Senior Application Security Compliance Lead

SMBCCharlotte, NC
Hybrid

About The Position

As a Senior Application Security Compliance Lead, you will help strengthen SMBC's application security program by ensuring security findings are identified, prioritized, and addressed before code is released to production. You will work closely with software engineers, security teams, and technology leaders to improve secure development practices and reduce application risk. This role is well suited for someone with a strong technical background who can review code, explain security issues clearly, and guide remediation efforts across a diverse technology environment.

Requirements

  • 5+ years of experience in application security, application penetration testing, or a related cybersecurity discipline.
  • 5+ years of experience with Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), or similar application security technologies.
  • Strong knowledge of secure software development lifecycle (SSDLC) principles, OWASP Top 10, CWE, and common application security threats and mitigations.
  • Experience managing vulnerability remediation programs and engaging development teams to improve security outcomes.
  • Strong ability to read, analyze, and explain code-level security issues and remediation approaches.
  • Experience with one or more programming languages such as C#, C++, Java, Python, or .NET technologies.
  • Ability to develop remediation examples, automation scripts, and tooling to support cybersecurity initiatives.
  • Experience integrating security controls within CI/CD pipelines to improve code quality and vulnerability detection.
  • Experience with securing containerized environments and addressing container security risks.
  • Experience using Jira and Confluence for project tracking, documentation, and collaboration.
  • Strong attention to detail with the ability to create and maintain clear process documentation.

Nice To Haves

  • Experience building or leading security champion programs.
  • Experience with application security awareness and developer outreach initiatives.
  • Bug bounty participation or application penetration testing experience.
  • Experience presenting security metrics and program updates to senior leadership.

Responsibilities

  • Partner with application development teams to review security findings and drive timely remediation of vulnerabilities identified through security testing activities.
  • Monitor and support application security scanning programs, including SAST, SCA, DAST, IAST, and container security assessments.
  • Review code across multiple programming languages and explain security risks, root causes, and remediation approaches to technical and non-technical audiences.
  • Collaborate with application security, security architecture, and development teams to improve secure software development practices and threat mitigation strategies.
  • Work with vulnerability management teams to validate findings, track remediation progress, and ensure compliance with established service level agreements (SLAs).
  • Create and deliver reports and presentations that communicate application security posture, trends, risks, and remediation progress to leadership.
  • Perform targeted manual validation and testing of security findings, including vulnerability and penetration testing results when needed.
  • Contribute to process improvements, documentation, automation, and application security program maturity initiatives.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service