Job Closed
This listing is no longer active.
Invicti Security is an IT services and consulting company on a mission to transform how web applications are secured. Self-described as one of the fastest-growi
Senior Application Security Manager
Location
Turkey
Posted
103 days ago
Salary
0
Seniority
Senior
Job Description
Senior Application Security Manager
Invicti Security
**What You’ll Be Doing: ** • Strategic Advisory: Act as a lead consultant for enterprise customers, moving beyond tool configuration to advising on global web application security strategies and DevSecOps maturity. • Program Architecture: Guide customers in integrating ASPM, DAST, SAST, and SCA into complex CI/CD workflows (GitHub, GitLab, Jenkins, ADO) at an enterprise scale. • Thought Leadership: Act as an internal Subject Matter Expert for the consulting organization, refining our playbooks and guiding technical standards for AppSec, API security and cloud-native testing. • Technical Excellence: Resolve the most complex DAST rollout challenges, including authentication hurdles and scan accuracy in unique, abstract customer environments.
Job Requirements
- Wh**at You’ll Need**
- Experience: 7–12 years of relevant experience in AppSec consulting, penetration testing, or vulnerability management.
- Security Mastery: Expert-level hands-on experience with SAST, DAST methodologies and advanced configurations (Invicti, Burp Suite, Snyk, Semgrep etc.).
- DevSecOps DNA: Proven ability to automate security workflows using Python, Bash, or PowerShell within enterprise pipelines.
- Compliance & Risk: Deep understanding of mapping technical controls to frameworks like NIST 800-218 (SSDF), OWASP ASVS, OWASP API TOP TEN and PCI-DSS.
- Strategic Soft Skills: The ability to negotiate success outcomes and influence stakeholders without direct authority in high-pressure environments.
- What Will Be A Plus**
- Advanced knowledge or hands-on experience with CI/CD platforms and tools such as Gitlab CI, Azure DO, Github Actions, or Jenkins
- Experience with Infrastructure as Code (Terraform, CloudFormation) or specific Cloud Security tooling.
- Hands-on experience in managing security in the software development lifecycle (SDLC)
- Holding OSCP, OSWE or similar certifications
- What Will Be Required Personal Skills**
- Technical Project & Engagement Management: Ability to lead complex, multi-phase security deployments, manage project timelines, and ensure milestone delivery.
- Strategic Influence: Proven ability to "influence without authority," navigating internal and external stakeholders to drive AppSec adoption.
- Analytical Negotiation: Strong problem-solving skills with a focus on negotiating realistic and valuable success outcomes in high-pressure environments.
- Mentorship & Coaching: A proactive approach to knowledge sharing, capable of upskilling both junior team members and customer "security champions."
- Excellent command of English both verbal and written
Benefits
- Why Invicti?**
- Your Health & Wellness Matters:**
- Health Insurance: Taking care of our team goes beyond the office. We cover 100% of employee and dependent health costs. Coverage is effective your first day.
- Family Leave: 16 week paid leave for birthing parent recovery.4 week paid leave for non-birthing/bonding parent. Mother receives $250/month after returning back to work up to the child's first birthday
- We Value Adult/Life Balance:**
- Excellent Working Options: *Work from home or join us in our Turkey Istanbul - Ankara Offices, whichever works best for you!
- Discretionary Time Off:* Enjoy a flexible vacation schedule where you do not have to wait to use time off until it is accrued. 14 extra days in the first year upon completion of the 2nd month. 10 days of paid sick leave every year.
- Quarterly Thrive-Wellness Days: *One extra vacation day per quarter where the entire company takes a break from normal, daily activities to refresh and rejuvenate
- Volunteerism Time Off :*5 days of paid time off each year to participate in the volunteer activities of your choice.
- Paid Birthday Off: *Take your birthday off to celebrate you!
- Mobile Allowance Benefit :*This allowance will be provided to ensure you have support for work-related communication and tasks.
- We Value You:*
- Employee Recognition: Ongoing recognition & rewards. Culture that emphasizes personal and professional growth.
- "At Invicti, we embrace diversity and individuality in all forms. Discrimination has no place here - regardless of race, religion, gender, age, ability, sexual orientation, or any other aspect that makes you unique. We're all about creating a space where everyone feels valued and included. So come as you are and join us in shaping the future of our industry."*
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Support security automation and Identity & Access Management (IAM) initiatives. • Implement, integrate, and operationalize security technologies while developing automation and integration among enterprise security tools. • Work closely with IT and security teams to design, deploy, and maintain secure systems. • Play a critical role in enhancing enterprise security posture, mitigating threats, and ensuring compliance with applicable security frameworks. • Ensure consistent application of security measures across business applications and infrastructure. • Conduct security monitoring, SIEM analysis, and reporting.
Security Engineer
SenseOnSenseOn makes advanced cybersecurity quickly accessible for organisations of all sizes. Our mission is your mission.
• Author and maintain detection rules across SenseOn's dual-engine architecture: • Real-time streaming detections evaluated in milliseconds, written as YAML compiled to binary rulesets • Batch behavioral detections backed by parameterised ClickHouse SQL, running on a seconds-to-minutes cadence • Write aggregations and materialised views in ClickHouse that power statistical anomaly baselines • Build and extend our hunting query library. MITRE-mapped ClickHouse queries that analysts use daily for threat hunting • Map every rule precisely to MITRE ATT&CK techniques and tactics, including subtechnique granularity • Instrument your own rules: measure false positive rates, define confidence scores, build test datasets, and own the quality of what ships • Tune detections against real-world telemetry. Understanding why a rule fires is as important as making it fire • Extend our existing LLM driven rule writing engine to have much wider coverage • Design and build pipelines where LLMs can propose detection rules from threat intelligence, CVE disclosures, or analyst hunt findings, with structured output, YAML validation, and human-in-the-loop approval gates • Build feedback loops: when a detection fires or produces a false positive, that signal should flow back to improve future AI-generated rules • Define the prompt engineering and evaluation harness for detection generation. Pass@k metrics, FP/TP scoring, MITRE alignment validation • Work with engineering to make the detection data model AI-legible: schemas, annotations, and context structures that LLMs can reason over reliably • Think about our hunting interface: how does an analyst describe a threat in natural language and get a validated ClickHouse query back?
• Develop and implement the organization's information security strategy. • Provide regular security updates to the CIO, other executives, and the board of directors, including presentations on security matters. • Represent the organization in security-related matters with external parties, including vendors and auditors. • Work closely with the CIO and operate as a member of the DevOps team to emphasize and implement security initiatives. • Conduct regular risk assessments and vulnerability scans using tools like Rapid7 IVM and internal tracking systems. • Oversee the development and implementation of incident response plans and conduct tabletop exercises with DevOps team members. • Ensure compliance with relevant regulations and standards, including HITRUST, NIST, DirectTrust, HIPAA, SOC 2 (Type II), ISO. • Manage internal and external security audits, including evidence collection and preparation. • Develop, review, and update information security policies and procedures, including the Vulnerability and Patch Management Procedure and Data Center Access Procedure. • Participate in the day-to-day operations of the security team and manage security tools and technologies, including Check Point, SentinelOne, and intrusion detection systems. • Lead and mentor the security team, reviewing tasks and responsibilities working closely with the DevOps team members. • Evaluate and manage security vendors, including VDA Labs, KnowBe4, and perform vendor audits.
Sales Development Representative, Tech, SaaS, Cybersecurity
Hire Hangar GlobalOffshoring as a service. Hire the top 1% of flexible, global talent. $0 fees to get started.
• Execute outbound prospecting campaigns via phone, email, and LinkedIn • Qualify inbound and outbound leads to identify sales-ready opportunities • Educate prospects on Tech, SaaS, cybersecurity, FinTech, and AI solutions • Set qualified meetings and demos for Account Executives • Research target accounts and identify key stakeholders • Maintain accurate CRM records and pipeline activity




