Intercontinental Exchange Holdings, Inc.

Director, Application Security

Intercontinental Exchange Holdings, Inc. Atlanta, Georgia, United States

Financial Services · 10,001+ employees

20 h ago
security Principal (10+ yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Director of Application Security will lead teams responsible for secure software development and cloud security through continuous testing, education, and consultation. They will also manage security programs, oversee bug bounty initiatives, and implement cutting-edge security tools and AI-driven technologies.

What they look for

Application Security Cloud Security Software Development Lifecycle Vulnerability Management Team Leadership Risk Assessment Java C++ Python AWS Azure Bug Bounty Programs Secure Coding AI-assisted Vulnerability Detection Security Policy Management Mentorship

Requirements

Candidates must have a bachelor's degree in a technical discipline and extensive experience running enterprise-scale application security programs. Proficiency in software engineering languages like Java, C++, or Python and expertise in cloud platforms such as AWS or Azure are required.

Full description

Overview

Job Purpose

As a Director in this role, you will lead two teams responsible for assuring secure software development and cloud security through education, continuous testing, and consultation.

Responsibilities

  • Competently differentiates FUD and hype from legitimate business risk and assigns practical severity ratings to detected weaknesses
  • Demonstrates compromise of detected vulnerabilities to educate and motivate development teams
  • Adopts and improves on an established education, testing, and remediation methodology. Innovates and ensures all areas of the programs are operated effectively and results are distilled into meaningful metrics. Articulately codifies and communicates the Application and Cloud Security programs through writing and discussion
  • Recruits, retains, and motivates highly talented staff and balances the need to allocate tasks efficiently with the need to keep talent engaged, challenged, and growing
  • Successfully run an established enterprise AppSec program at scale, with 2,000+ applications and a large pool of developers
  • Coaches and develops team leaders, including newer leadership hires, within an already high-performing, well-structured team
  • Committed to continuous education and being a recognized industry leader in Application and Cloud Security
  • Application Identification and Review: is responsible for maintenance, execution, and reporting of the AppSec assurance tasks from Design Review through operating a Bug Bounty program
  • Standards and Policies: owns the Application Development Security Policy and is responsible for timely, practical updates, communication, and education
  • Secure Design: establishes security requirements early in the SDLC and contributes security subject matter expertise during the development of new projects and releases
  • Tool Management: implements and maintains cutting-edge technology to assess and protect applications and cloud environments throughout the SDLC and post deployment
  • Evaluates and applies AI and machine learning capabilities within the AppSec space, including AI-assisted vulnerability detection, AI-powered code review and testing tooling, and securing AI-integrated development pipelines
  • Developer Education: keeps software engineers apprised of secure coding practices and builds strong rapport and respect with the ICE application development community
  • Cloud Practitioner: provides security leadership and solutions to business and technical teams as they look to build or buy products in the cloud
  • Bug Bounty Program: operates a responsible disclosure program that appropriately incentivizes and fosters positive relationships with security researchers

Knowledge and Experience

  • Bachelor's degree in Computer Science, Engineering, MIS, CIS, or a related discipline
  • Hands-on or program-level experience applying AI in the AppSec space
  • Software engineering experience in Java, C++, Python, and/or related languages
  • Hands-on experience with information security and related technologies

Preferred Skills

  • Background in financial services or a comparable regulated enterprise environment
  • Technical expertise and understanding of AWS and/or Azure cloud platforms
  • Hands-on experience with information security and related technologies
  • Participation and leadership in Application Security consortia such as OWASP

#LI-LG

----------

Intercontinental Exchange, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to legally protected characteristics.

Similar roles