Simpson Thacher & Bartlett LLP Logo

Simpson Thacher & Bartlett LLP

Senior Manager, Application Security

Posted 4 Days Ago
Be an Early Applicant
In-Office
New York, NY, USA
190K-220K Annually
Senior level
In-Office
New York, NY, USA
190K-220K Annually
Senior level
Lead and operationalize the enterprise application security program across internal and third-party applications, APIs, cloud-native and containerized workloads. Define secure SDLC/DevSecOps standards, integrate automated testing into CI/CD, manage AppSec tooling lifecycle, perform threat modeling and architecture reviews, mentor engineers, manage third‑party risk, and report metrics to technical and executive stakeholders.
The summary above was generated by AI

JOB SUMMARY
The Senior Manager, Application Security is responsible for defining, leading, and operationalizing the firm’s application security program across internally developed applications, SaaS platforms, APIs, databases, generative AI platforms, and emerging application architectures. This role partners closely with application engineering, cloud, and platform teams to embed security into the software development lifecycle while enabling teams to deliver securely at scale.

The ideal candidate is a highly skilled, hands-on technical leader who can translate security requirements into practical developer workflows while enabling rapid and reliable software delivery.

JOB DUTIES & RESPONSIBILITIES

  • Develop, execute, and continuously mature the enterprise application security strategy in alignment with industry best practices, regulatory requirements, and client contractual obligations.

  • Define and maintain secure application development standards for internally developed software, third-party applications, APIs, SaaS platforms and containerized workloads.

  • Establish minimum security requirements for application authentication, authorization, encryption, secrets handling, and data protection.

  • Define, maintain, and enforce secure SDLC and DevSecOps standards across all development teams.

  • Integrate application security controls into CI/CD pipelines, developer platforms, and engineering workflows with a focus on automation and scalability.

  • Partner with Application Engineering and DevOps teams to embed automated security testing and preventive controls while maintaining security ownership of policy and enforcement.

  • Evaluate, select, implement, and manage the full lifecycle of application security tooling including:

    • SAST, DAST, SCA, and API security testing platforms

    • Container image scanning and registry security tooling

    • Kubernetes security and runtime protection solutions

    • Software supply chain security tooling

  • Design and implement integrations between application security tooling and developer workflows to minimize friction and maximize adoption.

  • Design and build automation to support application security processes including:

    • Orchestrated automated security testing.

    • Vulnerability triage and prioritization workflows

    • Developer feedback loops and ticketing system integrations

    • Exception handling, risk acceptance, and policy waiver workflows

    • Security metrics and pipeline telemetry

  • Identify and assess application security risks including vulnerable dependencies, insecure authentication patterns, data exposure risks, and insecure configuration.

  • Perform and support threat modeling, architecture reviews, and secure design assessments for high-risk, or business critical applications.

  • Support the security review, onboarding, and ongoing risk management of third-party and SaaS applications.

  • Develop and maintain metrics, dashboards, and reporting to measure application security posture, testing coverage, and vulnerability remediation effectiveness.

  • Provide application security subject matter expertise during security incidents, investigations, and post-incident remediation efforts.

  • Lead, mentor, and develop a team of application security engineers, fostering strong technical depth and career growth.

  • Partner with engineering leadership to drive secure-by-design development practices and shared accountability for risk reduction.

  • Communicate application security risks, tradeoffs, and recommendations clearly to both technical and executive stakeholders.

  • Promote a developer-friendly security culture focused on automation, guardrails, measurable risk reduction, and engineering velocity.

  • Stay current on emerging application threats, attack techniques, and defensive technologies, and apply this knowledge to continuously improve program effectiveness.

EDUCATION 
Required

  • Bachelor’s degree in information security, IT, risk management, related discipline, or equivalent experience

Preferred

  • Professional certifications such as CISSP, CISM, or similar

SKILLS AND EXPERIENCE

  • 10+ years of progressive experience in application security, product security, or software security engineering roles

  • Hands-on experience securing modern application ecosystems, including web applications, APIs, microservices, cloud-native workloads, container, and Kubernetes platforms

  • Demonstrated success building, scaling, and operating enterprise-grade Application Security programs within large, complex organizations, preferably in hybrid environments (on-premises, multi-cloud, Kubernetes, and SaaS).

  • Experience partnering with application, DevOps, and platform engineering teams to design and implement security controls that scale without impeding developer velocity.

  • Hands‑on experience implementing and operationalizing enterprise application security tooling and integrating controls into CI/CD pipelines and developer workflows.

  • Technical Skills & Knowledge:

    • Secure SDLC principles and DevSecOps integration patterns

    • Application security testing methodologies and tooling (SAST, DAST, SCA, API testing)

    • Container security concepts, including image hardening, vulnerability scanning, secure registries, and container lifecycle management.

    • Cloud-native application security concepts

    • Software supply chain security principles

    • Security automation and scripting (Python, PowerShell, or similar)

    • CI/CD security integration patterns

  • Demonstrated ability to lead, mentor, and develop high‑performing application security or product security engineering teams.

  • Strong program and project management capabilities, with a track record of delivering complex, cross‑functional initiatives on time and within budget.

  • Experience operating within global organizations and collaborating effectively across diverse geographies, cultures, and business units.

  • Proven ability to manage third‑party vendors and security technology providers, including evaluation, onboarding, delivery oversight, and performance management.

  • Strong interpersonal and collaboration skills, with comfort engaging regularly with senior leadership and key internal and external stakeholders.

  • Excellent executive communication and presentation skills, with the ability to clearly articulate risk, strategy, and technical concepts to both technical and non-technical audiences.

  • Strong ability to manage multiple concurrent priorities, exercise sound judgment, and effectively allocate time and resources in a fast‑paced environment.

  • Proven ability to execute effectively amid ambiguity and incomplete information, applying risk‑based decision‑making.

  • Demonstrated continuous learning mindset, staying current on emerging technologies, security threats, vulnerabilities, and attack vectors.

  • Passion for innovation, automation, and driving continuous improvement in application security processes.

POSTING DISCLOSURE:

Simpson Thacher will not sponsor applicants for work visas for this position.

Salary Information

NY Only: The estimated base salary range for this position is $190,000 to $220,000 at the time of posting.

The actual salary offered will depend on a variety of factors, including without limitation, the qualifications of the individual applicant for the position, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location in which the applicant lives and/or from which they will be performing the job. This role is exempt meaning it is not overtime pay eligible.


Simpson Thacher will not sponsor applicants for work visas for this position.

Privacy Notice

For information about how Simpson Thacher & Bartlett LLP collects and processes your personal information, please refer to our Privacy Notice available at https://www.stblaw.com/other/privacy-notice.

Simpson Thacher & Bartlett is committed to a collegial work environment in which all individuals are treated with respect and dignity. The Firm prohibits discrimination or harassment based upon race, color, religion, gender, gender identity or expression, age, national origin, citizenship status, disability, marital or partnership status, sexual orientation, veteran’s status or any other legally protected status. This Policy pertains to every aspect of an individual’s relationship with the Firm, including but not limited to recruitment, hiring, compensation, benefits, training and development, promotion, transfer, discipline, termination, and all other privileges, terms and conditions of employment.

#LI-Hybrid

Similar Jobs

3 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
170K-190K Annually
Senior level
170K-190K Annually
Senior level
AdTech • Artificial Intelligence • Marketing Tech • Software • Analytics
Lead end-to-end Application Security product and program: set strategy, prioritize roadmap, ship AI-powered threat modeling and code-evaluation surfaces, enable secure-by-design SDLC, enforce CI/CD gates, drive vulnerability prioritization/remediation, establish governance and metrics, and align security initiatives with engineering and executive stakeholders.
Top Skills: AIApi SecurityAuthenticationAuthorizationCi/CdContainer ScanningCryptographyDastIac ScanningIde IntegrationsLlmsMr IntegrationsMulti-TenancyRapid7Remediation OrchestrationSastScaSecrets ScanningSecure SdlcSecurity DashboardsSnykSupply Chain SecurityThreat ModelingVulnerability ManagementWiz
4 Days Ago
In-Office
New York, NY, USA
210K-250K Annually
Senior level
210K-250K Annually
Senior level
Consumer Web • Fintech • Mobile • Software • Financial Services
Lead Betterment's Application Security squad to enable secure-by-default development: build guardrails, threat modeling, design reviews, vulnerability management, and developer tooling; mentor senior engineers; drive roadmap and cross-functional partnerships; and incorporate AI to scale AppSec operations.
Top Skills: Ai-Assisted Security ToolsAWSCi/CdContainersKubernetes
4 Days Ago
In-Office
New York, NY, USA
125K-233K Annually
Senior level
125K-233K Annually
Senior level
Information Technology
Lead and grow an Application Security practice: define standards, assess application security posture, advise on secure-by-design architectures, integrate AI scanning, lead teams of engineers/architects, drive remediation, and support business development and sales for application security services.
Top Skills: Ai ScanningCi/CdCode Scanning ToolsDastFrontier AiIastMythosNistOwasp Top 10SastScaThreat ModelingVulnerability Management

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account