Sr. Manager, Application Security

4 months ago
Full-time
Lead
Cybersecurity
Prosper

Prosper

Prosper is an online marketplace lending platform that connects borrowers with lenders, offering personal loans, credit cards, and home equity options. With a focus on financial education, Prosper helps individuals manage their finances and achieve pea...

Banks
251-1K
Founded 2005
$490M raised

Description

  • Define and execute a multi-year application security roadmap aligned with business goals and industry best practices.
  • Integrate threat modeling, security testing, and secure-by-design practices into the SDLC and CI/CD pipeline.
  • Perform security architecture reviews for major product changes.
  • Oversee the end-to-end application security vulnerability lifecycle, including identification, prioritization, and remediation based on risk and threat intelligence.
  • Direct and manage incident response for application security alerts and incidents.
  • Lead the strategy for third-party penetration tests and offensive security activities.
  • Deliver executive-level dashboards and reports on application security posture and risk trends.
  • Manage, mentor, and develop a high-performing team of application security engineers.
  • Drive continuous improvement in application security processes and leadership awareness of product and application security risks.
  • Collaborate with Engineering and Product leadership to embed security into the SDLC and scale the Security Champions program.

Requirements

  • 10+ years of progressive application security experience.
  • 3+ years of people leadership experience leading and developing a technical Application Security Engineering team.
  • Prior software development experience preferred.
  • Strong interpersonal skills and the ability to foster constructive dialogue.
  • Deep technical knowledge with a track record of successful execution in secure SDLC, penetration testing, and security tooling.
  • Experience with SAST, DAST, IAST, RASP, and SCA tools.
  • Strong knowledge of CI/CD pipelines.
  • Experience with cloud-native security, specifically GCP.
  • Experience with container security.
  • Bachelor's degree in Computer Science or a related field, or equivalent work experience.
  • Strong working knowledge of at least two programming or scripting languages.

Benefits

  • Competitive salary of $226,000 - $270,000 annually, plus bonus.
  • 401(k) with a 5% company match.
  • Flexible time off.
  • Paid parental leave.
  • Annual wellness allowance.
  • Comprehensive health coverage.
  • Remote work flexibility, including fully remote options.
  • Udemy access, childcare assistance, pet insurance, and additional savings through Beneplace.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Staff Product Certification Manager

PQShield 11-50 Semiconductors & Semiconductor Equipment

PQShield is hiring an Experienced Security Certification Manager/Engineer to lead certification efforts for its RISC-V and post-quantum cryptography security IP platform.

CI/CD GitLab CI HubSpot
1 week ago

Staff Application Security Engineer

Beyond Finance 251-1K Banks

Beyond Finance is hiring a Staff Application Security Engineer to own and advance application security across its product and cloud engineering teams.

AWS CI/CD CloudFormation Go Python React Native Ruby on Rails Secrets Management Terraform
1 week, 5 days ago

Senior Security Engineer - Product Security

Ondo Finance 11-50 Diversified Financial Services

Ondo Finance is hiring a Senior Security Engineer for Product Security to secure its tokenized real-world asset platform by partnering with product engineering on threat modeling, secure reviews, and security-by-default delivery.

CI/CD Encryption Go JavaScript OAuth OpenID Connect Penetration Testing Python Rust Terraform TypeScript
2 weeks ago

Senior Application Security Engineer

Counterpart Health 51-200 hospital & health care

Counterpart Health is hiring a Senior Application Security Engineer to secure its AI-enabled primary care platform, Counterpart Assistant, by finding and fixing vulnerabilities that affect clinicians during live patient visits.

Penetration Testing
2 weeks ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers