Application Security Manager

Overstock.com
$150,000 - $185,000

About The Position

The Application Security Manager is a key role in reducing application risk across Bed Bath & Beyond’s technology environment. This position drives the execution of secure SDLC practices, improves remediation discipline, matures developer-facing security capabilities, and ensures application security risks are visible, prioritized, and addressed through defensible governance. The manager grows the capability of the Application Security team while serving as a trusted advisor to engineering and product leaders.

Requirements

  • Hands-on experience with application security assessments, secure code reviews, threat modeling, API testing, security design reviews, and risk-based remediation.
  • Experience leading or materially coordinating application security, secure SDLC, vulnerability governance, DevSecOps, vulnerability disclosure, bug bounty, external testing, or coordinated vulnerability intake processes.
  • Experience with SAST, DAST, SCA, secrets detection, container scanning, cloud security posture, WAF or runtime protection, and vulnerability management tooling.
  • Working knowledge of application architectures, APIs, authentication and authorization patterns, CI/CD pipelines, dependency management, Git-based workflows, and cloud-hosted delivery models.
  • Ability to partner with engineers, architects, platform teams, product leaders, and security teams to drive practical remediation, control adoption, and business-appropriate security decisions.
  • Ability to create clear metrics, dashboards, technical documentation, remediation guidance, project plans, executive summaries, and leadership-ready risk reporting.
  • Proficiency in at least one common development or scripting language such as Java, Python, JavaScript, TypeScript, or Node.js.
  • Graduation from an accredited institution with a Bachelor’s degree in Engineering, Information Systems, Computer Science or a related field or any combination of education and/or experience.

Nice To Haves

  • Experience securing retail, ecommerce, payments, loyalty, customer identity, fraud prevention, or high-traffic customer-facing platforms built on modern web, cloud, container, CDN, or edge architectures.
  • Experience with application security and delivery platforms.
  • Experience improving AppSec outcomes through automation, prototypes, AI security practices, secure AI-assisted development, model/component inventory, or developer remediation workflows.
  • OSCP
  • SANS/GIAC (GWAPT, GSEC, GCIH, GCIA, etc.)
  • Public Cloud DevOps certifications
  • CEH
  • Relevant coding certifications

Responsibilities

  • Lead the Application Security team across secure SDLC enablement, vulnerability management, secure code review, security testing, and developer partnership.
  • Oversee application security reviews, including architecture and design review, threat modeling, code review, API security review, and targeted testing.
  • Own application vulnerability governance, including intake, triage, prioritization, SLA management, remediation tracking, validation, exceptions, and leadership reporting.
  • Manage vulnerability disclosure, bug bounty, and external findings processes.
  • Partner with CI/CD, DevOps, SRE, Platform Engineering, and development teams to integrate security controls into delivery pipelines.
  • Translate security findings into actionable remediation plans and maintain application security requirements and control expectations aligned to internal standards and industry practices.
  • Drive secure design and remediation for commerce platforms, APIs, web applications, mobile-supporting services, cloud workloads.
  • Identify and reduce software supply chain risk, including vulnerable or malicious packages, dependency management gaps, SBOM visibility, repository controls, and dependency confusion risks.
  • Support application-related security incidents and postmortems.
  • Partner with Security Operations on WAF, bot mitigation, cloud security, logging, alerting, and compensating controls when remediation requires staged mitigation or fast-follow delivery.
  • Create metrics and dashboards showing application security posture.
  • Deliver developer enablement through application security training, security champion content, secure coding guidance, and just-in-time coaching.
  • Evaluate application security tooling, vendor capabilities, proof-of-concepts, renewals, and integrations that improve outcomes without unnecessary operational friction.
  • Contribute to security reviews of AI-enabled development workflows, AI-native application components, model integrations, and emerging secure AI-SDLC practices.
  • Perform other job-related duties as assigned.

Benefits

  • 401k (6% match)
  • Flexible Schedules
  • Tuition Reimbursement
  • Leadership Development Program
  • Mentorship Program
  • Employee Resource Groups (LatinX, Black Employee Network, LGBTQIA+, Women’s Network, Women In Tech)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service