Login Enter

Empresa Confidencial

1 month ago

Application Security Lead

Sign up free Log in

Sign up to save this job, get alerts, and apply with an optimized CV.

Company information

Company
Empresa Confidencial
Location
México Mexico
Posted
1 month ago
View all jobs at Empresa Confidencial

Job description

We are a leading company in B2B electronic payment platforms with operations in Latin America and the United States. Originally founded in Monterrey, Mexico, the company has experienced significant growth and is currently headquartered in Houston, Texas.

We connect banks, fintechs, and merchants through a financial infrastructure that facilitates international remittances, payment processing, and embedded financial services.

Our organizational culture is entrepreneurial, dynamic, and execution-oriented. We seek leaders capable of combining strategic thinking with a practical approach to problem-solving, driving results, and generating a tangible impact on the business.


Application Security Lead (AppSec Lead)

We are looking for an Application Security Lead to define and lead the organization's AppSec strategy, integrating security from design throughout the software development lifecycle (SDLC/SSDLC).

This person will be responsible for building and maturing the AppSec program, leading a team of security engineers, and acting as a technical and strategic point of reference for development, architecture, product, and executive leadership.


Responsibilities

  1. Define the strategy, roadmap, and KPIs for the AppSec program, aligned with business objectives and risk appetite.
  2. Lead, mentor, and develop the team of application security engineers (junior/mid-level).
  3. Establish and evolve the architecture review model as part of the SDLC.
  4. Define secure coding standards and policies, and ensure their adoption across development teams.
  5. Select, implement, and optimize the tool stack (SAST, DAST, SCA, IAST, secrets scanning) and their integration into CI/CD pipelines.
  6. Design and oversee the vulnerability lifecycle management process: identification, prioritization, remediation SLAs, and stakeholder reporting.
  7. Lead or coordinate penetration tests (internal or with third parties) and red teaming exercises focused on applications.
  8. Drive a security culture through training, security champions, and close collaboration with development and product teams.
  9. Ensure compliance with relevant regulatory frameworks and standards (OWASP SAMM/ASVS, ISO 27001, PCI-DSS, SOC 2, as applicable).
  10. Report metrics, risks, and program progress to leadership (CISO, VP Engineering, etc.).
  11. Assess third-party/vendor risks related to applications and APIs.


Requirements

  1. 6-8+ years of experience in application security, with at least 2-3 years leading teams or programs.
  2. Solid experience in software development and modern architectures (cloud, microservices, APIs, containers).
  3. Deep understanding of offensive and defensive security: threat modeling, pentesting, secure code review.
  4. Experience leading the selection and integration of SAST/DAST/SCA tools (e.g., SonarQube, Checkmarx, Fortify, Burp Suite, Snyk, Veracode) into DevSecOps pipelines.
  5. Profound knowledge of OWASP Top 10, OWASP ASVS/SAMM, CWE, MITRE ATT&CK.
  6. Experience managing vulnerability programs at scale and defining remediation SLAs with development teams.
  7. Leadership, stakeholder management, and effective communication skills with technical and executive audiences.
  8. Desirable: certifications such as OSCP, CISSP, GWAPT, CSSLP, or similar.
  9. Desirable: experience with cloud security (AWS/Azure/GCP) and container security/Kubernetes.
  10. Advanced English proficiency

Required skills

Interested in this position?

Create your free account and tailor your CV to match this job.