Empresa Confidencial
1 month ago
Application Security Lead
Sign up to save this job, get alerts, and apply with an optimized CV.
Company information
- Company
- Empresa Confidencial
- Location
- México Mexico
- Posted
- 1 month ago
Job description
We are a leading company in B2B electronic payment platforms with operations in Latin America and the United States. Originally founded in Monterrey, Mexico, the company has experienced significant growth and is currently headquartered in Houston, Texas.
We connect banks, fintechs, and merchants through a financial infrastructure that facilitates international remittances, payment processing, and embedded financial services.
Our organizational culture is entrepreneurial, dynamic, and execution-oriented. We seek leaders capable of combining strategic thinking with a practical approach to problem-solving, driving results, and generating a tangible impact on the business.
Application Security Lead (AppSec Lead)
We are looking for an Application Security Lead to define and lead the organization's AppSec strategy, integrating security from design throughout the software development lifecycle (SDLC/SSDLC).
This person will be responsible for building and maturing the AppSec program, leading a team of security engineers, and acting as a technical and strategic point of reference for development, architecture, product, and executive leadership.
Responsibilities
- Define the strategy, roadmap, and KPIs for the AppSec program, aligned with business objectives and risk appetite.
- Lead, mentor, and develop the team of application security engineers (junior/mid-level).
- Establish and evolve the architecture review model as part of the SDLC.
- Define secure coding standards and policies, and ensure their adoption across development teams.
- Select, implement, and optimize the tool stack (SAST, DAST, SCA, IAST, secrets scanning) and their integration into CI/CD pipelines.
- Design and oversee the vulnerability lifecycle management process: identification, prioritization, remediation SLAs, and stakeholder reporting.
- Lead or coordinate penetration tests (internal or with third parties) and red teaming exercises focused on applications.
- Drive a security culture through training, security champions, and close collaboration with development and product teams.
- Ensure compliance with relevant regulatory frameworks and standards (OWASP SAMM/ASVS, ISO 27001, PCI-DSS, SOC 2, as applicable).
- Report metrics, risks, and program progress to leadership (CISO, VP Engineering, etc.).
- Assess third-party/vendor risks related to applications and APIs.
Requirements
- 6-8+ years of experience in application security, with at least 2-3 years leading teams or programs.
- Solid experience in software development and modern architectures (cloud, microservices, APIs, containers).
- Deep understanding of offensive and defensive security: threat modeling, pentesting, secure code review.
- Experience leading the selection and integration of SAST/DAST/SCA tools (e.g., SonarQube, Checkmarx, Fortify, Burp Suite, Snyk, Veracode) into DevSecOps pipelines.
- Profound knowledge of OWASP Top 10, OWASP ASVS/SAMM, CWE, MITRE ATT&CK.
- Experience managing vulnerability programs at scale and defining remediation SLAs with development teams.
- Leadership, stakeholder management, and effective communication skills with technical and executive audiences.
- Desirable: certifications such as OSCP, CISSP, GWAPT, CSSLP, or similar.
- Desirable: experience with cloud security (AWS/Azure/GCP) and container security/Kubernetes.
- Advanced English proficiency
Required skills
- english
- training
- mentoring
- ci/cd
- software development
- team leadership
- sdlc
- strategy
- aws
- kubernetes
- kpis
- risk management
- gcp
- azure
- containers
- microservices
- threat modeling
- cloud security
- penetration testing
- application security
- ssdlc
- cissp
- oscp
- devsecops
- owasp
- pci-dss
- vulnerability management
- roadmap
- iso 27001
- slas
- mitre att&ck
- secure coding
- policies
- ciso
- cloud architecture
- soc 2
- sast
- dast
- third-party risk
- red teaming
- api security
- owasp top 10
- sca
- pentesting
- cwe
- architecture review
- iast
- appsec
- owasp asvs
- vp engineering
- gwapt
- csslp
- security culture
- secrets scanning
- owasp samm
- security champions
- secure code review
Interested in this position?
Create your free account and tailor your CV to match this job.