Application Security, Lead
Toyota North AmericaAbout the role
Overview
Who we are
Collaborative. Respectful. A place to dream and do. These are just a few words that describe what life is like at Toyota. As one of the world’s most admired brands, Toyota is growing and leading the future of mobility through innovative, high-quality solutions designed to enhance lives and delight those we serve. We’re looking for talented team members who want to Dream. Do. Grow. with us.
An important part of the Toyota family is Toyota Financial Services (TFS), the finance and insurance brand for Toyota and Lexus in North America. While TFS is a separate business entity, it is an essential part of this world-changing company- delivering on Toyota's vision to move people beyond what's possible. At TFS, you will help create best-in-class customer experience in an innovative, collaborative environment.
Application Security, Lead
Plano, TX
To save time applying, Toyota does not offer sponsorship of job applicants for employment-based visas or any other work authorization for this position at this time.
Who We’re Looking For
Toyota Financial Services (TFS) Technology team is looking for a highly motivated person to fill a role as an Application Security, Lead.
The primary responsibility of this role is lead implementation of robust application security measures to safeguard our organization's software assets against cyber threats. This role requires technical expertise in application security and guidance to both security and development teams.
What you’ll be doing
Lead the design and implementation of application security policies, standards, and best practices in alignment with industry standards and regulatory requirements.
Lead a team of application security engineers to develop and drive initiatives to secure products.
Foster a culture of security awareness within the team and across the organization.
Conduct comprehensive security assessments of applications throughout the software development lifecycle (SDLC) to identify and mitigate security vulnerabilities and weaknesses.
Collaborate with software development teams to integrate security controls and best practices into the SDLC, including secure coding standards, static and dynamic code analysis, and security testing.
Provide guidance and support to developers on secure coding techniques, security architecture, and threat modeling.
Manage and oversee application security testing activities, including vulnerability scanning, penetration testing, and code reviews.
Monitor and analyze security incidents related to applications, and coordinate incident response and remediation efforts as needed.
Stay current with emerging threats, vulnerabilities, and industry trends in application security.
Develop and deliver application security training and awareness programs for development teams and other stakeholders.
Collaborate with cross-functional teams to ensure the security of third-party and open-source software components used in our applications.
Develop and maintain documentation related to application security architecture, processes, and procedures.
What You Bring
Extensive experience in application security, with a focus on secure software development practices and techniques.
Strong understanding of web application security vulnerabilities and mitigation strategies, such as OWASP Top 10.
Experience with security testing tools and technologies, such as SAST, DAST, and IAST solutions.
Experience with Penetration testing tools such as: (web/mobile: Qualys, Burp Suite)
Experience with cloud security, containerization, and DevSecOps practices is a plus
Proficiency in programming languages commonly used in web application development, such as Java, Python, or JavaScript.
Excellent analytical and problem-solving skills, with the ability to analyze complex application security issues and recommend effective solutions.
Added Bonus if you have
Bachelor’s degree or equivalent work experience
Experience with developing and Implementing Cyber Security Policies.
Risk Management Experience in a regulated environment.
Knowledge of Cyber Security Regulations and Laws.
Cyber Incident Response experience.
What we’ll bring
During your interview process, our team will provide detailed information about our industry-leading benefits and career development opportunities. Here are a few highlights:
A work environment built
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s