Назад
Company hidden
5 часов назад

AVP Cybersecurity (DevSecOps)

171 750 - 257 700$
Формат работы
remote (только USA)/onsite
Тип работы
fulltime
Грейд
head
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
AVP Cybersecurity (DevSecOps): Building and maturing an application security program covering secure SDLC, DevSecOps tooling, vulnerability management, and security architecture with an accent on hands-on code reviews, threat modeling, and CI/CD security automation. Focus on integrating SAST, DAST, SCA, container, cloud, and API security while leading critical vulnerability remediation and reporting application risk to executive leadership.

Location: Remote nationwide within the United States; candidates must reside in and be authorized to work in the United States. Travel to and work onsite at client, temporary, or corporate office locations may be required as business needs dictate.

Salary: $171,750–$257,700 per year, based on experience.

Company

hirify.global provides technology-enabled revenue cycle management solutions and point solutions for hospitals, health systems, and affiliated physician groups.

What you will do

  • Build, lead, and mature the application security and DevSecOps program across the secure software development lifecycle.
  • Perform secure code reviews, threat modeling, security architecture reviews, and critical vulnerability triage.
  • Design and tune SAST, DAST, SCA, container scanning, secrets detection, and API security tooling.
  • Integrate security gates into CI/CD pipelines and embed security requirements into product and feature design.
  • Own application vulnerability management, including prioritization, remediation SLAs, escalation, and incident response.
  • Mentor application security engineers and security champions and report application risk metrics to executive leadership.

Requirements

  • 8+ years of experience in application security, secure software development, or DevSecOps, including hands-on engineering or security engineering work.
  • 3+ years in a leadership or technical lead capacity while remaining hands-on.
  • Experience with SAST, DAST, SCA tools, CI/CD pipelines, cloud security, and container or orchestration security.
  • Working proficiency in at least one programming language such as Java, Python, JavaScript/TypeScript, Go, or C#.
  • Experience with threat modeling, security architecture reviews, vulnerability management programs, remediation SLAs, and executive reporting.
  • Must reside in and be authorized to work within the United States.

Nice to have

  • CSSLP, OSCP, GWAPT, CISSP, or a similar relevant certification.
  • Familiarity with OWASP ASVS, OWASP Top 10, and NIST SSDF.
  • Openness to using AI to improve processes and reduce friction.

Culture & Benefits

  • Remote work with business-related onsite travel when required.
  • Healthcare, paid time off, retirement, and well-being benefits.
  • Professional certification opportunities and tuition reimbursement.
  • Quarterly and annual incentive programs.
  • A culture focused on collaboration, growth, innovation, work-life flexibility, and purpose.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →