Source description
About the role
Program Leadership: Define and execute a multi-year Application Security roadmap aligned with business goals and industry best practices
AI Security Leadership: Help define the secure architecture and guardrail framework for AI adoption across the company
Security Engineering & Automation: Integrate threat modeling, security tools & testing (SAST, SCA, DAST, IAST, RASP, etc.), and secure by design processes into the SDLC (CI/CD pipeline)
Architecture Reviews & Technical Execution: Perform security architecture reviews for major product changes; conduct in-house secure code reviews and threat modeling for high-impact features and critical products.
Vulnerability Management: Oversee the end-to-end AppSec vulnerability lifecycle (identification, prioritization, and remediation based on business risk, exploitability, and threat intelligence)
Incident Response: Direct and manage incident response for application security alerts/incidents
Offensive Security & Testing: Lead the strategy for third party penetration tests
Reporting & Metrics: Deliver executive-level dashboards and reports on application security posture and risk trends
Continuous Improvement: Drive continuous improvement activities, and deepen leadership awareness of product and application security risks
Strategic Partnership & Collaboration: Collaborate with Engineering and Product leads to embed security into the SDLC and scale the Security Champions program
Team Leadership: Direct a small team of AppSec engineers while remaining deeply hands-on in technical execution
More at Prosper
Related open roles
Product Manager (Credit Card)
San Francisco Bay Area · Hybrid
Credit Risk Analyst
San Francisco Bay Area · Hybrid
Sr. Credit Risk Analyst
Remote · United States
Sr. Software Engineer, Backend
San Francisco Bay Area · Hybrid
Sr. Product Manager, Core Experience
San Francisco Bay Area · Hybrid
Sr. Infrastructure Security Engineer
Remote · United States
