Jobs and Careers
ST

Application Security Lead, Cyber Security

Stanley Black & Decker
New Britain, United StatesRemotefull_timeVerifiedPosted 14 Nov 2025

About the role

Application Security Lead, Cyber Security–United States – Remote

 

Come build something that matters.

It takes great people to achieve greatness. People with a sense of purpose and integrity. People with a relentless pursuit of excellence. People who care about making things better For Those Who Make The World™. Sound like you? Join our top-notch team of more than 50,000 diverse and high-performing professionals globally who are making their mark on some of the world’s most beloved brands, including DEWALT®, BLACK+DECKER®, CRAFTSMAN®, STANLEY®, CUB CADET®, and HUSTLER®.

The Job:  

As Application Security Lead, Cyber Security, you’ll be part of our Tools & Outdoor team and will be working as a remote employee.  As a highly skilled and experienced Application Security lead, you will play a critical role in ensuring the security of a variety of SBD applications. You will be responsible for in-depth penetration testing of SBD assets, identifying and mitigating security vulnerabilities, implementing security best practices and working closely with development teams to integrate security into the Software Development Lifecycle. Your expertise in Application Security Testing (AST) tools, penetration testing, and vulnerability management will be essential in safeguarding our applications.. You’ll get to:  

  • Conduct security assessments and penetration testing of web and mobile applications using tools such as Burp Suite.
  • Identify, analyze, and prioritize security vulnerabilities in applications and provide actionable recommendations for remediation.
  • Collaborate with development teams to integrate security best practices into the Software Development Lifecycle.
  • Utilize Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and secret scanning tools to automate security testing and improve the efficiency of vulnerability detection.
  • Manage the vulnerability lifecycle, including identification, assessment/verification, mitigation assistance and remediation status tracking.
  • Work with cross-functional teams to ensure timely and effective remediation of identified vulnerabilities.
  • Stay up-to-date with the latest security threats, trends, and technologies, and proactively apply this knowledge to enhance our security measures.
  • Develop and maintain security documentation, including security policies, standards, procedures, best practices/recommendations and guidelines.
  • Educate and train development teams on secure coding practices and securing against the OWASP Top 10 vulnerabilities.
  • Participate in incident response activities and exercises which would include: assisting in the initial investigation, pre and post mortem reporting, resolution of security incidents as well as assisting in documenting lessons learned to enhance security procedures for the future.

The Person:  

You love to learn and grow and be acknowledged for your valuable contributions. You’re not intimidated by innovation. Wouldn’t it be great if you could do your job and do a world of good? In fact, you embrace it. You also have: 

  • Bachelor’s degree in Computer Science, Information Technology, or a related field
  • Hands-on experience with penetration testing tools and creating meaningful reports to present to internal stakeholders of varying technical backgrounds.
  • Proven experience in application security, with a strong understanding of the NIST Cybersecurity Framework, OWASP SAMM, OWASP ASVS security requirements and the OWASP Top 10 vulnerabilities and their remediation.
  • Proficiency in using Application Security Testing tools: SAST, DAST, SCA, secret scanning.
  • Strong knowledge of vulnerability management processes, the stages of the secure development lifecycle process, common attack types and remediation techniques.
  • Excellent problem-solving skills and attention to detail.
  • Strong communication skills, with the ability to convey complex security concepts to technical and non-technical stakeholders through both executive-level summary reports and detailed technical reports
  • Relevant certifications such as CSSLP, CISSP, CISM, CEH, or OSCP are a plus.

The Details:  

You’ll receive a competitive salary and a great benefits plan including:

  • Medical, dental, life, vision, wellness program, disability, 401(k), Employee Stock Purchase Plan, paid time off, and tuition reimbursement.
  • Discounts on Stanley Black & Decker tools and other partner programs.

And More:  

We want our company to be a place you’ll want to be – and stay. Being part of our team means you’ll get to:

  • Grow: Be part of our global company wi

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Stanley Black & Decker

View company profile →