Job Closed
This listing is no longer active.
TrueML is a fintech company building software to create positive experiences for consumers seeking financial health.
Application Security Manager
Location
United States
Posted
166 days ago
Salary
$150K - $190K / year
Seniority
Senior
Job Description
Application Security Manager
TrueML
• Develop, implement, and maintain a comprehensive application security strategy aligned with business objectives and industry best practices. • Lead and mentor the app security team, fostering a culture of security awareness and continuous improvement across the organization. • Report to leadership on the status of the application security program, including risk posture, incidents, and performance metrics. • Evaluate and recommend new application security technologies and tools to enhance the organization's security posture. • Oversee the day-to-day security operations, including monitoring, threat detection, incident response, and vulnerability management. • Design, implement, and manage security controls for our cloud-based SaaS platform (AWS), corporate network, and endpoints. • Conduct regular application security assessments, penetration tests, and vulnerability scans, and manage the remediation of identified issues. • Maintain an application security risk management framework, identifying, analyzing, and treating risks. • Ensure compliance with relevant regulatory requirements and industry standards (e.g., ISO 27001, NIST, PCI DSS, GDPR). • Maintain and enforce application security policies, standards, and procedures. • Liaise and coordinate internal and external security audits. • Lead the security incident response team, managing all phases of the incident lifecycle from detection and containment to eradication and recovery. • Conduct post-incident reviews to identify root causes and implement preventative measures. • Manage, mentor, and develop the application security team.
Job Requirements
- Bachelor's degree in Computer Science, Information Security, or a related field; or equivalent practical experience.
- 5+ years of experience in application security, with at least 2+ years in a management or leadership role, preferably at a SaaS company.
- Proven experience designing and securing cloud-native environments (e.g., microservices, containers, serverless).
- Strong knowledge of vulnerability analysis, network security, infrastructure security, identity and access management, logging and monitoring, incident response, application security, and data protection technologies.
- Proven experience developing and managing an enterprise-level information security program.
- Relevant security certifications such as CISSP, CISM, or CISA.
- Familiarity with common exploitation techniques, attack vectors, and defensive strategies.
- Experience with SIEM tools, vulnerability scanners, penetration testing and threat model methodologies.
- Understanding of generative AI and its usage within security and engineering as well as best practices.
- Identity Management and Cloud Security.
- Exceptional communication and interpersonal skills to articulate complex security concepts to technical and non-technical audiences.
- Strong leadership, organizational, and project management abilities.
- Excellent problem-solving and decision-making skills.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Lead cross-functional, enterprise-wide projects and define the strategic direction for cutting-edge security development lifecycle (SDL) practices • Conduct security design reviews and sophisticated threat modeling for new and existing mission-critical services • Establish secure architecture standards, frameworks, and resilient security patterns • Evaluate, prototype, implement, operate, and provide governance over core security tools and services • Discover and analyze emerging security threats • Maintain a strong knowledge of current security threats • Drive security assessment, penetration testing, and bug bounty programs • Ensure all application security practices adhere to PCI DSS requirements • Participate in security incident response activities as a technical leader
Staff Security Engineer
Modern HealthOffering global, personalized mental health care designed to help you feel more resilient, productive, and empowered.
• Define and drive the strategic roadmap for proactive security vulnerability analysis in web and mobile applications, setting the organizational standard for risk determination and leading complex, company-wide remediations. • Establish the technical vision and program for integrating robust security controls at every stage of the Software Development Life Cycle (SDLC), championing secure development practices and scalable agile delivery. • Architect, deploy, and manage defensive security tooling (e.g., SAST, DAST, SCA) and evaluate new industry-leading application security solutions to create a robust, automated security platform. • Lead the maturation of the Product and Application Security Program by developing and implementing security policies, standards, and metrics to continually raise the security bar and demonstrate compliance. • Lead collaborative and cross-functional threat modeling initiatives for core systems, new features, and evolving services, ensuring proactive risk identification and structural security improvement. • Engage with Cloud Security efforts by partnering with DevOps and Infrastructure teams to assess, improve, and monitor cloud architecture, security policies, and cloud-native controls to ensure secure deployment and operations.
• Own the strategic relationship with assigned strategic customers • Drive business value and ensure long-term retention and growth • Serve as the primary business-facing contact and trusted advisor for customers • Own the post-sale customer journey from onboarding through renewal • Collaborate with Sales on long-term account strategy • Partner closely with TAMs to drive adoption of new capabilities • Develop and manage joint success plans aligned to customer objectives • Build strong relationships across executive, security, DevOps, and cloud leadership • Lead Quarterly Business Reviews (QBRs) and program reviews
• Own product roadmap, priorities, and execution • Translate cybersecurity workflows into clear product requirements • Work closely with Engineering, AI/ML, and Security Research teams • Define MVPs, iterate fast, and ship production-ready features • Gather feedback from customers, pilots, and internal stakeholders • Balance security depth, usability, and business goals • Contribute to product positioning and go-to-market alignment




