This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an AVP Cybersecurity based in the United States.
This is a senior, hands-on cybersecurity leadership role focused on building and advancing a comprehensive application security and DevSecOps program.
You will shape secure software development practices across the organization, embedding security throughout the SDLC from design through deployment.
The role combines strategic ownership with deep technical involvement in areas such as threat modeling, secure code review, vulnerability management, and security architecture.
You will lead and mentor highly skilled security professionals while partnering closely with engineering, product, architecture, and infrastructure teams.
A major focus will be strengthening automation, security tooling, cloud and application protection, and proactive risk management.
You will also translate application security risks and program performance into clear insights for executive stakeholders.
This remote opportunity offers the chance to influence security strategy at scale while remaining a credible and active technical practitioner.
Accountabilities
- Build, lead, and continuously mature a comprehensive application security and DevSecOps program covering secure SDLC practices, SAST, DAST, SCA, container and cloud-native security, and API security.
- Remain actively involved in technical security work, including secure code reviews, threat modeling, security architecture assessments, critical vulnerability triage, and hands-on remediation guidance.
- Lead, mentor, and develop application security engineers and embedded security champions, strengthening technical capabilities and supporting long-term team growth.
- Design, implement, configure, and optimize the application security toolchain, integrating security controls and automated gates into CI/CD pipelines in partnership with engineering teams.
- Own application vulnerability management, including finding triage, risk prioritization, remediation SLAs, escalation processes, and direct leadership of high-severity vulnerability response.
- Partner with engineering, product, and architecture leaders to introduce security requirements and threat modeling early in product and feature development, advancing a shift-left security approach.
- Develop and maintain secure coding standards, application security policies, DevSecOps playbooks, and training programs that promote secure development practices.
- Oversee third-party and open-source software security, including software composition analysis and remediation of vulnerable dependencies.
- Report application security risk posture, key program metrics, vulnerability trends, and remediation progress to executive leadership and other stakeholders.
- Participate in application-level security incident response, including root cause analysis, containment support, and remediation planning.
- Encourage innovation and the practical use of emerging technologies, including AI, to improve security processes, reduce friction, and enhance operational effectiveness.
- Foster a culture built around collaboration, accountability, trust, initiative, inclusion, and continuous improvement.
- 8+ years of experience in application security, secure software development, DevSecOps, or a closely related discipline, including substantial hands-on engineering or security engineering experience.
- 3+ years of experience in a leadership or technical lead capacity, with a demonstrated ability to mentor or manage teams while remaining technically engaged.
- Strong knowledge of application security principles and frameworks, including OWASP ASVS, OWASP Top 10, and NIST SSDF.
- Hands-on experience with SAST, DAST, and SCA solutions such as Checkmarx, Veracode, Snyk, Semgrep, or Fortify, including configuration, tuning, troubleshooting, and optimization.
- Working proficiency in at least one programming language such as Java, Python, JavaScript/TypeScript, Go, or C#, sufficient for code review and security automation.
- Experience integrating security controls into CI/CD and DevOps environments such as Jenkins, GitHub Actions, GitLab CI, or Azure DevOps.
- Practical experience with cloud and container security across platforms such as AWS, Azure, or GCP, including technologies such as Docker and Kubernetes.
- Demonstrated expertise in threat modeling, including approaches such as STRIDE, and conducting application security architecture reviews.
- Experience developing and scaling vulnerability management programs, including remediation SLAs, prioritization frameworks, escalation procedures, and executive reporting.
- Relevant security certifications such as CSSLP, OSCP, GWAPT, or CISSP are preferred.
- Strong analytical and critical-thinking skills, with the ability to assess complex risks, prioritize effectively under pressure, and meet deadlines.
- Excellent communication and presentation skills, with the ability to translate technical security risks into clear business implications for non-technical and executive audiences.
- Strong collaboration, stakeholder management, and relationship-building abilities, with a track record of working effectively across diverse teams.
- Demonstrated curiosity and openness to innovation, including the ability to explore and apply AI and emerging technologies to improve security processes and outcomes.
- Comfortable working independently while providing credible technical leadership to a highly skilled cybersecurity team.
- Willingness and ability to travel to client, temporary, or corporate office locations as business needs require.
- Annual salary range of $171,750-$257,700, depending on experience and other job-related factors.
- Comprehensive benefits designed to support physical, emotional, and financial well-being, including healthcare, paid time off, retirement, and wellness programs.
- Remote work flexibility, with travel and occasional onsite work required according to business needs.
- Professional development opportunities and support for relevant certifications.
- Tuition reimbursement to support continued learning and career growth.
- Career advancement opportunities within a collaborative, innovation-focused environment.
- Quarterly and annual recognition and incentive programs for employees who deliver exceptional results.
- A people-focused culture emphasizing innovation, leadership, collaboration, continuous improvement, and meaningful impact.

