368,910open jobs
9,449companies
47,822added this week
Browse all
Salary
$200k – $215k per year
Location
Remote/Hybrid (Austin, United States)
Seniority
Architect · 10+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Western Union operates a global money transfer network spanning agents and digital channels. Customers send remittances to bank accounts, wallets and cash locations worldwide. The company has invested heavily in shifting transactions to its own app.

We are seeking an experienced and visionary Director Application Security to lead the strategy, development, and execution of our Application Security program. Reporting to the Vice President of Security Operations, this leader will be responsible for maturing and optimizing application security capabilities across the software development lifecycle, ensuring secure-by-design principles are embedded into engineering practices while enabling rapid delivery of innovative products.

This individual will partner closely with Engineering, Product Management, Architecture, DevOps, Cloud Engineering, and Security Operations to integrate security into every phase of software development. The successful candidate will have extensive experience building or transforming Application Security programs within complex technology organizations and will possess the ability to influence engineering culture through collaboration rather than gatekeeping.

Role Responsibilities:

Application Security Strategy

  • Develop and execute the enterprise Application Security strategy aligned with business and technology objectives.

  • Build and mature a scalable Application Security program supporting modern software development practices.

  • Define the long-term roadmap for secure software development across cloud, web, mobile, APIs, and emerging technologies.

  • Establish secure-by-design principles and integrate them throughout the Software Development Life Cycle (SDLC).

Secure Development Lifecycle (SSDLC)

  • Lead the implementation and continuous improvement of a Secure Software Development Lifecycle (SSDLC).

  • Develop standards and security requirements for application development.

  • Partner with engineering teams to integrate security early within CI/CD pipelines.

  • Promote developer-friendly security practices that minimize friction while improving software security.

Security Testing & Assurance

Oversee enterprise application security testing, including:

  • Static Application Security Testing (SAST)

  • Dynamic Application Security Testing (DAST)

  • Software Composition Analysis (SCA)

  • Interactive Application Security Testing (IAST)

  • API Security Testing

  • Container Security

  • Infrastructure-as-Code (IaC) Security

  • Secure code reviews

  • Penetration testing coordination

DevSecOps Enablement

  • Partner with DevOps teams to embed automated security controls into CI/CD pipelines.

  • Improve automation of security testing and vulnerability management.

  • Reduce developer burden through integrated tooling and streamlined workflows.

  • Measure security effectiveness while enabling engineering velocity.

Operationalize Continuous Threat & Exposure Management (CTEM) across critical applications and business services

  • Define CTEM scope around critical business services, crown-jewel applications, sensitive data, material APIs, and externally exposed assets.
  • Consolidate exposure signals from application testing, attack-surface management, cloud security, vulnerability management, penetration testing, bug bounty, and threat intelligence.
  • Establish a common exposure taxonomy and risk model that incorporates exploitability, reachability, business criticality, threat activity, and compensating controls.
  • Maintain an evidence-backed view of application exposure rather than relying primarily on scanner severity.

Cloud & Modern Architecture Security

Provide application security guidance for:

  • Cloud-native applications

  • Microservices

  • APIs

  • Containers

  • Kubernetes

  • Serverless architectures

  • Artificial Intelligence and Machine Learning applications

  • Third-party integrations

Engineering Partnership

  • Build trusted relationships with engineering leadership.

  • Champion security as an engineering quality function.

  • Develop security champions programs across engineering organizations.

Leadership

  • Lead, mentor, and develop a high-performing Application Security team.

  • Establish performance metrics and operational objectives.

  • Manage vendor relationships and application security technologies.

  • Support hiring and organizational growth as the program matures.

  • Mentor developers on secure coding practices and emerging threats.

Role Requirements:

  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related field required.

  • Advanced degree preferred.

  • 10+ years of progressive experience in Application Security, Software Security, Product Security, Secure Engineering, or related cybersecurity disciplines.

  • 5+ years leading Application Security teams.

  • Demonstrated success building, transforming, or significantly maturing Application Security programs within enterprise organizations.

  • Experience partnering closely with software engineering organizations in Agile and DevSecOps environments.

  • Strong understanding of:

    • Secure Software Development Lifecycle (SSDLC)

    • OWASP Top 10

    • Secure coding principles

    • Threat modeling

    • Modern authentication protocols

    • API security

    • Cloud-native application security

    • Container security

    • CI/CD security

    • DevSecOps

    • Software supply chain security

    • AI-assisted software development ("vibe coding") governance and secure use

    • Application vulnerability management

  • Possesses at least one of the following certifications (o4 comparable alternative):

    • CISSP

    • CSSLP

    • GIAC Secure Software Programmer (GSSP)

    • GIAC Cloud Security Automation (GCSA)

What Success Looks Like:

Within the first 12-18 months, this leader will

  • Complete a comprehensive assessment of the organization's Application Security maturity.

  • Develop and execute a multi-year Application Security transformation roadmap.

  • Fully integrate security into CI/CD pipelines across major engineering organizations.

  • Implement meaningful risk-based application security metrics and executive dashboards.

  • Reduce application vulnerability remediation times while improving engineering satisfaction.

  • Standardize threat modeling, secure code review, and security testing practices.

  • Develop measurable improvements in software security posture without negatively impacting developer productivity.

Work Shift - HYBRID

Benefits

You will also have access to short-term incentives, multiple health insurance options, accident and life insurance, and access to best-in-class development platforms, to name a few. Please see the benefits below specific to your country. If applicable, additional role-specific benefits will be mentioned during your interview process or in an offer of employment.

Your United States specific benefits include:

  • Parental Leave

  • Family First Programs

  • Medical, Dental, and Life Insurance

  • Tuition Repayment Assistance Program

For residents of Colorado, California, Connecticut, Delaware, Minnesota, and Pennsylvania: Please do not respond to any questions on this initial application that may seek age-identifying information such as age, date of birth, or dates of school attendance or graduation. You may also redact this information from any materials you submit during the application process. You will not be penalized for redacting or removing this information.

Salary

The base salary range is $200,000 - $215,000 USD per year, total on target compensation includes a base salary plus a variable target incentive that aligns with individual and company performance.

Other Details

As part of the application process, all applicants are required to take assessments. Western Union has partnered with a 3rd party provider to administer these tests. Applicants will need to provide their name and email address in order to process the assessments. If you have any questions, you may reach out to [email protected].

We are passionate about honoring our employee's identity and fostering a feeling of belonging. Our commitment is to provide an inclusive culture that celebrates the unique backgrounds and perspectives of our global teams while reflecting the communities we serve. We do not discriminate based on race, color, national origin, religion, political affiliation, sex (including pregnancy), sexual orientation, gender identity, age, disability, marital status, or veteran status. The company will provide accommodation to applicants, including those with disabilities, during the recruitment process, following applicable laws.

#LI-AM3

Estimated Job Posting End Date:

09-14-2026

This application window is a good-faith estimate of the time that this posting will remain open. This posting will be promptly updated if the deadline is extended or the role is filled.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,910 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Austin
$98k – $195k per year (Estimated) • In office • Full-Time • 7+ years exp • Wellington
Java
Python
SQL
Java
Spring Boot
Databases
Apache Kafka
Databricks
Neo4j
AI/ML
Flink
Spark
Frontend
GraphQL
DevOps
Azure
CI/CD
Datadog
Dynatrace
Kibana
Kubernetes
OpenShift
Platform Engineering
Splunk
Amazon ECS
Apply
$84k – $178k per year (Estimated) • In office • Full-Time • 10+ years exp • Wellington
Java
Python
DevOps
Ansible
AWS
Azure
CI/CD
Docker
GCP
Helm
Kubernetes
Platform Engineering
Prometheus
Service Mesh
Terraform
GitLab
IAM
Apply
$123k – $251k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Dallas • Denver • Birmingham
Java
SQL
Java
Gradle
Hibernate
Maven
Spring Boot
Spring Framework
Databases
Apache Kafka
MySQL
Redis
DevOps
CI/CD
Dynatrace
Jenkins
Kubernetes
OpenShift
Cybersecurity
SonarQube
Apply
$28k – $58k per year (Estimated) • Remote/Hybrid • Full-Time • 7+ years exp • Moscow
DevOps
Ansible
CI/CD
FinOps
Kubernetes
OpenStack
SLI/SLO/SLA
Terraform
VMWare
Apply
Platform Engineer 1 day ago
$87k – $140k per year • In office • Full-Time • 3+ years exp • Berlin
Databases
PostgreSQL
Redis
DevOps
AWS
Azure
Bicep
CI/CD
Docker
GCP
GitHub Actions
Kubernetes
OpenShift
Terraform
GitHub
Apply
$97k – $195k per year (Estimated) • In office • Full-Time • 7+ years exp • Bachelor's Degree • Denver • Atlanta • Austin
AI/ML
AI Agents
Apply
$110k – $150k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Austin
JavaScript
TypeScript
Frontend
Angular
DevOps
AWS
AWS Lambda
CI/CD
Docker
Amazon ECS
Amazon S3
API Gateway
Apply
$140k – $180k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • New York
Web3
DeFi
MetaMask
Apply
$135k – $160k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Austin
Java
Java
Apache Camel
Spring Boot
Databases
Apache Kafka
DynamoDB
PostgreSQL
Redis
DevOps
AWS
CI/CD
Apply
$215k – $245k per year • Remote/Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • New York
Web3
DeFi
Apply
$96k – $200k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Hillsboro • Austin
C++
AI/ML
NCCL
DevOps
HPC
Apply
In office • Internship • Master's Degree • Austin
C++
Python
C++
PyTorch C++
AI/ML
AI Agents
CUDA
CUDA Toolkit
LLM
NCCL
PyTorch
TensorRT
TensorRT-LLM
Triton
vLLM
Apply
$106k – $145k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Austin
Apply
$70k – $206k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
AI/ML
AI Agents
Apply
$100k – $180k per year • Equity • Remote • Full-Time • 7+ years exp • Bachelor's Degree • Austin
DevOps
VMWare
Cybersecurity
ISO 27001
SOC 2
Zero Trust
Apply
See all jobs
This is one of many
368,910 more open roles from verified company boards, updated every day.