Senior Manager of Application Security
Cox EnterprisesAbout the role
Company
Cox Automotive - USAJob Family Group
Information TechnologyJob Profile
Sr Manager, CybersecurityManagement Level
Sr Manager - People LeaderFlexible Work Option
Hybrid - Ability to work remotely part of the weekTravel %
Yes, 25% of the timeWork Shift
DayCompensation
Compensation includes a base salary of $144,900.00 - $241,500.00. The base salary may vary within the anticipated base pay range based on factors such as the ultimate location of the position and the selected candidate’s knowledge, skills, and abilities. Position may be eligible for additional compensation that may include an incentive program.Job Description
The Senior Manager of Application Security is responsible for leading a team of application security engineers in evaluating the secure coding of all of Cox Automotive’s custom and third-party software, executing manual and automated dynamic application security testing, managing web application firewalls, and developing standards related to software and application programming interfaces (API). The scope includes global development of all products and enterprise tools.
This leader’s organization will use their deep knowledge of secure coding to implement methods to ensure security controls are applied throughout the software development lifecycle. Operational activities will involve designing and maintaining the web application firewalls that protect the hundreds of Cox Automotive public-facing websites, securing SaaS through configuration management, and managing the dynamic testing by third-party providers of all websites and mobile applications. The leader will be in constant contact with engineering teams to implement the cybersecurity architecture guidelines for routing website traffic through protective cybersecurity tools.
This role will report directly to the Director of Cybersecurity Software Engineering at Cox Automotive.
Primary Responsibilities
- Lead an application security team that implements and enforces secure coding guidelines, application vulnerability identification, and risk mitigation throughout the software development lifecycle.
- Oversee the operations of web application firewalls that protect public-facing product and enterprise websites.
- Oversee the execution of manual and dynamic assessments by third-party providers to identify application vulnerabilities.
- Manage the security researcher responsible disclosure process for reporting vulnerabilities in our public-facing websites.
- Ensure all aspects of Cybersecurity application security support are provided in an effective, integrated and business-focused manner.
- Manage and coordinate Cybersecurity engagement, processes and policy implementation across the organization.
- Participate in security events and incident response to identify gaps in current design and propose solutions to prevent threats from reoccurring.
- Research and evaluate emerging security trends, threats, and technologies, and recommend appropriate solutions and enhancements.
- Collaborate with cybersecurity peers to incorporate vulnerability management, governance, risk and compliance, cyber defense, continuous controls monitoring, and identity governance into cybersecurity standards as a cohesive cybersecurity organization.
Minimum Qualifications
- Bachelor’s degree in a related discipline and 8 years of experience in a related field. The right candidate could also have a different combination, such as a master's degree and 6 years of experience; a Ph.D. and 3 years of experience in a related field; or 12 years’ experience in a related field.
- At least 6 years focused on cybersecurity.
- At least 3 years in a people leader role directing and reviewing people’s performance.
- Must have practical expertise in static source code analysis, manual and automated dynamic analysis, secrets management, web application firewall, and API security. Must be able to create design patterns and explain anti-patterns to engineering peers.
- Proficient in Python and expertise in at least one additional language of C#, Go, PHP, Java, or JavaScript (Node, Vanilla JS, or React).
- Clearly articulate the objective of specific cybersecurity policies and procedures to technical and non-technical stakeholders.
- Able to make decisions, supervise complex programs, and set priorities for highly skilled individual contributors.
- Excellent customer service skills, writing, and executive presentation skills.
- Develop a strong and productive working environment with key stakeholders and collaborate closely with other Cox entities’ cybersecurity teams to implement cybersecurity best practices.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s