See all roles

DevSecOps & Application Security Lead

Work from home Full-time role Hiring

We are looking for a DevSecOps and Application Security Lead to join our team and build our application security from scratch. In this role, you will lead the security direction within our department, focusing on integrating security into the software development process. By balancing automation with practical DevSecOps practices, you will help our engineering teams find and fix vulnerabilities early, ensuring our products are safe and strong without slowing down development.

Responsibilities

Build the DevSecOps/AppSec function from scratch, and create the roadmap, KPIs, and metrics for leadership Create secure development processes, including release security gates and vulnerability management Choose, configure, and integrate security scanners (SAST, SCA, secrets) with a focus on automation and AI-assisted workflows Integrate security checks into pipelines and development processes together with Engineering, DevOps, and Product teams Run threat modeling and security reviews for high-risk systems and major architecture changes Create clear security standards, checklists, and practical guidelines for developers (covering code, APIs, and secrets) Launch and grow a Security Champions program to involve engineers in security processes Help investigate incidents related to application vulnerabilities, leaked secrets, and supply-chain attacks Requirements 5+ years of experience in DevOps, SRE, Platform Engineering, or related infrastructure/security roles 3+ years focused on DevSecOps and Application Security 1+ years in a lead/ownership role Deep understanding of modern software development, Git workflows, and hands-on experience integrating security checks into CI/CD pipelines without creating bottlenecks Practical experience with SAST, SCA, secrets scanning, and vulnerability management (triage, risk rating, remediation, and validation) Ability to select and scale security tools based on accuracy, false-positive rates, and developer experience Strong knowledge of web/API/mobile risks (OWASP Top 10, auth, supply-chain risks) and ability to run threat modeling and secure design reviews Good scripting skills (Python, Bash, or similar) and understanding of cloud-native/containerized environments Ability to write clear security requirements and guidelines for developers English - Intermediate+ or higher

Nice to Have

Experience building AppSec/DevSecOps functions from scratch or early maturity stages Hands-on experience with tools like Snyk, Aikido, Semgrep, Trivy, Gitleaks, GitHub/GitLab Security, or SonarQube Experience with cloud/IaC security, Kubernetes, and mobile app security Knowledge of compliance standards (SOC 2, ISO 27001, PCI DSS, DORA) and experience with Bug Bounty or pentest coordination Experience with Security Champions programs and AI-assisted security tools We offer 20 paid vacation days per year 10 paid sick leave days per year Public holidays as per the company’s approved Public holiday list Medical budget Opportunity to work remotely Professional education budget Language learning budget Wellness budget (gym membership, sports gear and related expenses) Apply To This Job

You might like

Data Engineer

Work from home Full-time role

Data Scientist

Work from home Full-time role

Senior Infrastructure Engineer

Work from home Full-time role

HVAC Controls Operator

Work from home Full-time role

HVAC Monitoring Technician

Work from home Full-time role

Senior Consultant, Data Engineer

Work from home Full-time role

Business Development Manager

Work from home Full-time role

Senior Performance Marketing Designer

Work from home Full-time role

Talent Community - R&D

Work from home Full-time role

Regional Sales Manager (CO/UT/AZ and NV)

Work from home Full-time role

Content Fellow, Math

Work from home Full-time role

Pearson – HR Business Partner II (Remote) – Columbia, MD

Work from home Full-time role

Experienced Full Stack Customer Support Representative – Ramp Agent (Customer Service Agent) at blithequark

Work from home Full-time role

[Remote/WFM] Customer Service Representatives

Work from home Full-time role

Onsite Data Entry Clerk – Vermont (South Burlington) – Full‑Time Day & Evening Shifts – Competitive Hourly Pay & Career Growth at arenaflex

Work from home Full-time role

Experienced and Dedicated West Middle School General Education Noon Recess Building Paraeducator

Work from home Full-time role

Apply Now: Work Remotely as a Sales Pro: Flexible Hours, Great

Work from home Full-time role

Experienced Operations Research Analyst - United Airlines Employee Satisfaction with $25/Hour Compensation

Work from home Full-time role

Experienced Data Entry Representative – Remote Opportunity for a Dynamic Team

Work from home Full-time role

Unity Developer / VFX Artist

Work from home Full-time role