freehire launches on Product Hunt on 26 August.

Follow →

Senior Application Security and Infrastructure Protection Manager

Summary

Senior Application Security and Infrastructure Protection Manager leading a comprehensive security function that embeds security into software development, protects critical infrastructure, strengthens security operations, and supports compliance across VENU+ technology platforms (Mobility Services, Smart Lockers, Photo Services), working with development, DevOps, and business stakeholders to ensu

At VENU+, work feels like play — but with purpose.

As the global leader in creating unforgettable guest experiences, we combine entertainment, gaming, souvenirs, mobility, and storage solutions to bring more excitement, engagement, and convenience to the world’s top destinations. From ScooterPals® Fur-Wheelers and claw machines to photo capture, arcade games, and smart lockers, our creative programs help venues operate more efficiently, elevate guest satisfaction, and increase revenue — all with ease. Guided by collaboration, innovation, and a passion for excellence, we empower our team members to grow, contribute, and make a meaningful impact.

If you’re seeking a career that’s dynamic, rewarding, and full of opportunity, you’ll find it at VENU+.

At VENU+, we believe great work deserves meaningful rewards. Our benefits are designed to support your health, financial security, and overall well-being — so you can thrive both personally and professionally:

Benefits Available to Qualifying Full-Time and Part-Time Employees:

  • Flexible Time Off – Paid time off that allows you to take the time off you need, along with paid holidays.

  • Health & Wellness Coverage – Comprehensive medical, dental, and vision plans.

  • Retirement Planning – 401(k) plan with 50% company match on the first 6% contributed, including Roth options

  • And more!!

Grow your career with great benefits—and even better people!

Job Summary:

The Senior Application Security and Infrastructure Protection Manager is responsible for leading a comprehensive security function that embeds security into software development, protects critical infrastructure, strengthens security operations, and supports compliance and risk management across VENU+ technology platforms and business lines, including Mobility Services, Smart Lockers, and Photo Services. This role combines secure software development, application security engineering, DevSecOps enablement, infrastructure security, vulnerability management, incident response, policy governance, and audit readiness into one integrated position. The role works closely with software development, DevOps, IT operations, cybersecurity, executive leadership, vendors, finance, and business stakeholders to ensure applications, systems, cloud services, networks, endpoints, identities, data, and third-party platforms are designed, deployed, monitored, and maintained in a secure, resilient, compliant, and risk-aware manner.

Key Responsibilities:

  • Advise on application security engineering practices across the software development lifecycle, including secure design reviews, threat modelling, secure coding standards, architecture input, code review guidance, and release security validation.
  • Embed DevSecOps controls into development and delivery pipelines, including SAST, DAST, dependency scanning, secret scanning, container scanning, infrastructure-as-code review, security gates, and remediation workflows.
  • Partner with software, DevOps, product, and QA teams to identify application risks early, validate security requirements, prioritize vulnerabilities, and ensure secure-by-design outcomes for web, mobile, API, cloud, SaaS, and integration platforms.
  • Protect infrastructure, cloud services, networks, endpoints, servers, databases, identities, privileged access, and business-critical systems through secure configuration baselines, hardening standards, monitoring, patching, and control validation.
  • Manage vulnerability, patch, and remediation programs across applications and infrastructure, including risk ranking, ownership assignment, exception handling, reporting, verification, and executive escalation where required.
  • Lead security operations activities, including alert triage, incident response coordination, investigation support, root cause analysis, containment, recovery, post-incident reviews, and improvement actions.
  • Maintain and improve security monitoring, logging, endpoint protection, identity protection, email security, backup resilience, disaster recovery readiness, and business continuity controls.
  • Develop, maintain, and enforce cybersecurity policies, secure software development standards, infrastructure protection procedures, risk registers, control evidence, security documentation, and operational runbooks.
  • Support compliance, audit readiness, and governance activities aligned with applicable internal policies, customer requirements, contractual obligations, privacy requirements, and recognized security frameworks.
  • Assess and manage technology, application, infrastructure, cloud, vendor, and third-party security risks, including due diligence, control reviews, risk acceptance, remediation tracking, and security recommendations.
  • Provide security guidance to leadership and stakeholders through clear reporting on security posture, vulnerabilities, incidents, compliance status, control gaps, residual risks, and improvement priorities.
  • Promote a security-first culture by coaching developers, IT teams, business users, and vendors on secure practices, risk awareness, incident prevention, and practical control adoption.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available