Director, App Security

UFCNew York, NY
Hybrid

About The Position

TKO Group Holdings, Inc. is seeking a hands-on Director, Application Security Engineering to enhance its cybersecurity defenses. This role involves partnering with software development teams across web, mobile, data, and AI to integrate security into delivery practices, reduce risk, and improve application and agent security. The Director will collaborate with various engineering, platform, DevOps, architecture, QA, infrastructure, compliance, and security teams to mature secure SDLC (SSDLC) practices, implement developer-friendly guardrails, and address application and agent security. Responsibilities include code review, tooling configuration, threat modeling, vulnerability management, automation, security enablement, and addressing emerging AI security concerns. This is a hybrid role requiring 3 days per week in-office, with a preference for candidates located near TKO offices in NYC, Stamford, Orlando, Austin, or Las Vegas.

Requirements

  • 5+ years of hands-on experience in application security, product security, DevSecOps, and security engineering or a closely related software security role.
  • Proven experience working directly with engineering teams in fast-moving delivery environments.
  • Hands-on experience configuring, tuning, and operationalizing SAST, SCA, and related tooling such as SonarQube, Dependabot, GitHub, GitHub Advanced Security, or comparable platforms.
  • Ability to interpret and reason about code, identify meaningful risk, and provide specific, implementable remediation guidance to engineers.
  • Practical experience with SSDLC and shift-left practices, including automated code review support, threat modeling, security design review, and vulnerability management.
  • Strong understanding of application and API security, including common software weaknesses, authN/authZ, secrets handling, dependency risk, injection, deserialization, and data protection.
  • Experience integrating reliable, scalable, and minimally disruptive security controls into CI/CD pipelines and developer workflows.
  • Hands-on familiarity with cloud and modern software delivery patterns, including containers, IaC, and Git-based workflows.
  • Strong judgment in vulnerability triage, balancing severity, exploitability, business impact, and engineering realities.
  • Ability to write clear guidance, standards, and technical documentation for technical and non-technical audiences.
  • Bias toward automation, simplification, and scalable solutions over manual heroics.
  • Broad DevSecOps mindset across code, pipelines, dependencies, platforms, deployment, and operations.
  • Experience using AI tools responsibly to improve engineering and security outcomes.

Nice To Haves

  • Experience securing AI agents, LLM-enabled applications, copilots, or agentic workflows in production or near-production environments.
  • Experience with DAST, API security testing, penetration testing coordination, red-team support, or adversarial testing of application and AI systems.
  • Experience with policy-as-code, IaC scanning, container/image security, software supply-chain security, SBOMs, provenance, attestation, and secrets management.
  • Familiarity with cloud security across AWS and/or GCP and the application-layer implications of cloud-native architectures.
  • Experience in regulated, audit-sensitive, or event-critical environments where evidence, controls, and operational rigor matter.
  • Experience building metrics, dashboards, or reporting that show AppSec posture and remediation progress.
  • Experience mentoring engineers and influencing secure engineering culture without direct people management responsibility.

Responsibilities

  • Own and evolve application security practices across the SSDLC, emphasizing scalable, developer-aligned, shift-left controls.
  • Operate and improve SAST, SCA, secret scanning, code scanning, repository protections, and related controls across repositories and CI/CD pipelines.
  • Develop secure development enablement for citizen developers, vibe coding, and AI-assisted development, including practical guidance for tooling, code assurance, identity, observability, and enterprise standards.
  • Review application and code-level vulnerabilities, validate findings, reduce noise, and drive risk-based remediation plans.
  • Conduct threat modeling and security design reviews for new systems, major changes, integrations, APIs, and high-risk workflows.
  • Advise teams on secure coding, authentication and authorization, session management, secrets handling, logging, encryption, dependency hygiene, and data protection.
  • Improve security guardrails for build pipelines, containers, APIs, third-party components, and deployment practices across modern and legacy environments.
  • Mature risk-based vulnerability management across intake, validation, prioritization, remediation guidance, exception handling, and reporting.
  • Support secure adoption of AI-assisted development and agentic systems by assessing trust boundaries, data exposure paths, prompt and tool-invocation risks, and misuse scenarios.
  • Develop pragmatic standards, playbooks, reference architectures, documentation, and office-hour support that improve consistency without slowing teams down unnecessarily.
  • Track recurring weaknesses, recommend structural fixes, and help leadership understand where engineering investment will reduce risk most effectively.
  • Use AI productively and responsibly to accelerate analysis, triage, documentation, coding support, and security review while maintaining strong human judgment.

Benefits

  • health care
  • retirement
  • vacation
  • other paid time off
  • additional offerings
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service