Application Security Assurance Lead, Vice President

Sumitomo Mitsui Banking Corporation•Charlotte, NC
•Hybrid

About The Position

Join SMBC’s Application Security team and help strengthen the security of applications across the Americas Division. In this role, you will lead application security assurance activities, drive vulnerability remediation efforts, and partner closely with software engineering teams to identify and address security risks throughout the software development lifecycle. You will serve as a trusted advisor on secure coding, code review findings, and application security controls while helping mature the organization’s application security program.

Requirements

  • 7+ years of experience in application security, application penetration testing, or a related cybersecurity discipline.
  • Experience leading vulnerability remediation efforts and working directly with software engineering teams to improve security outcomes.
  • Ability to read, analyze, and explain source code vulnerabilities and secure coding approaches.
  • Experience developing or maintaining secure software delivery processes within CI/CD environments.
  • Strong understanding of the Secure Software Development Lifecycle (SSDLC).
  • Knowledge of common application security threats, attack techniques, and mitigation strategies.
  • Experience creating process documentation, security standards, and operational procedures.
  • Experience using Jira and Confluence.
  • Experience with one or more programming languages such as C#, C++, Java, Python, or .NET technologies.
  • Ability to develop proof-of-concept fixes, remediation guidance, or automation scripts that support cybersecurity operations.
  • 5+ years of experience with application security testing, including Static Application Security Testing (SAST) and/or Dynamic Application Security Testing (DAST).
  • Strong knowledge of OWASP Top 10, Common Weakness Enumeration (CWE), and secure coding practices.
  • 2+ years of experience securing containerized applications and working with container technologies.

Nice To Haves

  • Experience managing Security Champion programs or developer security outreach initiatives.
  • Experience conducting application penetration testing.
  • Participation in bug bounty programs.
  • Familiarity with application security metrics and executive-level reporting.
  • Experience building automation to improve security testing, reporting, or remediation workflows.

Responsibilities

  • Partner with software engineering teams to identify, prioritize, and remediate application security vulnerabilities before production release.
  • Review and explain security findings from code scans, helping development teams understand root causes and remediation options.
  • Ensure applications are consistently assessed through security testing activities, including SAST, SCA, DAST, IAST, and container security scanning.
  • Collaborate with security architecture teams on secure design reviews, threat modeling activities, and application security improvements.
  • Work with vulnerability management teams to validate findings and ensure remediation activities meet established service level agreements.
  • Develop and maintain reporting that measures application security risk, remediation progress, and program effectiveness for leadership.
  • Perform targeted manual validation of security findings and support application security testing efforts when needed.
  • Contribute to the continuous improvement of secure development processes, security champion programs, and developer education initiatives.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service