Engineering Manager, Application & Product Security
United States,
New York
Permanent
Job ID: 2460
Job Description
[Up to c. $325k Base Salary + Discretionary Bonus | Hybrid Working]
Role Overview
We’re representing an elite global investment and technology firm looking for a hands-on security engineering leader to own application and product security across a high-calibre engineering environment. This role sits at the point where secure design, developer enablement, product-security tooling and AI-assisted security workflows are starting to converge. You’ll lead a distributed team, grow the function, and help reshape how AppSec operates as agentic development and automation become part of day-to-day engineering...
Key Responsibilities
- Lead a global application security team across developer consulting, secure design review, penetration testing, code review and product-security engineering
- Set the direction for how the function evolves as AI-assisted development, agentic tooling and automation change traditional AppSec workflows
- Partner closely with software engineering teams to improve secure design, testing, implementation and developer-facing security practices
- Drive the build-out of internal security products, automation and tooling that help developers move faster without lowering the security bar
- Hire, interview and grow the team, with approved headcount for further expansion
- Stay technically close enough to review architecture, challenge engineering assumptions and contribute to higher-value security decisions
- Balance hands-on technical leadership with people management, prioritisation and long-term team development
What You’ll Bring…
- 8+ years across application security, product security, security engineering or software engineering with strong hands-on technical depth
- 4+ years leading AppSec, product security, secure engineering, developer-security tooling or adjacent technical security teams
- Experience managing security consulting-style work with engineering teams, including design reviews, threat modelling, secure code review and penetration testing
- Strong judgement on where AppSec creates leverage, where automation helps, and where human review still matters
- Experience building, shaping or integrating developer-facing security tooling such as SAST, DAST, SCA, secret scanning, automated testing or secure SDLC controls
- Practical interest in AI-assisted engineering and security automation, with the ability to explain how you use tools such as Claude Code, Cursor or similar
- Credibility with senior engineers, security leaders and cross-functional technical stakeholders
- Strong hiring experience, including interviewing, calibration, bar-setting and decision-making
- Exposure to AI security, agentic application risks, LLM-enabled developer workflows or agentic security tooling
- (Preferred) Prior experience in a high-performance financial services, trading, investment management, fintech or technology-led engineering environment
...
Apply for this role
All fields marked with * are required.