Sr. Manager, Application Security

5 months ago
Full-time
Lead
Cybersecurity
Prosper

Prosper

Prosper is an online marketplace lending platform that connects borrowers with lenders, offering personal loans, credit cards, and home equity options. With a focus on financial education, Prosper helps individuals manage their finances and achieve pea...

Banks
251-1K
Founded 2005
$490M raised

Description

  • Define and execute a multi-year application security roadmap aligned with business goals and industry best practices.
  • Integrate threat modeling, security testing, and secure-by-design practices into the SDLC and CI/CD pipeline.
  • Perform security architecture reviews for major product changes.
  • Oversee the end-to-end application security vulnerability lifecycle, including identification, prioritization, and remediation based on risk and threat intelligence.
  • Direct and manage incident response for application security alerts and incidents.
  • Lead the strategy for third-party penetration tests and offensive security activities.
  • Deliver executive-level dashboards and reports on application security posture and risk trends.
  • Manage, mentor, and develop a high-performing team of application security engineers.
  • Drive continuous improvement in application security processes and leadership awareness of product and application security risks.
  • Collaborate with Engineering and Product leadership to embed security into the SDLC and scale the Security Champions program.

Requirements

  • 10+ years of progressive application security experience.
  • 3+ years of people leadership experience leading and developing a technical Application Security Engineering team.
  • Prior software development experience preferred.
  • Strong interpersonal skills and the ability to foster constructive dialogue.
  • Deep technical knowledge with a track record of successful execution in secure SDLC, penetration testing, and security tooling.
  • Experience with SAST, DAST, IAST, RASP, and SCA tools.
  • Strong knowledge of CI/CD pipelines.
  • Experience with cloud-native security, specifically GCP.
  • Experience with container security.
  • Bachelor's degree in Computer Science or a related field, or equivalent work experience.
  • Strong working knowledge of at least two programming or scripting languages.

Benefits

  • Competitive salary of $226,000 - $270,000 annually, plus bonus.
  • 401(k) with a 5% company match.
  • Flexible time off.
  • Paid parental leave.
  • Annual wellness allowance.
  • Comprehensive health coverage.
  • Remote work flexibility, including fully remote options.
  • Udemy access, childcare assistance, pet insurance, and additional savings through Beneplace.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Application Security Engineer - Senior

Banco Plata, S.A., Institución de Banca Múltiple. 1001-5000 Banking / financial services

Plata is seeking an Application Security Engineer to join its Information Security team and embed security controls, testing, and practices throughout the software development lifecycle.

Burp Suite CI/CD Kubernetes Microservices OWASP Penetration Testing
1 day, 21 hours ago

Senior Product Security Engineer

payabl. 51-250 Diversified Financial Services

Payabl is seeking a Senior Product Security Engineer to establish and embed product security across its payments engineering organization, integrating secure practices throughout the software development lifecycle.

AWS CI/CD Penetration Testing
1 day, 21 hours ago

Senior Product Security Engineer (Contract)

Iru Enterprise IT, cybersecurity, identity/security, endpoint management, compliance software

Iru is seeking a Senior Product Security Engineer for a 6-month, 40-hour-per-week contract to embed security throughout the software development lifecycle and help teams build secure-by-design products.

AWS Azure GCP GitHub Actions Kubernetes Microservices OAuth OpenID Connect
3 days, 20 hours ago

Senior Application Security Engineer

Radicle Health 11-50 Internet Software & Services

Radicle Health is seeking a Senior Application Security Engineer to strengthen security across its 10 SaaS platforms by integrating security tooling and practices into software development and operations.

AWS HIPAA OWASP Penetration Testing
3 days, 21 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers