Jobs and Careers
LU

Manager, Application Security

Lumin Digital
Remote- United States, United StatesRemotefull_timeVerifiedPosted 29 Aug 2025

About the role

Basic FunctionThe Application Security (AppSec) team at Lumin Digital is responsible for guiding and supporting a secure software development lifecycle across all products and internal applications developed within the company.  This team is responsible for helping code authors across the entire organization build security into our technology from early conceptualization and design phases, not bolt it on as an afterthought or check-the-box activity.   This role leads the AppSec function by driving strategic improvements in application security, coordinating with teams across the company, and promoting a shared understanding that code quality includes security. The role requires strong technical leadership and collaboration to ensure our application security posture continuously evolves and strengthens over time.
Essential Functions and Responsibilities:Identify emerging industry threats, observed trends, and industry best practices guidelines to identify gaps and identify, plan, design, and enhance our application security posture in collaboration across Lumin DigitalDevelop, collect, and summarize meaningful measures of application security to evaluate program performanceCollaborate with other leaders to understand vulnerabilities and to develop mitigation strategies that address current findings and reduce the likelihood of future occurrence of the same classes of issuesEnsure integration of security tooling into CI/CD pipelines with minimal developer frictionReview the technical methods and output of the AppSec team to ascertain the quality and fit of activities such as thread modeling, secure design reviews, and architectural risk assessments, and provide constructive and detailed feedback to improve team members’ ability to perform their dutiesLead improvements in secure coding standards, developer training, and evaluation of assessment toolsReview client-sponsored application assessments to qualify and prepare responsesPerform other duties as assigned
Supervisory Responsibility:Set clear expectations, offer direction, and ensure alignment with organizational goals while fostering a supportive environment that encourages collaboration, accountability, and growth.Coach, mentor, and provide training opportunities to build team members’ skills, promote internal growth, and prepare staff for future roles and responsibilities.Manage hiring, onboarding, performance evaluations, promotions, compensation, and terminations, ensuring fair and consistent application of policies and procedures.Assess team performance regularly, address gaps, and ensure duties are completed efficiently and effectively in alignment with department and organizational objectives.
Position Specifications
Education: Bachelor's degree in Computer Science, Information Assurance, Information Security, Cybersecurity, or related field is required; or equivalent combination of education and experience in cybersecurity with demonstrated command of key application security concepts and technologies and proficiencies in threat modeling, detective and preventative controls, application security testing, and other relevant technical security risk management domains.Certifications relevant to application security or management of application security teams, such as the GWEB, GWAPT, CSSLP, or CISM, are preferred.
Experience:5 years of hands-on technical experience directly working with detective security controls, including web application firewalls, TLS introspecting proxies, tools integrated into CI/CD pipelines, including SCA, SAST, DAST, and MAST required.3 years of experience leading complex security initiatives or driving secure application design practices within a team or organization required. This may include project leadership, technical mentorship, or ownership of code security or quality programs, ideally within financial institutions or fintech companies..Experience with large-scale AWS operating environments, Linux, Kubernetes, Git, and scripting languages required.Experience with administering public or private bug bounty programs required.Experience analyzing and summarizing trends in application-layer threats, vulnerabilities, and posture to internal management teams is required.  Applicants are invited to provide an example or excerpt of a report or presentation they solely developed, with any confidential information redacted, in their cover letter that illustrates this experience and skill.
Knowledge, Skills, & Abilities:Excellent teamwork skills, including the ability to develop long-term partnerships for continual improvement in established technology platforms with mature product lifecycle management processesExcellent data analysis skills, including using tools like Excel or Google Sheets, to customize and report on key metrics specifically useful for the company and relevant to the current threat environment and organizational needs o

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Lumin Digital

View company profile →