function in client discussions, audits, risk committees, and vendor assessments.
Web Application Penetration Testing
- Oversee and conduct advanced web application penetration testing including complex business logic, authentication/authorisation flaws, API abuse, and chained attack scenarios.
- Define and maintain testing methodology aligned to OWASP Testing Guide, PTES, and client-specific requirements.
- Review and quality-assure penetration test reports produced by the team before delivery to clients or stakeholders.
- Drive responsible disclosure and coordinated vulnerability management for critical findings.
Mobile Application Security
- Lead mobile security assessments for Android and iOS—static/dynamic analysis, reverse engineering, and runtime manipulation (Frida, objection, Drozer).
- Establish and maintain mobile security standards aligned to OWASP MASVS and MSTG across product teams.
- Guide development teams on secure mobile architecture: certificate pinning, secure storage, and inter-process communication security.
Source Code Review
- Conduct and oversee manual source code security reviews across multiple languages (Java, Python, JavaScript/TypeScript, Go, C#, and others).
- Define code review standards and integrate SAST tooling (Semgrep, Checkmarx, Veracode, SonarQube) into development workflows.
- Provide actionable, developer-centric findings with clear severity ratings and remediation guidance.
- Track remediation SLAs and report on code security posture trends over time.
DevSecOps Integration
- Lead integration of security tooling (SAST, DAST, SCA, container scanning, API security) into CI/CD pipelines (Jenkins, GitHub Actions, and similar).
- Define pipeline security gates, policy-as-code standards, and developer feedback loops to shift security left.
- Oversee IaC security (Terraform, CloudFormation), secrets management, and supply-chain security controls.
- Collaborate with platform and cloud engineering on secure architecture, baseline hardening, and runtime protection.
Governance, Risk & Compliance
- Own the application security risk register; track, prioritise, and report on vulnerability posture to senior leadership.
- Ensure AppSec activities align with OWASP ASVS, NIST 800-53, ISO 27001, PCI-DSS, and SOC 2.
- Define and track AppSec KPIs: mean time to remediation, critical findings per release, and coverage rates.
- Translate regulatory and client security requirements into testable engineering controls.
AI / GenAI Security
- Assess and mitigate risks in AI/GenAI applications: LLM-based apps, RAG pipelines, agentic workflows (OWASP LLM Top 10, prompt injection, data leakage).
Incorporate AI security testing into standard AppSec assessment methodologies.
Leadership & Programme Management
- Own and evolve the application security strategy, testing roadmap, and service catalogue aligned to business and regulatory requirements.
- Lead, and mentor a team of AppSec engineers and penetration testers; manage workload, quality, and career development.
- Act as the primary escalation point for application security risk decisions across engineering and product leadership.
- Drive continuous improvement in AppSec tooling, methodologies, and coverage metrics.
- Represent the AppSec function in client discussions, audits, risk committees, and vendor assessments.
Web Application Penetration Testing
- Oversee and conduct advanced web application penetration testing including complex business logic, authentication/authorisation flaws, API abuse, and chained attack scenarios.
- Define and maintain testing methodology aligned to OWASP Testing Guide, PTES, and client-specific requirements.
- Review and quality-assure penetration test reports produced by the team before delivery to clients or stakeholders.
- Drive responsible disclosure and coordinated vulnerability management for critical findings.
Mobile Application Security
- Lead mobile security assessments for Android and iOS—static/dynamic analysis, reverse engineering, and runtime manipulation (Frida, objection, Drozer).
- Establish and maintain mobile security standards aligned to OWASP MASVS and MSTG across product teams.
- Guide development teams on secure mobile architecture: certificate pinning, secure storage, and inter-process communication security.
Source Code Review
- Conduct and oversee manual source code security reviews across multiple languages (Java, Python, JavaScript/TypeScript, Go, C#, and others).
- Define code review standards and integrate SAST tooling (Semgrep, Checkmarx, Veracode, SonarQube) into development workflows.
- Provide actionable, developer-centric findings with clear severity ratings and remediation guidance.
- Track remediation SLAs and report on code security posture trends over time.
DevSecOps Integration
- Lead integration of security tooling (SAST, DAST, SCA, container scanning, API security) into CI/CD pipelines (Jenkins, GitHub Actions, and similar).
- Define pipeline security gates, policy-as-code standards, and developer feedback loops to shift security left.
- Oversee IaC security (Terraform, CloudFormation), secrets management, and supply-chain security controls.
- Collaborate with platform and cloud engineering on secure architecture, baseline hardening, and runtime protection.
Governance, Risk & Compliance
- Own the application security risk register; track, prioritise, and report on vulnerability posture to senior leadership.
- Ensure AppSec activities align with OWASP ASVS, NIST 800-53, ISO 27001, PCI-DSS, and SOC 2.
- Define and track AppSec KPIs: mean time to remediation, critical findings per release, and coverage rates.
- Translate regulatory and client security requirements into testable engineering controls.
AI / GenAI Security
- Assess and mitigate risks in AI/GenAI applications: LLM-based apps, RAG pipelines, agentic workflows (OWASP LLM Top 10, prompt injection, data leakage).
Incorporate AI security testing into standard AppSec assessment methodologies.
Skills & Capabilities
Non-Negotiable – Must Have
- 6–8+ years of progressive experience in application security, penetration testing, or a closely related security engineering discipline.
- Expert-level web application penetration testing: complex chained attacks, API abuse, OAuth/OIDC flaws, deserialization, advanced injection techniques.
- Hands-on mobile security testing for Android and iOS (static/dynamic analysis, Frida scripting, MASVS/MSTG alignment).
- Strong source code review skills across at least two major languages—able to identify security defects manually and via SAST tooling.
- Proven experience embedding security into CI/CD pipelines and operating SAST/DAST/SCA tooling in a DevSecOps environment.
- Experience managing or technically leading a team of security engineers or penetration testers.
- Ability to communicate complex security risk credibly to technical and executive audiences.
Good to Have
- Certifications: eWPTX, OSCP, OSWE, BSCP (Burp Suite Certified Practitioner), GWAPT, GWEB, GPEN, CPENT, or equivalent offensive security credentials.
- Cloud security experience across AWS, Azure, or GCP (IAM, network security, SIEM integration).
- Knowledge of AI/GenAI security risks and securing ML pipelines (MLSecOps).
- Threat modelling frameworks: STRIDE, PASTA, attack trees.
- Experience in client-facing security consulting or managed security services.
Leadership & Soft Skills
- Proven ability to build, mentor, and retain high-performing security teams.
- Strong programme management—able to manage concurrent assessments, client deliverables, and operational priorities.
- Influencing skills to drive secure-by-design adoption across engineering organisations without being a pure gatekeeper.
- Commercial awareness: able to balance thoroughness, risk, and delivery timelines.
Qualifications
- Bachelor’s or master’s degree in Computer Science, Information Security, Engineering, or equivalent practical experience.
- 6–8+ years of relevant experience in application security, penetration testing, or DevSecOps with progressive responsibility.
- 1–2+ years in a team lead or management capacity within a security function.
- Offensive security certifications (eWPTX, OSCP, OSWE, or equivalent) strongly preferred.