Senior Manager, Application Security
ZillowAbout the role
About the team
Our team is dedicated to leading the configuration of critical perimeter defense systems, including anti-bot technologies, web application firewalls (WAF), and AWS Shield! Our responsibility extends to ensuring the security and resilience of the CI/CD pipeline across a diverse and evolving array of technologies.We collaborate closely with customers to implement security standard processes, integrating their insights with our technical expertise. The goal is to provide a robust, secure foundation for continuous development and deployment, ensuring our organization stays protected against emerging threats while maintaining operational efficiency. Our passion for innovation and security drives us to stay ahead in safeguarding all facets of the development lifecycle.
About the role
We are seeking an experienced and dynamic Cloud Security Engineering Manager to lead and own a versatile team of security engineers responsible for safeguarding our cloud infrastructure, web applications, and CI/CD pipelines! As a hands-on leader, you will be responsible for all aspects of cloud security, mentor your team, and collaborate with cross-functional teams to ensure secure development practices, robust perimeter defense, and compliance with industry standards.
As a Senior Manager, Application Security, you will:
Lead, mentor, and manage a team of cloud security engineers responsible for securing our cloud infrastructure, applications, and pipelines.
Provide technical mentorship and expertise to your team in key areas such as AWS architecture, web application security, anti-bot technologies, CI/CD security, and secure coding practices.
Coordinate the design, deployment, and maintenance of security services and infrastructure, ensuring robust perimeter defenses, threat detection, and collaborate on incident response processes.
Manage the configuration and optimization of AWS security services, including WAF, Shield, IAM, GuardDuty, Security Hub, CloudFront, VPC, and KMS, in alignment with standard processes.
Drive the implementation of Infrastructure as Code (IaC) security using tools like Terraform and AWS CloudFormation, ensuring secure and scalable deployments.
Collaborate with development, operations, and product teams to ensure security is integrated into all stages of the software development lifecycle.
Define security metrics, supervise progress, and report on the overall health of the organization’s cloud security posture to executive leadership.
Manage security incidents and escalations, and work with your team to continuously improve incident response processes, using automation wherever possible.
Develop and implement security policies, standards, and best practices that align with industry regulations and internal compliance requirements.
Drive the adoption of secure coding practices and cultivate a culture of security awareness across the organization.
Who you are
Strong understanding of AWS architecture and security services, including WAF, Shield, IAM, CloudFront, VPC, GuardDuty, Security Hub, and KMS.
Validated leadership experience in leading and mentoring a team of cloud or security engineers.
Hands-on experience with Infrastructure as Code (IaC) tools such as Terraform and AWS CloudFormation.
In-depth knowledge of web application security and perimeter defense technologies, including anti-bot solutions, SSL/TLS, HTTP security headers, and DNS security.
Experience in securing CI/CD pipelines, integrating security testing tools, and leading secret management systems like AWS Secrets Manager or HashiCorp Vault.
Solid understanding of secure coding practice
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s