About The Position

The Senior Application Security and Infrastructure Protection Manager is responsible for leading a comprehensive security function that embeds security into software development, protects critical infrastructure, strengthens security operations, and supports compliance and risk management across VENU+ technology platforms and business lines, including Mobility Services, Smart Lockers, and Photo Services. This role combines secure software development, application security engineering, DevSecOps enablement, infrastructure security, vulnerability management, incident response, policy governance, and audit readiness into one integrated position. The role works closely with software development, DevOps, IT operations, cybersecurity, executive leadership, vendors, finance, and business stakeholders to ensure applications, systems, cloud services, networks, endpoints, identities, data, and third-party platforms are designed, deployed, monitored, and maintained in a secure, resilient, compliant, and risk-aware manner.

Requirements

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Software Engineering, Information Systems, or a related field, or equivalent practical experience.
  • 7+ years of progressive experience across cybersecurity, application security, secure software development, DevSecOps, infrastructure security, security operations, or related technology roles.
  • Strong understanding of secure software development practices, OWASP Top 10, secure coding principles, threat modelling, API security, authentication, authorization, session management, encryption, and data protection.
  • Hands-on experience with security tools and practices such as SAST, DAST, SCA, dependency scanning, container scanning, secret scanning, vulnerability scanning, SIEM, EDR, log analysis, and incident response workflows.
  • Experience protecting infrastructure, cloud platforms, SaaS systems, networks, endpoints, servers, databases, identity platforms, privileged access, backups, and disaster recovery capabilities.
  • Working knowledge of risk management, control frameworks, audit evidence, compliance obligations, privacy requirements, third-party risk management, security policies, and governance processes.
  • Strong leadership, analytical thinking, risk judgement, documentation, communication, stakeholder engagement, incident coordination, prioritization, and problem-solving skills.

Nice To Haves

  • Familiarity with frameworks and standards such as NIST, ISO 27001, CIS Controls, SOC 2, PCI DSS, OWASP ASVS, ITIL, and secure software development lifecycle practices is preferred.
  • Relevant certifications such as CISSP, CSSLP, CISM, CCSP, GIAC, Security+, Azure Security Engineer, AWS Security Specialty, or equivalent credentials are desirable.

Responsibilities

  • Advise on application security engineering practices across the software development lifecycle, including secure design reviews, threat modelling, secure coding standards, architecture input, code review guidance, and release security validation.
  • Embed DevSecOps controls into development and delivery pipelines, including SAST, DAST, dependency scanning, secret scanning, container scanning, infrastructure-as-code review, security gates, and remediation workflows.
  • Partner with software, DevOps, product, and QA teams to identify application risks early, validate security requirements, prioritize vulnerabilities, and ensure secure-by-design outcomes for web, mobile, API, cloud, SaaS, and integration platforms.
  • Protect infrastructure, cloud services, networks, endpoints, servers, databases, identities, privileged access, and business-critical systems through secure configuration baselines, hardening standards, monitoring, patching, and control validation.
  • Manage vulnerability, patch, and remediation programs across applications and infrastructure, including risk ranking, ownership assignment, exception handling, reporting, verification, and executive escalation where required.
  • Lead security operations activities, including alert triage, incident response coordination, investigation support, root cause analysis, containment, recovery, post-incident reviews, and improvement actions.
  • Maintain and improve security monitoring, logging, endpoint protection, identity protection, email security, backup resilience, disaster recovery readiness, and business continuity controls.
  • Develop, maintain, and enforce cybersecurity policies, secure software development standards, infrastructure protection procedures, risk registers, control evidence, security documentation, and operational runbooks.
  • Support compliance, audit readiness, and governance activities aligned with applicable internal policies, customer requirements, contractual obligations, privacy requirements, and recognized security frameworks.
  • Assess and manage technology, application, infrastructure, cloud, vendor, and third-party security risks, including due diligence, control reviews, risk acceptance, remediation tracking, and security recommendations.
  • Provide security guidance to leadership and stakeholders through clear reporting on security posture, vulnerabilities, incidents, compliance status, control gaps, residual risks, and improvement priorities.
  • Promote a security-first culture by coaching developers, IT teams, business users, and vendors on secure practices, risk awareness, incident prevention, and practical control adoption.

Benefits

  • Flexible Time Off
  • Paid holidays
  • Comprehensive medical, dental, and vision plans
  • 401(k) plan with 50% company match on the first 6% contributed, including Roth options
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service