TG IT Application Security Manager

Terumo BCT, Inc.Lakewood, IL
$121,400 - $151,800Hybrid

About The Position

The Application Security Manager is responsible for leading the organization's Application Security program, ensuring that security is integrated throughout the Application Cycle (SDLC). This role partners closely with the software teams, cloud, architecture, infrastructure, and potentially product teams to identify, assess, and mitigate application security risks while enabling secure software delivery. The successful candidate will lead a team of application security analysts, establish secure development standards, oversee security testing programs, and drive adoption of security best practices aligned with industry standards such as NIST SP 800-218 (Secure Software Development Framework), NIST Cybersecurity Framework (CSF) 2.0, OWASP, and CIS Controls.

Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field.
  • 8–10+ years of cybersecurity experience.
  • 5+ years in Application Security.
  • 3+ years leading security teams.
  • Experience implementing enterprise DevSecOps programs.
  • Experience working with Agile and CI/CD environments.
  • Experience with cloud-native application security.
  • CISSP
  • CSSLP
  • GIAC Web Application Penetration Tester (GWAPT)
  • GIAC Secure Software Programmer (GSSP)
  • Certified Cloud Security Professional (CCSP)
  • Certified Information Security Manager (CISM)
  • Microsoft Certified: Cybersecurity Architect Expert
  • Microsoft Certified: Azure Security Engineer Associate

Nice To Haves

  • Master's degree preferred.

Responsibilities

  • Collaborate with other global and regional leaders within to develop the enterprise Application Security strategy.
  • Lead, mentor, and develop Application Security Analysts.
  • Define AppSec metrics, KPIs, and maturity goals in collaboration with regional and global security leaders.
  • Integrate security into all phases of the enterprise application portfolio.
  • Ensure security requirements are incorporated during design and architecture reviews.
  • Promote security-by-design principles across application teams.
  • Manage and oversee Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Interactive Application Security Testing (IAST), API Security Testing, Container Security, Infrastructure as Code (IaC) Security, Mobile Application Security Testing, and Secrets Detection.
  • Review findings, prioritize remediation, and validate fixes.
  • Assist in Supply Chain Security.
  • Facilitate threat modeling sessions with development teams.
  • Identify abuse cases and attack paths.
  • Recommend architectural improvements.
  • Ensure high-risk applications undergo formal security architecture reviews.
  • Establish application vulnerability management processes.
  • Prioritize remediation using risk-based methodologies.
  • Track remediation SLAs.
  • Report vulnerability metrics to executive leadership.
  • Coordinate penetration testing remediation activities.
  • Support secure development within cloud platforms including AWS, Microsoft Azure, and Google Cloud Platform.
  • Conduct manual secure code reviews.
  • Review high-risk applications.
  • Provide secure coding guidance.
  • Coach development teams on remediation.
  • Establish and set-up safe rules for API security.
  • Find weak spots through testing for API security.
  • Monitor logs to spot shadow APIs and strange traffic patterns.
  • Collaboration on training programs covering OWASP Top 10, Secure Coding, API Security, Cloud Security, Common software vulnerabilities, and Secure design principles.
  • Perform application security risk assessments.
  • Support enterprise application risk management initiatives.
  • Support cyber incident response by investigating application security incidents, supporting forensic analysis, identifying root causes, leading post-incident reviews, and developing preventive controls.
  • Support compliance initiatives including NIST CSF 2.0, NIST SP 800-218 (SSDF), NIST SP 800-53, OWASP ASVS, PCI DSS, HIPAA, SOX, ISO/IEC 27001, and SOC 2.

Benefits

  • multiple group medical, dental and vision plans
  • a robust wellness program
  • life insurance and disability coverages
  • group accident
  • hospital indemnity
  • critical illness
  • pet insurance
  • 401(k) plan with a matching contribution
  • vacation and sick time programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service