_(1).png?1695930103)
Application Security Manager
Company Description
Workleap builds practical employee experience software that makes work simpler.
Our products include Workleap, a simple employee experience platform to boost engagement, drive performance, and develop teams, and ShareGate by Workleap, a single, trusted out-of-the-box solution for fast and secure migration, adoption, and Copilot readiness—simplifying data management across Microsoft 365.
With over 20,000 happy customers in more than 100 countries, Workleap products are a must-have for businesses looking to create a more engaging and successful workplace.
Job Description
So, what will your new role look like?
As an Application Security Manager, you will be responsible for driving the security posture of our products by operationalizing and managing our application security program. You will oversee the identification, remediation, and closure of security vulnerabilities within our codebase. Your role will be instrumental in ensuring that security best practices are embedded throughout the Software Development Lifecycle (SDLC) while maintaining strong collaboration with our engineering teams.
You will work will involve three key pillars:
- Program Management – Develop, implement, and oversee all aspects of the AppSec program, ensuring vulnerabilities are systematically identified and remediated.
- Stakeholder Management – Partner with developers, product managers, and other stakeholders to enable a security-first mindset without disrupting agile development workflows.
- Technical Expertise – Act as a hands-on security expert, performing security reviews, threat modelling and contributing to secure coding practices.
Responsibilities:
- Lead the operational execution of the application security program across all products;
- Perform security reviews, threat modeling, and penetration testing for new features and major code changes;
- Identify, assess, and report security vulnerabilities, ensuring timely remediation and closure;
- Develop security tooling and automation to improve vulnerability detection and response;
- Collaborate closely with development teams to enhance secure coding awareness and best practices;
- Investigate and validate externally reported security vulnerabilities;
- Monitor emerging threats and security research to proactively enhance our security posture;
- Define and implement security requirements for application architecture and development processes;
- Support security incident response efforts, contributing to forensic analysis and remediation;
- Establish and track key AppSec metrics to measure program effectiveness and continuous improvement.
A typical week?
- Engage with engineering teams to review code, conduct security assessments, and drive remediation efforts;
- Collaborate with product managers and stakeholders to integrate security requirements into development workflows;
- Develop and refine security automation tools to streamline vulnerability identification and management;
- Participate in security architecture reviews and design discussions;
- Monitor security alerts and vulnerabilities, triaging and prioritizing responses as needed;
- Contribute to security awareness training and advocate for secure development best practices.
What does your future team look like?
You will work closely with engineering, security, and product teams to implement security controls, assess risks, and promote a security-first culture. Your role is hands-on and influential, ensuring that security is a business enabler rather than an obstacle.
What are the next challenges awaiting your team?
- Expanding and scaling the application security program across a growing portfolio of SaaS products;
- Enhancing security automation and tool integration within CI/CD pipelines;
- Strengthening developer security awareness and secure coding capabilities;
- Participating in the incident response processes and reducing risk across cloud-native environments.
Qualifications
- 8+ years of experience in Application Security and running an AppSec program;
- Deep understanding of web application security fundamentals, OWASP Top 10, and CWE Top 25;
- Hands-on experience with secure code reviews in Java, .NET, PHP, Go, C, C++, Python, Swift, or Kotlin;
- Experience integrating security into the SDLC, including SAST, DAST, SCA, and fuzzing;
- Proficiency in scripting languages (Python, Bash) for security automation;
- Familiarity with authentication protocols such as OIDC, SAML, and OAuth;
- Solid understanding of cloud-native security principles and modern infrastructure security controls;
- Strong ability to communicate security risks and best practices to technical and non-technical stakeholders;
- Experience leading technical security projects and influencing security culture within engineering teams.
Additional Information
At Workleap, we build together, we trust each other, and we support each other in success or failure. You will be able to express yourself, evolve and develop your creativity in an environment that will adapt to your daily life and your needs.
We strive to create a healthy and inclusive work environment. This is everyone’s business.
Our Candidate Experience Flow at Workleap:
Phone Screen - Virtual Interview using Microsoft Teams - Work Sample - Job Offer
We are looking forward to getting to know you!
By applying to this job, you are confirming that you have read and agree to the terms of our privacy policy.
#LI-Remote
Apply for this job
*
indicates a required field