ForgeApply · Job listing
Director Application Security
Western Union
See all 33 open roles at Western Union →
Tailor your resume for this Western Union job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Western Union's site. Free trial, no card required.
About this role
We are seeking an experienced and visionary Director Application Security to lead the strategy, development, and execution of our Application Security program. Reporting to the Vice President of Security Operations, this leader will be responsible for maturing and optimizing application security capabilities across the software development lifecycle, ensuring secure-by-design principles are embedded into engineering practices while enabling rapid delivery of innovative products.
This individual will partner closely with Engineering, Product Management, Architecture, DevOps, Cloud Engineering, and Security Operations to integrate security into every phase of software development. The successful candidate will have extensive experience building or transforming Application Security programs within complex technology organizations and will possess the ability to influence engineering culture through collaboration rather than gatekeeping.
Role Responsibilities: Application Security Strategy • Develop and execute the enterprise Application Security strategy aligned with business and technology objectives.
• Build and mature a scalable Application Security program supporting modern software development practices.
• Define the long-term roadmap for secure software development across cloud, web, mobile, APIs, and emerging technologies.
• Establish secure-by-design principles and integrate them throughout the Software Development Life Cycle (SDLC).
Secure Development Lifecycle (SSDLC) • Lead the implementation and continuous improvement of a Secure Software Development Lifecycle (SSDLC).
• Develop standards and security requirements for application development.
• Partner with engineering teams to integrate security early within CI/CD pipelines.
• Promote developer-friendly security practices that minimize friction while improving software security.
Security Testing & Assurance Oversee enterprise application security testing, including: • Static Application Security Testing (SAST)
• Dynamic Application Security Testing (DAST)
• Software Composition Analysis (SCA)
• Interactive Application Security Testing (IAST)
• API Security Testing
• Container Security
• Infrastructure-as-Code (IaC) Security
• Secure code reviews
• Penetration testing coordination
DevSecOps Enablement • Partner with DevOps teams to embed automated security controls into CI/CD pipelines.
• Improve automation of security testing and vulnerability management.
• Reduce developer burden through integrated tooling and streamlined workflows.
• Measure security effectiveness while enabling engineering velocity.
Vulnerability Management • Establish application vulnerability management standards and service level objectives.
• Prioritize remediation activities based on exploitability and business risk.
• Develop executive reporting for application security risk.
• Track remediation effectiveness across engineering organizations.
Cloud & Modern Architecture Security Provide application security guidance for: • Cloud-native applications
• Microservices
• APIs
• Containers
• Kubernetes
• Serverless architectures
• Artificial Intelligence and Machine Learning applications
• Third-party integrations
Engineering Partnership • Build trusted relationships with engineering leadership.
• Champion security as an engineering quality function.
• Develop security champions programs across engineering organizations.
Leadership • Lead, mentor, and develop a high-performing Application Security team.
• Establish performance metrics and operational objectives.
• Manage vendor relationships and application security technologies.
• Support hiring and organizational growth as the program matures.
• Mentor developers on secure coding practices and emerging threats.
Role Requirements: • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related field required.
• Advanced degree preferred.
• 10+ years of progressive experience in Application Security, Software Security, Product Security, Secure Engineering, or related cybersecurity disciplines.
• 5+ years leading Application Security teams.
• Demonstrated success building, transforming, or significantly maturing Application Security programs within enterprise organizations.
• Experience partnering closely with software engineering organizations in Agile and DevSecOps environments.
• Strong understanding of: • Secure Software Development Lifecycle (SSDLC)
• OWASP Top 10
• Secure coding principles
• Threat modeling
• Modern authentication protocols
• API security
• Cloud-native application security
• Container security
• CI/CD security
• DevSecOps
• Software supply chain security
• AI-assisted software development ("vibe coding") governance and secure use
• Application vulnerability management
• Possesses at least one of the following certifications (o4 comparable alternative): • CISSP
• CSSLP
• GIAC Secure Software Programmer (GSSP)
• GIAC Cloud Security Automation (GCSA)
What Success Looks Like: Within the first 12–18 months, this leader will • Complete a comprehensive assessment of the organization's Application Security maturity.
• Develop and execute a multi-year Application Security transformation roadmap.
• Fully integrate security into CI/CD pipelines across major engineering organizations.
• Implement meaningful risk-based application security metrics and executive dashboards.
• Reduce application vulnerability remediation times while improving engineering satisfaction.
• Standardize threat modeling, secure code review, and security testing practices.
• Develop measurable improvements in software security posture without negatively impacting developer productivity.
Work Shift - HYBRID
Benefits You will also have access to short-term incentives, multiple health insurance options, accident and life insurance, and access to best-in-class development platforms, to name a few. Please see the benefits below specific
Salary insight
The midpoint of this range ($208k) is about 28% above the median disclosed salary for Austin roles listed on ForgeApply ($163k across 938 jobs).
See full Security Engineer salary data for Austin →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Western Union role before you apply.
Tailor my resume for this jobSimilar jobs
- Director, Application Security — Zetaglobal · San Francisco, CA
- Staff Application Security Architect — Rocket · Seattle - 100 Stewart St | Detroit, MI
- Director, App Security — Wwecorp · New York, NY
- Staff Application Security Engineer — Abridge · Remote
- Staff Application Security Engineer — Reltio · United States
- Staff Application Security Engineer — Brex · United States
- Staff Application Security Engineer — Thenuclearcompany · Washington, DC
- Staff Application Security Engineer — Gemini · New York, New York; Miami, Florida; Remote (USA)
More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in Austin · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)