AVP, Security Architecture and Engineering
Cox EnterprisesAbout the role
Company
Cox Automotive - USAJob Family Group
Information TechnologyJob Profile
AVP, CybersecurityManagement Level
Assistant Vice Presidents (AVP)Flexible Work Option
Hybrid - Ability to work remotely part of the weekTravel %
Yes, 5% of the timeWork Shift
DayCompensation
Compensation includes a base salary of $207,900.00 - $346,500.00. The base salary may vary within the anticipated base pay range based on factors such as the ultimate location of the position and the selected candidate’s knowledge, skills, and abilities. Position may be eligible for additional compensation that may include an incentive program.Job Description
The Associate Vice President of Security Architecture and Engineering strategically sets the direction of Cox Automotive’s security architecture and secure development processes globally for both enterprise and product technology spanning both on-premise and multi-cloud environments. This leader defines security architecture and development guardrails, policies, and standards that foster an environment of secure development and operation, data protection, and adherence to relevant industry regulatory and client compliance obligations. This role builds strong partnerships with multiple stakeholder groups including Product and Enterprise Architecture, Site Reliability Engineering, Product and Technology Governance, Technology Vendor Management, as well as Product and Enterprise technology portfolio and delivery stream leaders. Key success factors include strong security knowledge in the design and build of secure software products in both on-premise and multi-cloud environments and the ability to partner, influence and lead both direct and cross-functional teams throughout the organization. This role will directly report to the Chief Information Security Officer of Cox Automotive.
Primary Responsibilities:
Embedded Security Champions:
- Lead of team of cybersecurity professionals that embed in delivery streams of a scaled agile (SAFe) product and technology organization.
- Serve as the primary security advocate for security principles, secure development controls, and standards driven security architecture guardrails.
- Review engineering team designs of epics, stories, and features for compliance with security architecture guardrails and controls and consider attacker threats, tactics and procedures when reviewing new functionality.
- Encourage self-sustaining security practices and behaviors within delivery teams.
- Reduce friction with delivery teams by enabling ready access to technical security decisioning that favor solutions that improve security posture while enabling the business to move faster.
Security Architecture:
- Lead a team of cybersecurity professionals that identify, develop, document, and socialize cybersecurity standards and guardrails for both product and enterprise technologies both in on-premise and multi-cloud environments that align with the overall cybersecurity strategy.
- Partner with the Legal and Security Governance, Risk and Compliance teams to ensure that security policies, standards, procedures, and guardrails enable compliance with relevant regulatory and contractual requirements.
- Drive consensus and gain alignment with product and technology architecture, site reliability, technology governance, and technology vendor management teams on cybersecurity guardrails, principles, and technologies.
Application Security COE:
- Lead a team of subject matter experts in secure application development, providing guidance and recommendations for secure coding practices, tools, and techniques.
- Provide technical guidance to development teams on secure coding issues identified by SAST, DAST, SCA, and manual penetration tests.
- Coordinate application penetration testing and ongoing threat modeling with embedded security practitioners and relevant members of the broader cybersecurity team.
Secure Development Tooling and Enablement
- Lead a team of cybersecurity and engineering professionals that build, operate, and integrate tools to enable software engineers to more easily develop software securely.
- Collaborate with cross-functional teams to ensure that application security is seamlessly integrated into the software development process and CI/CD pipelines.
- Manage the operations and effectiveness of the product security pipeline tools (SAST, DAST, SCA, Secrets, etc.).
- Update product security toolin
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s