Sr. Manager, Application Security

3 months, 1 week ago
Full-time
Lead
Cybersecurity
Prosper

Prosper

Prosper is an online marketplace lending platform that connects borrowers with lenders, offering personal loans, credit cards, and home equity options. With a focus on financial education, Prosper helps individuals manage their finances and achieve pea...

Banks
251-1K
Founded 2005
$490M raised

Description

  • Define and execute a multi-year application security roadmap aligned with business goals and industry best practices.
  • Integrate threat modeling, security testing, and secure-by-design practices into the SDLC and CI/CD pipeline.
  • Perform security architecture reviews for major product changes.
  • Oversee the end-to-end application security vulnerability lifecycle, including identification, prioritization, and remediation based on risk and threat intelligence.
  • Direct and manage incident response for application security alerts and incidents.
  • Lead the strategy for third-party penetration tests and offensive security activities.
  • Deliver executive-level dashboards and reports on application security posture and risk trends.
  • Manage, mentor, and develop a high-performing team of application security engineers.
  • Drive continuous improvement in application security processes and leadership awareness of product and application security risks.
  • Collaborate with Engineering and Product leadership to embed security into the SDLC and scale the Security Champions program.

Requirements

  • 10+ years of progressive application security experience.
  • 3+ years of people leadership experience leading and developing a technical Application Security Engineering team.
  • Prior software development experience preferred.
  • Strong interpersonal skills and the ability to foster constructive dialogue.
  • Deep technical knowledge with a track record of successful execution in secure SDLC, penetration testing, and security tooling.
  • Experience with SAST, DAST, IAST, RASP, and SCA tools.
  • Strong knowledge of CI/CD pipelines.
  • Experience with cloud-native security, specifically GCP.
  • Experience with container security.
  • Bachelor's degree in Computer Science or a related field, or equivalent work experience.
  • Strong working knowledge of at least two programming or scripting languages.

Benefits

  • Competitive salary of $226,000 - $270,000 annually, plus bonus.
  • 401(k) with a 5% company match.
  • Flexible time off.
  • Paid parental leave.
  • Annual wellness allowance.
  • Comprehensive health coverage.
  • Remote work flexibility, including fully remote options.
  • Udemy access, childcare assistance, pet insurance, and additional savings through Beneplace.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Product Security Engineer

Anduril Industries 1K-5K Aerospace & Defense

Anduril Industries is hiring a Product Security Engineer in the UK to secure advanced defense technologies, including AI systems, command and control platforms, aerospace vehicles, and long-range sensors.

C C++ Cybersecurity Embedded Systems Go IoT Linux Network Security Python Rust
4 hours, 30 minutes ago

Applications Security Specialist

Marathon Talent 1-10 Human Resources

R2 is hiring an Application Security Engineer to help secure its fintech platform and infrastructure as it expands financial services for SMBs across Latin America.

Burp Suite CI/CD Go Kubernetes Microservices Penetration Testing
5 hours ago

Application Security Engineer — Secure Mission Systems

Rackner 11-50 Internet Software & Services

Rackner is hiring a remote Application Security Engineer to strengthen secure software for Department of Defense mission systems through hands-on testing, vulnerability remediation, and secure delivery support.

CI/CD Git GitLab Kubernetes OpenShift
1 day, 3 hours ago

Product Security Engineer

Action1 11-50 Internet Software & Services

Action1 is seeking a Product Security Engineer to help secure its multi-tenant SaaS platform by partnering with engineering, product, and security teams to identify risks early and strengthen secure development practices.

AWS C++ Cybersecurity DevSecOps JavaScript Network Security Penetration Testing
1 day, 4 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers