Director, Application Security
Intercontinental Exchange · Atlanta, GA, US
About this role
## Director, Application Security ### Overview Lead two teams responsible for assuring **secure software development** and **cloud security** through education, continuous testing, and consultation. ### Responsibilities - Differentiate **FUD vs. hype** from legitimate business risk and assign **practical severity ratings** to detected weaknesses - Demonstrate compromise of vulnerabilities to educate and motivate development teams - Adopt and improve an established **education, testing, and remediation** methodology - Innovate to ensure the program operates effectively and distill results into meaningful **metrics** - Codify and communicate the **Application and Cloud Security** programs through writing and discussion - Recruit, retain, and motivate talented staff; balance efficient task allocation with ongoing engagement and growth - Successfully run an enterprise AppSec program at scale (e.g., **2,000+ applications**) - Coach and develop team leaders, including newer leadership hires - Commit to continuous education and be a recognized industry leader in Application and Cloud Security ### Program Areas - **Application Identification and Review**: Maintain, execute, and report AppSec assurance tasks from **Design Review** through operating a **Bug Bounty** program - **Standards and Policies**: Own the **Application Development Security Policy**; ensure timely, practical updates, communication, and education - **Secure Design**: Establish security requirements early in the SDLC and provide subject matter expertise during new projects and releases - **Tool Management**: Implement and maintain cutting-edge technology to assess and protect applications and cloud environments throughout the SDLC and post-deployment - Evaluate and apply **AI and machine learning** in AppSec (e.g., AI-assisted vulnerability detection, AI-powered code review/testing, and securing AI-integrated development pipelines) - **Developer Education**: Keep engineers current on secure coding practices and build strong rapport with the ICE application development community - **Cloud Practitioner**: Provide security leadership and solutions to business and technical teams building or buying cloud products - **Bug Bounty Program**: Operate a responsible disclosure program that incentivizes and fosters positive relationships with security researchers ### Knowledge & Experience - Bachelor’s degree in Computer Science, Engineering, MIS, CIS, or related discipline - Hands-on or program-level experience applying **AI in the AppSec** space - Software engineering experience in **Java, C++, Python**, and/or related languages - Hands-on experience with **information security** and related technologies ### Preferred Skills - Background in **financial services** or a comparable regulated enterprise environment - Technical expertise and understanding of **AWS and/or Azure** cloud platforms - Participation and leadership in Application Security consortia such as **OWASP** --- *Intercontinental Exchange, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to legally protected characteristics.*
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.