AVP Cybersecurity
Jobgether United States · $172K–$258K/yr
Internet Marketplace Platforms · 11-50 employees
About the role
You will lead and mature a comprehensive application security and DevSecOps program while remaining hands-on with technical tasks like threat modeling and secure code reviews. The role involves mentoring security engineers, optimizing security toolchains, and partnering with cross-functional teams to embed security into the SDLC.
What they look for
Requirements
Candidates must have 8+ years of experience in application security or DevSecOps, including at least 3 years in a leadership or technical lead capacity. Proficiency in programming languages, cloud security, and security frameworks like OWASP and NIST is required.
Benefits
Full description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an AVP Cybersecurity based in the United States.
This is a senior, hands-on cybersecurity leadership role focused on building and advancing a comprehensive application security and DevSecOps program. You will shape secure software development practices across the organization, embedding security throughout the SDLC from design through deployment. The role combines strategic ownership with deep technical involvement in areas such as threat modeling, secure code review, vulnerability management, and security architecture. You will lead and mentor highly skilled security professionals while partnering closely with engineering, product, architecture, and infrastructure teams. A major focus will be strengthening automation, security tooling, cloud and application protection, and proactive risk management. You will also translate application security risks and program performance into clear insights for executive stakeholders. This remote opportunity offers the chance to influence security strategy at scale while remaining a credible and active technical practitioner.
\n
Accountabilities
- Build, lead, and continuously mature a comprehensive application security and DevSecOps program covering secure SDLC practices, SAST, DAST, SCA, container and cloud-native security, and API security.
- Remain actively involved in technical security work, including secure code reviews, threat modeling, security architecture assessments, critical vulnerability triage, and hands-on remediation guidance.
- Lead, mentor, and develop application security engineers and embedded security champions, strengthening technical capabilities and supporting long-term team growth.
- Design, implement, configure, and optimize the application security toolchain, integrating security controls and automated gates into CI/CD pipelines in partnership with engineering teams.
- Own application vulnerability management, including finding triage, risk prioritization, remediation SLAs, escalation processes, and direct leadership of high-severity vulnerability response.
- Partner with engineering, product, and architecture leaders to introduce security requirements and threat modeling early in product and feature development, advancing a shift-left security approach.
- Develop and maintain secure coding standards, application security policies, DevSecOps playbooks, and training programs that promote secure development practices.
- Oversee third-party and open-source software security, including software composition analysis and remediation of vulnerable dependencies.
- Report application security risk posture, key program metrics, vulnerability trends, and remediation progress to executive leadership and other stakeholders.
- Participate in application-level security incident response, including root cause analysis, containment support, and remediation planning.
- Encourage innovation and the practical use of emerging technologies, including AI, to improve security processes, reduce friction, and enhance operational effectiveness.
- Foster a culture built around collaboration, accountability, trust, initiative, inclusion, and continuous improvement.
Requirements
- 8+ years of experience in application security, secure software development, DevSecOps, or a closely related discipline, including substantial hands-on engineering or security engineering experience.
- 3+ years of experience in a leadership or technical lead capacity, with a demonstrated ability to mentor or manage teams while remaining technically engaged.
- Strong knowledge of application security principles and frameworks, including OWASP ASVS, OWASP Top 10, and NIST SSDF.
- Hands-on experience with SAST, DAST, and SCA solutions such as Checkmarx, Veracode, Snyk, Semgrep, or Fortify, including configuration, tuning, troubleshooting, and optimization.
- Working proficiency in at least one programming language such as Java, Python, JavaScript/TypeScript, Go, or C#, sufficient for code review and security automation.
- Experience integrating security controls into CI/CD and DevOps environments such as Jenkins, GitHub Actions, GitLab CI, or Azure DevOps.
- Practical experience with cloud and container security across platforms such as AWS, Azure, or GCP, including technologies such as Docker and Kubernetes.
- Demonstrated expertise in threat modeling, including approaches such as STRIDE, and conducting application security architecture reviews.
- Experience developing and scaling vulnerability management programs, including remediation SLAs, prioritization frameworks, escalation procedures, and executive reporting.
- Relevant security certifications such as CSSLP, OSCP, GWAPT, or CISSP are preferred.
- Strong analytical and critical-thinking skills, with the ability to assess complex risks, prioritize effectively under pressure, and meet deadlines.
- Excellent communication and presentation skills, with the ability to translate technical security risks into clear business implications for non-technical and executive audiences.
- Strong collaboration, stakeholder management, and relationship-building abilities, with a track record of working effectively across diverse teams.
- Demonstrated curiosity and openness to innovation, including the ability to explore and apply AI and emerging technologies to improve security processes and outcomes.
- Comfortable working independently while providing credible technical leadership to a highly skilled cybersecurity team.
- Willingness and ability to travel to client, temporary, or corporate office locations as business needs require.
Benefits
- Annual salary range of $171,750–$257,700, depending on experience and other job-related factors.
- Comprehensive benefits designed to support physical, emotional, and financial well-being, including healthcare, paid time off, retirement, and wellness programs.
- Remote work flexibility, with travel and occasional onsite work required according to business needs.
- Professional development opportunities and support for relevant certifications.
- Tuition reimbursement to support continued learning and career growth.
- Career advancement opportunities within a collaborative, innovation-focused environment.
- Quarterly and annual recognition and incentive programs for employees who deliver exceptional results.
- A people-focused culture emphasizing innovation, leadership, collaboration, continuous improvement, and meaningful impact.
\nHow Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Similar roles
-
Government Cybersecurity Attorney | Government Contracts | $260K–$365K
Purple Cow Recruiting Washington, Maryland, United States · $260K–$365K/yr
-
Senior Cybersecurity Operations Analyst
DEFEND Limited Auckland, Auckland, New Zealand
-
RMF Cybersecurity Analyst II - 505767
Delaware Nation Industries Bath Township, Ohio, United States
-
AI Platform Security Engineer
Advanced Micro Devices, Inc San Diego, California, United States
- Junior Cloud Security Engineer Internship
-
Senior Manager - Product Cybersecurity (Remote)
United Airlines Chicago, Illinois, United States · $141K–$183K/yr