Overview
In this role you will strengthen the secure software development lifecycle across technology projects for a global investment manager. You will work with cross‑functional teams to design and operate appsec tooling and practices, reducing vulnerabilities and enabling secure delivery. You’ll lead and mentor in a growing security function while leveraging automation, AI-assisted evaluation, and cloud security tools to mitigate risk at scale. This is a hands‑on, impact‑driven position that combines security engineering with collaboration to protect critical applications.
Responsibilities
- Collaborate with software and security engineers to design, maintain and improve product security tooling and services
- Act as technical advisor to product teams on automation, CI/CD and application security operations
- Use AI models and security harnesses to assess code for logic flaws and vulnerabilities
- Develop tools and automation scripts to enable developers to consume security services
- Oversee security product QA and testing processes
- Foster strong partnerships with product development teams
- Operate and optimize SCA, SAST, DAST, and IaC security tooling
- Explain penetration testing findings to engineers and guide risk mitigation
- Assess business risk of software vulnerabilities for decision making
- Improve security tooling coverage in cloud environments (Azure, AWS) and WAF/IDS capabilities
Key requirements
- Computer Science/Cyber Security degree
- Application development background
- Azure DevOps experience
- Experience using AI models for security evaluation of code
- Proficiency in at least one programming language (Python/JavaScript/C#/PowerShell)
- CISSP/CSSLP/CEH/OSCP or similar certification
- Strong analytical skills and attention to detail
- Excellent English communication and presentation skills
- Team player and collaborative mindset
- Team leadership
- Strong communication with non-technical stakeholders
- Collaboration across cross-functional teams
- Azure DevOps
- GitHub, Copilot, Codex
- OWASP Top 10
…
