Talent.com
Director, Secure SDLC & Application Security
Director, Secure SDLC & Application SecurityIron Mountain • Boston, MA, United States
Director, Secure SDLC & Application Security

Director, Secure SDLC & Application Security

Iron Mountain • Boston, MA, United States
21 hours ago
Job type
  • Full-time
Job description

At Iron Mountain we know that work, when done well, makes a positive impact for our customers, our employees, and our planet. That’s why we need smart, committed people to join us. Whether you’re looking to start your career or make a change, talk to us and see how you can elevate the power of your work at Iron Mountain.

Job Summary

We are looking for a highly influential and experienced Director, Secure SDLC & Application Security to mature and establish control gates across our secure software development environments and practices. This strategic role is responsible for embedding security into every stage of our Software Development Lifecycle (SDLC, SP 800-64), guided by the principles of the NIST Secure Software Development Framework (SSDF, SP 800-218). This position bridges our development, IT, and cybersecurity organizations and reports directly to the CTO with a dotted line to the CISO.

Key Responsibilities

Strategic Ownership & Influence : Own the strategy for embedding security within the development lifecycle and act as the primary security partner for development leaders.

Secure SDLC Partnership & Compliance : Drive and manage key functions like threat modeling, automated testing, secure design reviews, and secure deployment practices in partnership with the CISO organization.

FedRAMP Application Compliance & Enablement : Ensure all applications meet FedRAMP technical controls and that all required documentation and evidence are properly created, maintained, and delivered for audits and Authorization to Operate (ATO) packages.

Policy and Process Development : Establish, maintain, and enforce secure coding standards, vulnerability management procedures, and policies for the use of third‑party and open‑source software.

Business Unit Security Leadership : Provide direct leadership for information security compliance across the Digital Business Unit’s development and product functions.

Cross‑Functional Partnership : Serve as the key liaison between the CTO’s engineering teams, the CISO’s security organization, and the broader IT organization.

Tooling and Automation Integration : Drive the strategy for security tooling within the CI / CD pipeline, including compliance with SAST, DAST, and SCA.

Metrics and Dual Reporting : Develop KPIs to measure the effectiveness of the application security program and provide clear, concise reports and updates on our software security posture.

Qualifications and Skills

Experience :

10+ years of experience in software development or information security, with at least 5 years in a leadership, principal, or senior role focused on application / product security.

Demonstrable experience implementing and managing a secure SDLC based on a recognized framework like NIST SSDF (800-218).

Direct, hands‑on experience developing and securing applications within FedRAMP High and / or Moderate compliant cloud environments.

Proven success in a matrixed environment, influencing change and driving initiatives across multiple teams and departments without direct authority.

Work Authorization :

  • Applicants must be legally authorized to work in the United States without the need for current or future visa sponsorship.

Technical Skills :

Expertise in threat modeling (e.g., STRIDE), secure coding practices, and modern application security vulnerabilities (OWASP Top 10).

Hands‑on experience with security testing tools (SAST, DAST, SCA and penetration tests) and their integration into developer workflows (GitLAB and Veracode).

Proven capability to utilize Tenable for enterprise‑wide vulnerability detection and compliance, driving remediation within SLA across diverse DevOps environments.

Strong understanding of DevOps / DevSecOps principles and CI / CD pipelines.

Experience building developer enablement programs covering secure coding, threat modeling, SBOM generation, and vulnerability management requirements.

Define secure baselines for third‑party components, open‑source dependencies and container registries.

Familiarity with cloud‑native security (AWS GovCloud, GCP, Azure Government).

Influence and Communication :

Exceptional stakeholder management skills, with the ability to build consensus between engineering, security, and business leaders.

Excellent ability to articulate complex security risks and concepts to varied audiences, from engineers to senior executives.

Education and Certifications :

Bachelor’s degree in Computer Science, Information Security, or a related field; Master’s degree preferred.

Relevant industry certifications (e.g., CISSP, CSSLP, GCSA) are highly desirable.

#LI-Remote

Reasonably expected salary range : $159,400.00 - $212,500.00

Category : Information Technology

Iron Mountain is a global leader in storage and information management services trusted by more than 225,000 organizations in 60 countries. We safeguard billions of our customers’ assets, including critical business information, highly sensitive data, and invaluable cultural and historic artifacts.

If you have a physical or mental disability that requires special accommodations, please let us know by sending an email to accommodationrequest@ironmountain.com. See the Supplement to learn more about Equal Employment Opportunity.

Iron Mountain is committed to a policy of equal employment opportunity. We recruit and hire applicants without regard to race, color, religion, sex (including pregnancy), national origin, disability, age, sexual orientation, veteran status, genetic information, gender identity, gender expression, or any other factor prohibited by law.

#J-18808-Ljbffr

Create a job alert for this search

Application Security • Boston, MA, United States

Related jobs
Sr. Staff Analyst, Information Security

Sr. Staff Analyst, Information Security

1010 Analog Devices Inc. • Wilmington, MA, United States
Full-time +1
NASDAQ : ADI ) is a global semiconductor leader that bridges the physical and digital worlds to enable breakthroughs at the Intelligent Edge. ADI combines analog, digital, and software technologie...Show more
Last updated: 30+ days ago • Promoted
Director of Infrastructure Security

Director of Infrastructure Security

VirtualVocations • Lowell, Massachusetts, United States
Full-time
A company is looking for a Director, Infrastructure Security Services.Key Responsibilities Lead the design and implementation of enterprise-wide security capabilities to protect critical IT asset...Show more
Last updated: 30+ days ago • Promoted
Workday Application Security & Controls Director

Workday Application Security & Controls Director

PRICE WATERHOUSE COOPERS • Boston, MA, United States
Full-time
A career in Enterprise Application Risk will allow you to develop and apply strategies that help clients leverage enterprise technologies to get a higher return on their investment, mitigate risks,...Show more
Last updated: 18 days ago • Promoted
Director, Cloud Security Specialist

Director, Cloud Security Specialist

Fidelity Investments • Boston, MA, United States
Full-time
The Cloud Security Center of Excellence within Fidelity Enterprise Cyber Security (ECS) is seeking a cloud or data platforms focused security engineer who has broad security domain knowledge includ...Show more
Last updated: 12 days ago • Promoted
Associate Director, Software Security Architecture and Enablement

Associate Director, Software Security Architecture and Enablement

KPMG US • Boston, MA, United States
Full-time
Associate Director, Software Security Architecture and Enablement.Associate Director, Software Security Architecture and Enablement. KPMG is currently seeking an Associate Director, Software Securit...Show more
Last updated: 5 days ago • Promoted
Director of Governance Risk Compliance

Director of Governance Risk Compliance

VirtualVocations • Lowell, Massachusetts, United States
Full-time
A company is looking for a Director of Governance, Risk, and Compliance (GRC).Key Responsibilities Develop and direct an enterprise-wide GRC program to support growth and security Lead and manag...Show more
Last updated: 30+ days ago • Promoted
Alliance Director

Alliance Director

VirtualVocations • Dorchester, Massachusetts, United States
Full-time
A company is looking for an Alliance Director - API Security.Key Responsibilities Define and execute the strategic partnership roadmap aligned with business goals Own and grow relationships with...Show more
Last updated: 30+ days ago • Promoted
Senior SOC Manager

Senior SOC Manager

VirtualVocations • Lowell, Massachusetts, United States
Full-time
A company is looking for a Senior Security Operations Center (SOC) Manager.Key Responsibilities Oversee daily SOC activities for timely detection and response to security incidents Manage, mento...Show more
Last updated: 30+ days ago • Promoted
Senior Director of Security Engineering

Senior Director of Security Engineering

VirtualVocations • Lowell, Massachusetts, United States
Full-time
A company is looking for a Senior Director of Security Engineering.Key Responsibilities Define and implement the long-term vision and strategy for the security engineering function Build and lea...Show more
Last updated: 3 days ago • Promoted
Senior Director, Cyber Security (Hybrid - San Diego, CA or Acton, MA)

Senior Director, Cyber Security (Hybrid - San Diego, CA or Acton, MA)

Insulet Corporation • , MA, United States
Full-time
Senior Director, Cyber Security (Hybrid - San Diego, CA or Acton, MA) page is loaded## Senior Director, Cyber Security (Hybrid - San Diego, CA or Acton, MA)locations : San Diego, California : Act...Show more
Last updated: 22 days ago • Promoted
Global Channel MSSP Program Director

Global Channel MSSP Program Director

Right Seat • Boston, MA, United States
Full-time
Global Channel MSSP Program Director.Our Client is seeking a Channel MSSP Program Director to lead and expand strategic partnerships with top global Managed Security Services Providers (MSSPs), inc...Show more
Last updated: 30+ days ago • Promoted
Safety and Security Director

Safety and Security Director

Boston Health Care for the Homeless Program • Boston, MA, US
Full-time +1
We are seeking a Safety and Security Director to join our team at Boston Health Care for the Homeless Program.As a Safety and Security Director, you will be responsible for the overall safety and s...Show more
Last updated: 18 days ago • Promoted
Director of Information Security Operations

Director of Information Security Operations

Southern New Hampshire University • Boston, MA, United States
Full-time
Southern New Hampshire University is a team of innovators.Individuals who believe in progress with purpose.Since 1932, our people-centered strategy has defined us - and helped us grow a team that n...Show more
Last updated: 2 days ago • Promoted
Senior Director, Enterprise Applications

Senior Director, Enterprise Applications

Vertex Pharmaceuticals • Boston, MA, United States
Full-time
KEY RESPONSIBILITIES : • • Work closely with Information Security, Internal Audit and Quality Assurance groups as needed to ensure compliance with Sarbanes-Oxley (SOX) and GxP regulations, as well as ...Show more
Last updated: 20 days ago • Promoted
Global Channel MSSP Program Director

Global Channel MSSP Program Director

ZipRecruiter • Boston, MA, United States
Full-time
Global Channel MSSP Program Director.Role Summary : Our Client is seeking a Channel MSSP Program Director to lead and expand strategic partnerships with top global Managed Security Services Provider...Show more
Last updated: 19 days ago • Promoted
Cybersecurity Product Management Director

Cybersecurity Product Management Director

VirtualVocations • Lowell, Massachusetts, United States
Full-time
A company is looking for a Director of Product Management, Cybersecurity.Key Responsibilities Define and own the cybersecurity product and managed services roadmap, aligning with enterprise custo...Show more
Last updated: 1 day ago • Promoted
Senior Manager, Information Security

Senior Manager, Information Security

VirtualVocations • Lowell, Massachusetts, United States
Full-time
Manager, Information Security Risk Management.Key Responsibilities Lead the supplier governance program and oversee supplier due diligence processes Partner with stakeholders for supplier sourci...Show more
Last updated: 30+ days ago • Promoted
Managing Director, Cryptography

Managing Director, Cryptography

State Street • Quincy, Massachusetts, United States
Full-time
This job is with State Street, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.Who we are ...Show more
Last updated: 9 days ago • Promoted