
AVP Cybersecurity
Ensemble Health Partners7 days ago
Remote, United StatesStaff+
Base Salary
$172k - $258k/yr
Responsibilities
- Build, lead, and mature an application security and DevSecOps program spanning secure SDLC, SAST, DAST, SCA, container and cloud-native security, and API security.
- Perform secure code reviews, threat modeling, security architecture reviews, critical vulnerability triage, and hands-on remediation guidance.
- Mentor and develop application security engineers and embedded security champions.
- Design, implement, tune, and troubleshoot the AppSec toolchain and integrate security gates into CI/CD pipelines.
- Own vulnerability management, including triage, prioritization, remediation SLAs, escalations, and high-severity response.
- Partner with engineering, product, and architecture teams to embed security requirements and threat modeling into product design.
- Develop application security policies, secure coding standards, DevSecOps playbooks, and engineering training.
- Manage third-party and open-source software risk and vulnerable dependency remediation.
- Report application security risk posture, program metrics, and remediation trends to executive leadership.
- Participate in application-level security incident response, root cause analysis, and remediation planning.
Requirements
- 8+ years of experience in application security, secure software development, or DevSecOps, including hands-on engineering or security engineering work.
- 3+ years in a leadership or technical lead capacity with the ability to remain hands-on while managing or mentoring a team.
- Relevant certification preferred, such as CSSLP, OSCP, GWAPT, or CISSP.
- Familiarity with OWASP ASVS, OWASP Top 10, and NIST SSDF.
- Hands-on experience configuring, tuning, and troubleshooting SAST, DAST, and SCA tools such as Checkmarx, Veracode, Snyk, Semgrep, and Fortify.
- Working proficiency in one or more programming languages, including Java, Python, JavaScript/TypeScript, Go, or C#.
- Experience integrating security into CI/CD pipelines and DevOps toolchains such as Jenkins, GitHub Actions, GitLab CI, or Azure DevOps.
- Experience with cloud security and container/orchestration security using platforms and tools such as AWS, Azure, GCP, Docker, or Kubernetes.
- Experience conducting threat modeling, including STRIDE, and security architecture reviews.
- Experience building and scaling vulnerability management programs with remediation SLAs and executive reporting.
- Strong communication, presentation, analytical, and critical-thinking skills, including the ability to translate technical risk for non-technical stakeholders.
- Ability to work independently, lead a highly skilled AppSec team, remain a credible technical practitioner, prioritize under pressure, and meet deadlines.
Benefits
- Remote position limited to candidates residing and authorized to work in the United States, with travel and onsite work at client, temporary, or corporate offices as business needs require.
- Comprehensive benefits supporting physical, emotional, and financial health, including healthcare, time off, retirement, and well-being programs.
- Professional development investment, including a relevant professional certification for each associate and tuition reimbursement.
- Quarterly and annual incentive programs for employees.
- Collaborative culture focused on growth, innovation, flexibility, and work-life balance.
Tech Stack
AWSAzureC#DockerGitHub ActionsGitLab CI/CDGoGoogle Cloud PlatformJavaJavaScriptJenkinsKubernetesPythonTypeScript