Manager, Application Security
Location
United States
Posted
113 days ago
Salary
$150K - $190K / year
Seniority
Lead
Job Description
Manager, Application Security
Cast & Crew
About Us At Cast & Crew, we’ve empowered creativity and supported the global entertainment industry for decades. Together with our family of brands - Backstage, CAPS, Checks & Balances, Final Draft, Media Services, Sargent-Disc, and The TEAM Companies – we operate as a combined entertainment technology and services provider offering industry standard screenwriting accounting software, digital payroll products, data & reporting, and a host of creative tools. The industry continues to move faster than ever, and the need for our expertise, our technology, and our people has never been greater. We are a production’s best ally every step of the way. #OneCastOneCrew We’re not looking for a security manager who used to write code. We’re looking for an engineer who happens to also lead people. The Manager, Application Security will own Cast & Crew’s application security program end-to-end — from threat modeling and code review to exploit development, red teaming, and building the tooling and pipelines that catch vulnerabilities before they ship. You will be deeply embedded in the engineering organization, embedded in pull requests, embedded in architecture conversations, and embedded in the minds of the developers you partner with. This role sits at the intersection of elite offensive security skills, deep software engineering fluency, and the ability to lead and develop a small but high-impact team. You will report to the CISO and work closely with the VP of Engineering and product teams across a complex, multi-product environment handling sensitive payroll, financial, and production data for major studios and streaming platforms. If you read CVEs for fun, have strong opinions about parser differentials, and can pivot from reviewing a threat model to writing a PoC exploit to coaching a junior engineer — this role was written for you. As the Manager of Product Security, you will build and lead a team responsible for embedding security into every phase of our software development lifecycle. You'll work at the intersection of application security, cloud infrastructure security, and DevSecOps, partnering closely with engineering, operations, and product teams to ensure that security is not an afterthought but a foundational element of everything we build. This is a leadership role for someone who is equally comfortable setting strategic direction, mentoring team members, and rolling up their sleeves to solve complex technical security challenges. You will manage a team of security engineers and analysts, drive our DevSecOps transformation, participate in architecture reviews, and champion a "shift left" security culture across the organization. If you're passionate about building secure software at scale, thrive in a collaborative environment, and want to make a tangible impact on an industry that touches millions of workers, we want to hear from you. What You’ll Do Application Security Engineering - Own and execute the full application security testing lifecycle: SAST, DAST, SCA, manual code review, and penetration testing across web, API, and mobile surfaces. - Write exploits. When a finding is disputed or unclear, you prove it — PoC code, not a CVSS score and a policy citation. - Perform deep manual code review across multiple languages and frameworks. You don’t rely solely on scanners; you read the code. - Lead threat modeling sessions for new features and architecture changes. You drive these, not just attend them. - Build and maintain internal security tooling — custom scanners, fuzz harnesses, pipeline integrations, automation scripts — in Python, Go, or similar. - Define and enforce secure coding standards across the SDLC. Champion shift-left security without being a blocker. - Operate and continuously tune SAST/DAST/SCA tooling (Snyk, Semgrep, Burp Suite, or equivalents) integrated into CI/CD pipelines. - Run or coordinate red team exercises and adversarial simulations against Cast & Crew products and infrastructure. - Lead vulnerability triage, root cause analysis, and post-incident security reviews for product security incidents. Team Leadership - Lead, mentor, and develop a team of security engineers and analysts (currently: 2 Application Security Engineers and an Application Security Analyst). - Set technical direction for the team. Your engineers should become better engineers because they work for you. - Conduct regular 1:1s, performance reviews, and career development conversations. - Hire and grow the team as the program scales. You know what good looks like because you’ve been it. - Build a culture of rigor and curiosity — where the team questions assumptions, hunts proactively, and owns outcomes. Engineering Partnership - Embed with engineering teams. Attend sprint planning, architecture reviews, and design sessions — not just as an observer but as a contributor. - Participate in the Architecture Review Board. Block what needs to be blocked; approve fast what doesn’t. - Build relationships with senior engineers and tech leads based on technical credibility. They should want you in the room. - Translate security risk into engineering language. No FUD, no compliance theater — clear, prioritized, evidence-based guidance. - Partner with the GRC team on SOC 2 and NIST 800-53 compliance for product security domains. - Collaborate with Corporate Security Operations on detection, response, and threat intelligence relevant to the product surface. What We’re Looking For Required - 7+ years in application security, offensive security, or product security — with hands-on technical depth throughout. Not 7 years of managing AppSec programs from a distance. - You write code. Not just scripts — real, production-quality code. Python, Go, Java, or similar. Security engineers who can’t code are a hard pass. - Deep, demonstrable expertise in at least three of the following: - Web application hacking: SQLi, XSS, SSRF, deserialization, auth flaws, business logic — you find these manually, not just with a scanner - Secure code review across multiple languages and frameworks - API security: REST, GraphQL, gRPC — you know where the attack surface lives - Cloud-native application security on AWS (IAM abuse, metadata service attacks, misconfigured S3/Lambda/ECS) - CI/CD pipeline security and DevSecOps toolchain integration - Exploit development, PoC writing, or red team operations - Fuzzing, static analysis, or custom security tooling development - 2+ years managing or leading security engineers, including mentorship and performance ownership. - Strong understanding of the entire vulnerability lifecycle: discovery, triage, reproduction, remediation validation, and root cause. - Experience working directly inside engineering orgs — reading PRs, attending standups, influencing architecture. Not operating from a separate security silo. - Can communicate technical risk clearly to both engineers and executives. No jargon substitutes for clarity. Strong Preference - CVEs to your name, bug bounty hall of fame credits, published research, CTF competition history, or an equivalent public body of offensive security work. - OSCP, OSED, OSWE, GWAPT, or similar offensive certifications. CISSP alone is not sufficient signal for this role. - Experience building internal security tooling from scratch — not just configuring vendor products. - Background in software development prior to moving into security. Engineers who crossed over understand how developers think. - Experience in regulated environments handling PII, financial data, or payroll data — SOC 2, NIST 800-53, CCPA familiarity. - Familiarity with secrets management (HashiCorp Vault, AWS Secrets Manager), container security, and IaC security (Terraform, CloudFormation). - Experience running or coordinating bug bounty programs and working with external researchers. You Are - Obsessively curious about how systems break. You read CVE disclosures and think about what you would have found first. - A multiplier. Your team gets sharper working with you — not dependent on you. - Pragmatic about risk. You know when to push hard and when a compensating control is good enough. - Allergic to security theater. Compliance checkboxes without security outcomes are not your idea of a good program. - Direct. You tell engineers — and executives — the truth about risk, even when it’s uncomfortable. - A continuous learner. The threat landscape moves. You move with it. Benefits Cast & Crew provides a comprehensive package of employee benefits including: Medical, Dental, Vision, PTO, health and wellness programs, employee discounts, and more! Note: Cast & Crew benefits are subject to eligibility requirements. Cast & Crew is an equal opportunity employer committed to hiring a diverse workforce and sustaining an inclusive culture. It is our policy to provide equal employment opportunities to all individuals based on job-related qualifications and ability to perform a job, without regard to age, gender, gender identity, sexual orientation, race, color, religion, creed, national origin, disability, genetic information, veteran status, citizenship or marital status, and to maintain a non-discriminatory environment free from intimidation, harassment or bias based upon these grounds. CA residents Your personal information may be collected in connection with certain services provided by Cast & Crew or its affiliated companies. A summary of your California privacy rights can be found at: https://www.castandcrew.com/privacy-policy/ Compensation is commensurate with various factors including, but not limited to, relevant experience, qualifications, skills, training, licensure, certifications, geographic cost of labor, and other business and organizational needs. Compensation range for candidates in other locations may differ based on the cost of labor in that location. The compensation range for this position is: $150,000.00 - $190,000.00 per year.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Computer Systems Specialist
Diné Development CorporationDiné Development Corporation (DDC) is a Navajo Nation enterprise dedicated to advancing sustainable economic prosperity for the Navajo people. Its mission focu
The Computer Systems Specialist supports evaluation, analysis, and optimization of computer systems, hardware, and software applications within the DLA EFM portfolio. The role focuses on troubleshooting system issues, supporting integration efforts, and recommending improvements to enhance system performance and maintainability. *This position is contingent upon contract award.* Responsibilities - Evaluate computer hardware and software to support mission requirements - Analyze system interfaces and integration with other systems - Troubleshoot system bottlenecks and recommend solutions - Support system optimization and performance improvements - Assist with system implementation, maintenance, and sustainment activities - Provide analytical support for system development and integration tasks - Utilize Microsoft tools and project management concepts to support analysis and reporting - Performs other related duties as assigned Qualifications - Basic understanding of IT systems, hardware, and software environments - Ability to troubleshoot and analyze system issues - Familiarity with system integration concepts - Proficiency with Microsoft tools - Strong analytical and problem-solving skills - Years of Experience: One (1) year of relevant experience - Education Level: Not specified - Clearance Requirements: Moderate Risk, Confidential, Non-Critical Sensitive; Tier 3 / NACLC / ANACI Any other work-related qualifications needed for the role: - Microsoft Suite (Word, Excel, Access, PowerPoint) - Project management familiarity - Ability to support enterprise IT environments About Us Diné Development Corporation (DDC) is a Navajo Nation owned family of companies that provides government agencies and commercial organizations with high-quality IT, professional, environmental, and research and development services. DDC is dedicated to empowering the Navajo Nation and communities we serve. Benefits Eligible full-time employees receive a comprehensive benefits package, including medical, dental, vision, life and disability coverage, retirement savings with company match, paid time off, voluntary supplemental benefits, and access to an employee assistance program. The package also includes educational assistance, with tuition reimbursement. EEO Statement This contractor and subcontractor shall abide by the requirements of 41 CFR 60-1.4(a), 60-300.5(a) and 60-741.5(a). These regulations prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, religion, sex, sexual orientation, gender identity, national origin, or for inquiring about, discussing, or disclosing information about compensation, or any other basis prohibited by law. We participate in E-Verify.
Senior Cybersecurity Engineer
RSB Automotive Consulting - | System | Embedded | Functional Safety | Cybersecurity |Driving automotive innovation through talent
• Support the design, analysis, and implementation of cybersecurity frameworks aligned with EU regulations and certification schemes • Contribute to security evaluations of ICT products and services within frameworks such as Common Criteria and EU cybersecurity certification schemes • Perform risk assessments in line with standards such as ISO/IEC 27005 and contribute to security assurance processes • Provide expertise on EU regulatory landscape, including Cybersecurity Act, NIS2, CRA, DORA, and eIDAS 2.0 • Participate in or lead technical workstreams related to cloud security (EUCS), managed security services (EU MSS), and digital identity frameworks (EUDI Wallet) • Support security assessments related to telecommunications and critical infrastructure (e.g. EU 5G initiatives) • Prepare high-quality technical documentation, reports, and assessments for stakeholders • Collaborate with cross-functional teams and external stakeholders, including regulatory bodies and standardisation groups
About Certora Certora is the security assurance partner trusted by the most advanced teams in Web3. Founded in 2018 by pioneers in programming languages and formal methods, Certora helps leading protocols like Lido, Aave, Uniswap, and Compound secure billions in value with confidence. But we’re not just another auditor. We’re a full-stack security assurance platform, combining best-in-class formal verification tools with expert advisory services, delivered on time and with zero compromise. Whether you’re launching a new protocol, upgrading core infrastructure, or securing a DeFi primitive, Certora doesn’t just look for vulnerabilities. We help you prove correctness, accelerate your development speed, and embed safety into your design from day one. With Certora, you get: - Proven, scalable tooling for checking real deployed code - A deep partnership model with on-demand support - Fast, responsive execution that helps you go-to-market faster For us, security isn’t a checklist, it’s a continuous process. Certora is the most comprehensive and trusted platform to ensure your platform is protected, even under adversarial conditions. From testnet to mainnet, we’re with you. About the role We are looking for brilliant security researchers who understand and can find security bugs in cryptographic primitives such as signatures, encryption, and zero-knowledge cryptography. The ideal candidate also cares about exploring the use of formal verification to secure code. Relevant skills - Experience reviewing cryptographic implementations, especially zero knowledge proof systems and circuits, and including MPC, signatures, and cryptographic libraries - Ability to dive into complex code bases written in Rust, C, C++ and other languages - Mathematically prove security properties of low-level code using state-of-the-art technology, including the Certora Prover and other products. Must-Have Requirements - An undergraduate degree in exact sciences from a strong university - The ability to quickly understand intricate programs, learn new protocols and frameworks, digest cryptography and security publications - Mathematical thinking - Hands-on cryptography understanding: the right candidate must be able to read and write code and come up with proof of concepts to demonstrate and communicate security claims - High integrity Significant Advantage - Previous experience in code auditing or vulnerability research - Expertise in code security and applied cryptography - Deep understanding of Blockchain technology (EVM, Solana) - Exposure to ZK technology: zkVMs, zkSNARKs or other proof systems - Understanding of Rust, Circom, Solidity - Publication of technical reports and blog posts - Participation in CTF’s/audit contests/bug bounties programs - Communication skills - High agency and ability to work independently - A European time zone or Eastern US is preferable Certora People We are Customer Centric, when we commit, the customer knows we will deliver in a quality and timely manner. We Move Fast - we’re looking for people with a bias for action and a sense of urgency to achieve quick results while we also Break Nothing – we have high-quality standards, we are looking for people who are professional and hold themselves accountable. We win as a Team – our teams are distributed around the world. We understand our individual roles and commit to the team's goals. We have a positive “can do” attitude. We support each other and are encouraged to ask for help and advice. We enable people to grow by clarifying expectations and giving candid feedback and on-the-job development opportunities. We welcome collaboration both internally and externally for outstanding delivery. We are Pioneers in DeFi security. We are one of the best companies to help developers and security researchers secure Web3, but we try to stay humble and are always eager to learn more. Why join Certora? Certora provides you a wonderful opportunity to: - Work on cutting-edge technology and challenging problems at the forefront of Web3 applications and technologies - Contribute to securing the web3 ecosystem with the leading provider of end-to-end security for blockchain-based applications - Experience a friendly creative start-up environment with top talent in the domain - Work in a fast-paced and supportive culture: we move fast and break nothing! - Enjoy flexible work (remote / hybrid) - Get competitive compensation & benefits (including equity)
Senior Information Security Consultant – SMB
CognisysYour trusted security & compliance partner for GRC consulting, CREST pen testing and vulnerability management.
• Lead and deliver GRC consulting engagements across a range of clients and industries. • Act as the primary point of contact for assigned clients, owning delivery quality and client satisfaction. • Design and implement GRC programmes aligned to frameworks such as ISO 27001, SOC 2, NIST, and related standards. • Lead security posture assessments, gap analyses, and maturity reviews. • Develop practical remediation roadmaps and guide clients through implementation. • Support clients through audit preparation, certification, and external assessments. • Facilitate client workshops, risk assessments and stakeholder sessions with confidence and authority. • Provide expert guidance on security governance, risk management, and compliance strategy. • Interpret standards and regulations and translate them into pragmatic, business-focused solutions. • Advise clients on control design, operating models, and sustainable compliance practices. • Support the development of client security documentation including policies, procedures, risk registers, control frameworks and governance models. • Help clients embed compliance into operational and technical processes rather than treating it as a one-off activity. • Own the quality of client deliverables, ensuring accuracy, clarity and consistency with internal standards. • Review and provide constructive feedback on work produced by junior consultants and analysts. • Continuously improve delivery playbooks, templates, and methodologies. • Ensure engagements are delivered on time, within scope, and to a high professional standard. • Mentor and support junior team members, accelerating their technical and consulting development. • Provide guidance, coaching, and informal line management support where required. • Act as a role model for consulting best practice and professional conduct. • Contribute to building a collaborative, high-performing team culture. • Identify opportunities to improve delivery efficiency, tooling, and ways of working. • Contribute to the development of a scalable and repeatable GRC consulting model. • Support pre-sales activity where required, including scoping, proposal input and client discovery sessions. • Help shape the strategic direction of the GRC practice through feedback and innovation.


