ApplySarthi Match jobs to your CV

Director, Application Security

Jobgether

Make my CV for this job, freeView job and applyYour CV, rewritten for this role using only your real experience. Sign in with Google and upload your CV. Nothing to install.

Skills named in this job

Read from the description itself, not inferred.

This role on the market

1,270 open application roles across 221 companies are on ApplySarthi right now, most of them in Bengaluru (104), Hyderabad (74), Delhi NCR (62).

What application roles keep asking for: Python (13%) — counted across their open postings here.

AWS jobs · CI/CD jobs · Go jobs · Kubernetes jobs

Jobgether has 3,942 open roles listed here.

Counted across 14 company job boards, updated as roles open and close.

Preparing for this interview

Interviews for application roles keep coming back to Python. Practise those questions before you sit with Jobgether.

Questions you are likely to be asked

  1. Why do you want to join Jobgether?
  2. What is your experience with CI/CD? Tell me one thing you learned the hard way.
  3. How do you keep secrets and access safe in your infrastructure?
  4. Walk me through how code gets from a commit to production where you work.
  5. Tell me about an outage you handled. What did you learn from it?

Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.

Practise the Director, Application Security at Jobgether interview free →

Accountabilities:: Lead and develop a multi-manager security organization spanning Application Security and Security Architecture, establishing clear priorities, strong team culture, and high-performance expectations. Define and execute a 2–3-year strategic roadmap aligned with product and platform engineering priorities and the organization’s evolving security needs. Own workforce planning, organizational design, talent acquisition, succession planning, and development of future security leaders. Build and retain highly technical security teams, with an emphasis on engineers who can develop, automate, and integrate security capabilities into engineering environments. Manage operational budgets, security tooling portfolios, and vendor relationships, prioritizing automation, measurable return on investment, consolidation, and reduction of unnecessary tool complexity. Represent application security and architecture at executive and leadership levels, translating technical security risks into clear business and financial implications. Lead an Application Security program that partners with engineering teams and embeds security capabilities into CI/CD pipelines, development frameworks, and developer tooling. Develop security enablement programs, secure coding training, and internal tools that make secure development practices easier for engineers to adopt. Ensure broad application security coverage across secure design reviews, SAST/DAST, dependency management, API security, and related application protection capabilities. Establish product security practices that incorporate security considerations during product and feature design rather than relying primarily on end-of-development audits. Build and maintain a risk-based vulnerability management program with defined service-level agreements, prioritization processes, and executive reporting. Partner with Security Architecture and Platform Engineering to establish enterprise security patterns, reference architectures, and practical guardrails for cloud-native infrastructure. Advance Zero Trust and identity-driven access principles across the environment, integrating security into infrastructure-as-code and platform capabilities. Provide proactive, practical security guidance during product and platform design reviews to help engineering teams move quickly while managing risk. Monitor emerging threats and technology developments, including AI/ML-related attack surfaces and cloud configuration risks, and evolve security architecture accordingly. Requirements: 12+ years of progressive experience in information security, including at least 5 years leading managers and multi-functional security teams. Previous experience in a high-growth consumer technology, fintech, or similarly engineering-driven environment is strongly preferred. Professional foundation in security engineering, software development, platform engineering, or a closely related technical discipline. Demonstrated ability to lead multiple security domains simultaneously while maintaining strong organizational execution and technical standards. Proven experience building and scaling Application Security programs that integrate into software development lifecycles, CI/CD environments, and developer workflows. Deep knowledge of multi-cloud security, with strong experience in AWS preferred. Hands-on understanding of infrastructure-as-code security, including technologies such as Terraform or CloudFormation, as well as Kubernetes and container security. Strong understanding of Zero Trust architecture and identity-focused security patterns. Experience with modern detection engineering, including custom detection pipelines, SOAR automation, and threat-model-driven security coverage. Ability to quantify security risk and communicate its business and financial implications to executive stakeholders and, ideally, board-level audiences. Demonstrated ability to recruit, develop, and retain highly experienced security engineers and senior individual contributors. Familiarity with modern security technologies and tooling, including SIEM, SOAR, DLP, EDR, EPM, CSPM/CWPP, SAST/DAST, infrastructure-as-code security, and container security. Strong judgment when evaluating security tooling, with an ability to rationalize and consolidate technologies rather than unnecessarily expanding the tool portfolio. Proficiency in at least one scripting or programming language, such as Python or Go, with sufficient technical depth to review automation, detection logic, and security tooling developed by the team. Strong communication, leadership, organizational design, strategic planning, and stakeholder-management skills. Ability to operate effectively in a distributed, remote environment while maintaining close collaboration with engineering and business leadership. Benefits: Base salary of $220,200–$351,800 annually in California, Connecticut, Maryland, Massachusetts, New Jersey, New York, Washington State, and Washington, D.C. Base salary of $209,200–$334,200 annually in Colorado, Hawaii, Illinois, Maine, Minnesota, Nevada, Ohio, Rhode Island, Vermont, and Virginia. Compensation varies based on factors including location, experience, and performance, with applicable state salary requirements observed. Eligibility for equity awards, with actual awards determined based on factors such as experience, performance, and location. Fully remote work within the United States, with employees able to work from a physical location of their choice, subject to limited location exceptions. A distributed-work environment built around flexibility, trust, collaboration, and productivity. Opportunity to lead high-impact security initiatives across application security, cloud security, and security architecture. Significant ownership of organizational strategy, technical roadmaps, budgets, tooling, and talent development. Opportunity to work closely with senior engineering, product, legal, privacy, compliance, and executive stakeholders. An inclusive and collaborative environment focused on innovation, professional growth, and meaningful technical impact. Equal employment opportunity and reasonable accommodation support for qualified candidates.

Match this job to your CV

ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.

Check my match →

Similar open roles

Need answers during your interview? Try Live Sarthi.

Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.

Try Live Sarthi free →

A Windows app, from the same team as ApplySarthi.

Listed on lever · posted 2026-09-23. ApplySarthi collects openings and links to application pages; the role is advertised by Jobgether, not by us.