2 дня назад
Senior Manager, Application Vulnerability Validation & Verification - USDS (Cybersecurity)
199 800 - 441 600$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Manager, Application Vulnerability Validation & Verification - USDS (Cybersecurity): Building and leading an application vulnerability validation function that confirms production exploitability across web, mobile, and API surfaces with an accent on AppSec leadership, automated triage, and attack-path analysis. Focus on developing scanner integrations and LLM-assisted tooling, mapping systemic blast radius, and driving secure architectural mitigations across distributed engineering organizations.
Location: San Jose, United States; fully in-person schedule up to 5 days a week
Salary: $199,800–$441,600 annually, with possible discretionary bonuses, incentives, and restricted stock units.
Company
operates a data privacy and cybersecurity program focused on protecting U.S. user data, applications, algorithms, and the U.S. content ecosystem.
What you will do
- Build, lead, hire, mentor, and technically direct an Application Security engineering team.
- Develop the automation strategy for application vulnerability validation, including scanner API integrations, custom tooling, and LLM-assisted triage.
- Oversee deep technical verification across web, iOS, Android, and API endpoints to confirm real production exploitability.
- Analyze attack paths, vulnerability chaining, and blast radius across a large software supply chain.
- Partner with U.S. and global engineering teams to implement systemic security mitigations.
- Provide actionable secure-coding and architectural guidance as a principal internal consultant.
Requirements
- Leadership experience in Application Security, Product Security, or Software Security Engineering, typically including 5 years of domain experience and formal team management.
- Strong software development and scripting skills in Python, Go, Java, or JavaScript.
- Deep experience with enterprise SAST, DAST, and SCA platforms such as Checkmarx, Veracode, Burp Suite Enterprise, Snyk, or GitHub Advanced Security.
- Strong understanding of microservices, service mesh, CI/CD pipelines, Kubernetes, Docker, and API gateways.
- Ability to coordinate remediation across large distributed engineering organizations and communicate objective threat evidence.
Nice to have
- Advanced security certifications such as OSWE, OSWA, GWE, CASE, or CSSLP.
- Experience with formal threat-modeling frameworks for complex features.
Culture & Benefits
- On-site collaboration focused on speed, alignment, real-time decision-making, team development, and integrated execution.
- Medical, dental, and vision insurance from day one.
- 401(k) savings plan with company match, paid parental leave, disability coverage, and life insurance.
- Wellbeing benefits, 10 paid holidays, 10 paid sick days, and 17 days of paid personal time.
- Inclusive workplace with reasonable accommodation support during recruitment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →