Application security program (cybersecurity)
Title: Engagement Lead ( Application security programs)Location: Dallas, Texas, USADuration: Longterm
Key Responsibilities:
· Lead end-to-end engagement for the AppSOC program, ensuring alignment with customer’s cybersecurity and business objectives
· Act as the primary point of contact for senior client stakeholders, building strong executive relationships
· Oversee program governance, including planning, execution, risk management, and reporting
· Drive delivery excellence across application security services such as SAST, DAST, SCA, and vulnerability management
· Provide hands-on technical direction and escalation support to AppSOC platform engineers - tool configuration, integration design reviews, and remediation prioritization
· Own the application log on boarding and detection engineering work streams -guiding normalization and standardization of application-layer logs into OCSF format for downstream consumption, and reviewing custom detection use cases with the client
· Collaborate with cross-functional teams (security, engineering) to ensure seamless integration of AppSec practices
· Monitor KPIs, SLAs, and overall program health, ensuring timely and high-quality deliverables
· Identify opportunities for expansion, optimization, and continuous improvement within the engagement
· Manage financials including budgeting, forecasting, and revenue assurance
Required Qualifications:
· 8+ years of experience in IT services, cybersecurity, or application security programs
· Proven experience managing large-scale client engagements, preferably in North America
· Hands-on experience with application security tooling across SAST, DAST, SCA, and API security (e.g., Checkmarx, Veracode, Snyk, Burp Suite)
· Hands-on experience building or operating an AppSOC, including integration of AppSec tools with SIEM/SOAR platforms overall (e.g., Microsoft Sentinel, Splunk, Google SecOps/Chronicle, Elastic)
· Working knowledge of application-layer log sources able to distinguish different app-layer log types including parsing logs in BigQuery and AWS S3 and normalization/standardization to OCSF, with solid grounding in detection engineering able to shape and validate custom detection use cases and the logic behind them
· Proven ability to define and drive vulnerability management workflows, remediation SLAs, and AppSec metrics (MTTR, coverage, risk reduction)
· Excellent stakeholder management and communication skills, including C-level interaction
· Experience in program management methodologies (Agile, Waterfall, Hybrid)
· Strong commercial acumen and experience managing P&L or large program budgets
Preferred Qualifications:
· Prior experience in Automotive or Manufacturing sector engagements
· Certifications such as CISSP, CISM, PMP, or equivalent
· Scripting/automation familiarity (Python, PowerShell) and exposure to cloud security across Azure/AWS/Google Cloud Platform, containers, and Kubernetes