Director Application Security
We are seeking an experienced and visionary Director Application Security to lead the strategy, development, and execution of our Application Security program. This leader will be responsible for maturing and optimizing application security capabilities across the software development lifecycle, ensuring secure-by-design principles are embedded into engineering practices while enabling rapid delivery of innovative products.
This individual will partner closely with Engineering, Product Management, Architecture, DevOps, Cloud Engineering, and Security Operations to integrate security into every phase of software development. The successful candidate will have extensive experience building or transforming Application Security programs within complex technology organizations and will possess the ability to influence engineering culture through collaboration rather than gatekeeping.
Role Responsibilities:
- Application Security Strategy
- Secure Development Lifecycle (SSDLC)
- Security Testing & Assurance
- DevSecOps Enablement
- Operationalize Continuous Threat & Exposure Management (CTEM)
- Cloud & Modern Architecture Security
- Engineering Partnership
- Leadership
Role Requirements:
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related field required.
- Advanced degree preferred.
- 10+ years of progressive experience in Application Security, Software Security, Product Security, Secure Engineering, or related cybersecurity disciplines.
- 5+ years leading Application Security teams.
- Demonstrated success building, transforming, or significantly maturing Application Security programs within enterprise organizations.
- Experience partnering closely with software engineering organizations in Agile and DevSecOps environments.
- Strong understanding of:
- Secure Software Development Lifecycle (SSDLC)
- OWASP Top 10
- Secure coding principles
- Threat modeling
- Modern authentication protocols
- API security
- Cloud-native application security
- Container security
- CI/CD security
- DevSecOps
- Software supply chain security
- AI-assisted software development ("vibe coding") governance and secure use
- Application vulnerability management
- Possesses at least one of the following certifications (or comparable alternative): CISSP, CSSLP, GIAC Secure Software Programmer (GSSP), GIAC Cloud Security Automation (GCSA)
What Success Looks Like:
- Complete a comprehensive assessment of the organization's Application Security maturity.
- Develop and execute a multi-year Application Security transformation roadmap.
- Fully integrate security into CI/CD pipelines across major engineering organizations.
- Implement meaningful risk-based application security metrics and executive dashboards.
- Reduce application vulnerability remediation times while improving engineering satisfaction.
- Standardize threat modeling, secure code review, and security testing practices.
- Develop measurable improvements in software security posture without negatively impacting developer productivity.
Work Shift - HYBRID
Benefits
You will also have access to short-term incentives, multiple health insurance options, accident and life insurance, and access to best-in-class development platforms, to name a few. Please see the benefits below specific to your country. If applicable, additional role-specific benefits will be mentioned during your interview process or in an offer of employment.
Your United States specific benefits include:
- Parental Leave
- Family First Programs
- Medical, Dental, and Life Insurance
- Tuition Repayment Assistance Program
Salary
The base salary range is $200,000 - $215,000 USD per year, total on target compensation includes a base salary plus a variable target incentive that aligns with individual and company performance.
Other Details
As part of the application process, all applicants are required to take assessments. Western Union has partnered with a 3rd party provider to administer these tests. Applicants will need to provide their name and email address in order to process the assessments. If you have any questions, you may reach out to careers@westernunion.com.
We are passionate about honoring our employee's identity and fostering a feeling of belonging. Our commitment is to provide an inclusive culture that celebrates the unique backgrounds and perspectives of our global teams while reflecting the communities we serve. We do not discriminate based on race, color, national origin, religion, political affiliation, sex (including pregnancy), sexual orientation, gender identity, age, disability, marital status, or veteran status. The company will provide accommodation to applicants, including those with disabilities, during the recruitment process, following applicable laws.