Padmi
Carter's logo
Carter's

children's apparel · baby clothing

Lead Application Security Engineer

United StatesPosted 5 days ago
SecurityStaff+Full Time
Apply at Carter's

Opens the source posting on carters.wd1.myworkdayjobs.com

Source description

About the role

View original

Serving the needs of all families with young children, Carter’s Inc. is the largest North American apparel retailer exclusively for babies and young children, encompassing Carter’s, OshKosh B’gosh, Skip*Hop and Little Planet brands. Meaningful work, constant learning, genuine people, and a community guided by core values that promote inclusion and innovation is in everything we do. There are many reasons to build your career at Carter's. How you’ll make an impact: The Lead Security Engineer – Application Security is a senior technical leader within the IT Security team, reporting to the Sr. Director, IT Security. This role serves as the primary architect and subject matter expert for application security across the enterprise, owning the AppSec program strategy, standards, and tooling roadmap. Working autonomously and with broad organizational influence, the Lead exercises expert-level judgment to define how security is built into software from the ground up. A critical distinction of this role is hands-on experience with artificial intelligence: the Lead is expected to build, secure, and govern AI-powered capabilities as they become embedded in Carter’s applications and infrastructure. The Lead acts as a force multiplier – elevating the security posture of every engineering team they engage with and translating complex risk into clear, actionable direction for both technical and business stakeholders. Key Responsibilities Depending on the needs of the department, the duties of this role could include: Application security, architecture & standards (25%) Defining and owning the enterprise application security architecture, standards, and secure-by-default patterns Establishing and maintaining AppSec tooling strategy, evaluating vendors, and driving adoption across engineering teams Leading threat modeling sessions for critical applications and new product features Serving as the final technical authority on AppSec decisions, including security design reviews and architecture signoffs Secure code review, API security & advanced testing (25%) Conducting and directing advanced secure code reviews, SAST/DAST assessments, and manual penetration testing across web, mobile, and API surfaces Owning API security standards including REST and GraphQL, enforcing OWASP API Top 10 controls and authentication/authorization design patterns Driving vulnerability triage, risk prioritization, and remediation accountability across development teams at scale DevSecOps engineering & platform ownership (20%) Owning the DevSecOps toolchain: designing, deploying, and maturing security gates within CI/CD pipelines enterprise-wide Acting as the primary security partner to engineering leadership, embedding security into system design, SDLC processes, and platform decisions Driving continuous improvement of AppSec metrics, dashboards, and KPIs to demonstrate program maturity and risk reduction AI security – build, secure & govern (20%) Hands-on building and deploying AI-powered security tooling and automation (e.g., AI-assisted code review, threat detection, or vulnerability triage) Securing AI/ML integrations and connectors: assessing prompt injection, data leakage, model supply chain, and third-party AI service risks Developing and enforcing AI governance policies: defining acceptable use, security review gates, and risk acceptance criteria for AI adoption Risk governance, compliance & cross-functional leadership (10%) Representing the IT Security team in architecture reviews, cross-functional planning, and executive risk reporting Owning security policy and standards documentation relevant to application security, AI use, and API governance Leading AppSec representation in PCI-DSS, NIST, and OWASP compliance audits and evidence collection Travel Requirements Open-to-travel between various Carter's offices as needed We’d Love to hear from you if: (Requirements section) Must have: 5+ years of application security, software engineering, or secure code review experience Strong proficiency in one or more languages (e.g., Python, Java, JavaScript, Go) with ability to perform in-depth code review and threat modeling. Experience with SAST/DAST tooling (e.g., Snyk, SonarQube, Semgrep, Checkmarx, Burp Suite, OWASP ZAP) and ownership of AppSec program design. Proven communication and presentation skill set abilities with multilevel stakeholders Ability to meet deadlines and work with management across various disciplines Proven collaborative experience with cross functional teams Ability to perform on-call duties during off-hours and holidays An adaptable and flexible attitude towards changing business needs Preferred skills and experience: Bachelor’s degree in computer science or related field Demonstrated experience leading or conducting red team, penetration testing, or adversarial simulation exercises. Experience designing and scaling security observability pipelines, including log analysis and application-layer telemetry. Working knowledge of PCI-DSS, NIST, OWASP, and other regulatory frameworks; experience representing security in audit and compliance reviews. Proven experience securing cloud-native or hybrid-cloud application environments (AWS, Azure, or GCP). Hands-on experience building, deploying, or integrating AI/ML-powered tools, combined with the ability to assess and govern their security posture (prompt injection, data leakage, model supply chain risks). Proven ability to define and enforce security standards across engineering organizations; prior experience owning a security capability or domain. Security+, ISC2 CC, CompTIA A+, CompTIA Network+, SSCP, CCT, GWEB, CSSLP, CEH, or OSCP certifications Carters is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity, sexual orientation, national origin, genetics, disability, age, veteran status, or any other status protected by federal, state, or local law. We’ve become an industry leader by providing quality – from the clothing we sell to the careers we offer our team. Shared values have paved the way to our success. We nurture inclusive work environments for everyone. We invest in our teams with training and development programs to help them build their skills. We succeed together; everyone is welcome to grow in many ways. We’ve kept our close-knit warmth since our founding. You’ll have the opportunity to work with colleagues who often become fast, lifelong friends while making new connections and sharing memorable experiences. Caring, teamwork, flexibility, and growth are what make us different. What’s not to love?

More at Carter's

Related open roles

View all roles