This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As the Director of Application Security, you will lead and scale AlphaSense's Application Security function, reporting to the VP of Product Security. You will build and manage a high-performing team responsible for securing our cloud-based SaaS products across the entire software development lifecycle. In this role, you'll establish strategic security initiatives, drive organizational change, and partner closely with engineering, product, and compliance teams to embed security as an enabler of innovation rather than a blocker. You'll balance hands-on technical leadership with people management, mentoring engineers while shaping the vision and roadmap for application security in a fast-growing, AI-driven technology company. This role requires someone who can translate complex security challenges into business outcomes and foster a culture of security excellence across distributed global teams.
Job Responsibility:
Build, mentor, and manage a globally distributed team of application security engineers, establishing career development paths and fostering a collaborative security culture
develop and execute the application security strategy, defining metrics and KPIs while partnering with leadership to communicate security posture to executives
oversee application security initiatives across all products, including secure SDLC practices, vulnerability management, threat modeling, architecture reviews, and bug bounty programs
define tooling strategy for Application Security, driving automation to achieve high remediation coverage while maintaining development velocity
partner with engineering, product, compliance, and other security teams to embed security throughout the organization, delivering training and acting as a trusted advisor on security architecture
Requirements:
10+ years of experience in Application or Product Security
at least 3+ years in a management or leadership role
proven track record of building and scaling security teams in SaaS or cloud-native environments
deep expertise in web application security, API security, microservices, and containerized architectures
strong understanding of modern development practices, including CI/CD, DevSecOps, and agile methodologies
experience implementing and managing security tooling across the SDLC (SAST, DAST, SCA, container scanning)
demonstrated ability to work effectively with distributed global teams across multiple time zones
excellent communication and stakeholder management skills, with the ability to present to executive audiences
strong technical background with hands-on experience in at least one major programming language (Python, Java, Go, JavaScript)
knowledge of cloud security best practices, particularly AWS, Kubernetes, and container orchestration
Nice to have:
Experience in data analytics, AI/ML, or LLM product security
background implementing runtime application security or supply chain security controls
track record of driving security automation initiatives that improve both security posture and developer experience
experience with security frameworks (OWASP SAMM, BSIMM, NIST CSF)
certifications such as CISSP, OSCP, OSWE, CSSLP, AWS Security Specialty, or CCSP
prior experience managing security in highly regulated industries or with enterprise customers
What we offer:
Competitive compensation, benefits, and career growth opportunities