Application security program (cybersecurity)

Title: Engagement Lead ( Application security programs)Location: Dallas, Texas, USADuration: Longterm

Key Responsibilities:

· Lead end-to-end engagement for the AppSOC program, ensuring alignment with customer’s cybersecurity and business objectives

· Act as the primary point of contact for senior client stakeholders, building strong executive relationships

· Oversee program governance, including planning, execution, risk management, and reporting

· Drive delivery excellence across application security services such as SAST, DAST, SCA, and vulnerability management

· Provide hands-on technical direction and escalation support to AppSOC platform engineers - tool configuration, integration design reviews, and remediation prioritization

· Own the application log on boarding and detection engineering work streams -guiding normalization and standardization of application-layer logs into OCSF format for downstream consumption, and reviewing custom detection use cases with the client

· Collaborate with cross-functional teams (security, engineering) to ensure seamless integration of AppSec practices

· Monitor KPIs, SLAs, and overall program health, ensuring timely and high-quality deliverables

· Identify opportunities for expansion, optimization, and continuous improvement within the engagement

· Manage financials including budgeting, forecasting, and revenue assurance

Required Qualifications:

· 8+ years of experience in IT services, cybersecurity, or application security programs

· Proven experience managing large-scale client engagements, preferably in North America

· Hands-on experience with application security tooling across SAST, DAST, SCA, and API security (e.g., Checkmarx, Veracode, Snyk, Burp Suite)

· Hands-on experience building or operating an AppSOC, including integration of AppSec tools with SIEM/SOAR platforms overall (e.g., Microsoft Sentinel, Splunk, Google SecOps/Chronicle, Elastic)

· Working knowledge of application-layer log sources able to distinguish different app-layer log types including parsing logs in BigQuery and AWS S3 and normalization/standardization to OCSF, with solid grounding in detection engineering able to shape and validate custom detection use cases and the logic behind them

· Proven ability to define and drive vulnerability management workflows, remediation SLAs, and AppSec metrics (MTTR, coverage, risk reduction)

· Excellent stakeholder management and communication skills, including C-level interaction

· Experience in program management methodologies (Agile, Waterfall, Hybrid)

· Strong commercial acumen and experience managing P&L or large program budgets

Preferred Qualifications:

· Prior experience in Automotive or Manufacturing sector engagements

· Certifications such as CISSP, CISM, PMP, or equivalent

· Scripting/automation familiarity (Python, PowerShell) and exposure to cloud security across Azure/AWS/Google Cloud Platform, containers, and Kubernetes

Back to blog