Jobs and Careers
TH

Director, Application Security

Therapy Brands
United StatesRemotefull_timeVerifiedPosted 22 Jan 2024

About the role

Company Description

Therapy Brands is the leading healthcare technology partner for mental, behavioral, and rehabilitative therapy. Our purpose-built and all-in-one practice management, data, and billing solutions drive exceptional clinical and financial outcomes. 

Thousands of therapy practices rely on us as a trusted partner, to make their lives simpler and more efficient, improve revenue, and enable them to focus on patient care.

For more information, explore our solutions at therapybrands.com

Job Description

We're seeking a Director of Application Security to lead our application security initiatives, interacting closely with software development and product teams to integrate secure practices within the SDLC. Key responsibilities include managing the application security program, collaborating with engineers and leadership to mitigate risks, and setting strategies for security testing operations. You will guide teams on security best practices, oversee vulnerability management, and provide strategic insights on security risks to senior management. The role also entails collaboration on compliance audits, leading security technology projects across the enterprise, and developing educational programs for the development community. This position requires a blend of expertise in application, network, and cloud security, along with a strong ability to integrate security measures into our CI/CD pipelines and development processes.

Responsibilities: 

  • Interact with Company's software development and product teams to advocate secure SDLC activities. Operate as an advocate for Security in interactions with internal and external teams.  
  • Collaborate with software engineers and leadership to address security risks and provide mitigation recommendations within the Secure Development Lifecycle (SDLC).  
  • Work with security champions to build relationships and ensure key activities are supported and deliverables are achieved in a timely manner.  
  • Manage and mature the application security program through direct interactions.  
  • Identify improvement opportunities in all processes and activities involved.  
  • Work with architects and engineers to review and design security requirements.  
  • Participate in security and technology strategic planning to ensure identified risk governance is incorporated into the enterprise strategy.  
  • Appropriately assess risk and provide software security advice when business decisions are made.  
  • Set strategies, processes and oversee the management and operations of SAST, SCA, DAST, and penetration testing operations to provide coverage for the application portfolio.  
  • Function as a subject matter expert in application, network and cloud penetration testing, scanning platforms, exploits, tools, and techniques.  
  • Building and executing a security testing strategy.  
  • Oversee vulnerability identification and measurement. Help the enterprise manage vulnerabilities across automated tooling and manual security assessments.  
  • Guide development teams through a review of their applications and risks against common application flaws like OWASP Top 10 and others  
  • Provide visibility to senior management along with context and prioritization of the issues.  
  • Work with Risk & Compliance teams on PCI-DSS, HIPAA, and other audits as needed  
  • Research and recommend policy and procedures as they relate to Application Security  
  • Lead projects to implement security technologies for the entire enterprise.  
  • Integrates 3rd party and builds custom solutions into our CI/CD pipelines and development cycles.  
  • Define security guardrails through automated tool policies, SLAs, custom rules, and support the developer community.  
  • Support education and awareness strategy, rollout for software development community.  

Qualifications

  • Proven experience in leading application security programs and initiatives in a large-scale environment.
  • Deep understanding and practical experience with Secure Software Development Life Cycle (SDLC) practices.
  • Strong technical expertise in SAST, SCA, DAST, and penetration testing methodologies.
  • Familiarity with common application security risks, such as the OWASP Top 10, and experience in guiding teams to mitigate these risks.
  • Knowledge of compliance and regulatory frameworks, such as PCI-DSS and HIPAA, and experience in managing related audits.
  • Proficiency in integrating security tools and practices into CI/CD pipelines and development processes.
  • Excellent leadership, communication, and project management skills, with a track record of driving security awareness and education initiatives within software development teams.

Ad

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Therapy Brands

View company profile →