hirly

Western Union

Director Application Security

USA TX - Austin - 11902 Burnet Rd

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Western Union first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.6M live jobs from 190,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Director
Country
US
Work mode
On-site / unstated
First seen by hirly
3 Oct 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

We are seeking an experienced and visionary Director Application Security to lead the strategy, development, and execution of our Application Security program. Reporting to the Vice President of Security Operations, this leader will be responsible for maturing and optimizing application security capabilities across the software development lifecycle, ensuring secure-by-design principles are embedded into engineering practices while enabling rapid delivery of innovative products.

This individual will partner closely with Engineering, Product Management, Architecture, DevOps, Cloud Engineering, and Security Operations to integrate security into every phase of software development. The successful candidate will have extensive experience building or transforming Application Security programs within complex technology organizations and will possess the ability to influence engineering culture through collaboration rather than gatekeeping.

Role Responsibilities:

Application Security Strategy

Develop and execute the enterprise Application Security strategy aligned with business and technology objectives.

Build and mature a scalable Application Security program supporting modern software development practices.

Define the long-term roadmap for secure software development across cloud, web, mobile, APIs, and emerging technologies.

Establish secure-by-design principles and integrate them throughout the Software Development Life Cycle (SDLC).

Secure Development Lifecycle (SSDLC)

Lead the implementation and continuous improvement of a Secure Software Development Lifecycle (SSDLC).

Develop standards and security requirements for application development.

Partner with engineering teams to integrate security early within CI/CD pipelines.

Promote developer-friendly security practices that minimize friction while improving software security.

  • Security Testing & Assurance
  • Oversee enterprise application security testing, including:

Static Application Security Testing (SAST)

Dynamic Application Security Testing (DAST)

Software Composition Analysis (SCA)

Interactive Application Security Testing (IAST)

API Security Testing

Container Security

Infrastructure-as-Code (IaC) Security

Secure code reviews

Penetration testing coordination

DevSecOps Enablement

Partner with DevOps teams to embed automated security controls into CI/CD pipelines.

Improve automation of security testing and vulnerability management.

Reduce developer burden through integrated tooling and streamlined workflows.

Measure security effectiveness while enabling engineering velocity.

Operationalize Continuous Threat & Exposure Management (CTEM) across critical applications and business services

  • Define CTEM scope around critical business services, crown-jewel applications, sensitive data, material APIs, and externally exposed assets.
  • Consolidate exposure signals from application testing, attack-surface management, cloud security, vulnerability management, penetration testing, bug bounty, and threat intelligence.
  • Establish a common exposure taxonomy and risk model that incorporates exploitability, reachability, business criticality, threat activity, and compensating controls.
  • Maintain an evidence-backed view of application exposure rather than relying primarily on scanner severity.
  • Cloud & Modern Architecture Security
  • Provide application security guidance for:

Cloud-native applications

Microservices

APIs

Containers

Kubernetes

Serverless architectures

Artificial Intelligence and Machine Learning applications

Third-party integrations

Engineering Partnership

Build trusted relationships with engineering leadership.

Champion security as an engineering quality function.

Develop security champions programs across engineering organizations.

Leadership

Lead, mentor, and develop a high-performing Application Security team.

Establish performance metrics and operational objectives.

Manage vendor relationships and application security technologies.

Support hiring and organizational growth as the program matures.

Mentor developers on secure coding practices and emerging threats.

Role Requirements:

Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related field required.

Advanced degree preferred.

10+ years of progressive experience in Application Security, Software Security, Product Security, Secure Engineering, or related cybersecurity disciplines.

5+ years leading Application Security teams.

Demonstrated success building, transforming, or significantly maturing Application Security programs within enterprise organizations.

Experience partnering closely with software engineering organizations in Agile and DevSecOps environments.

Strong understanding of:

Secure Software Development Lifecycle (SSDLC)

OWASP Top 10

Secure coding principles

Threat modeling

Modern authentication protocols

API security

Cloud-native application security

Container security

CI/CD security

DevSecOps

Software supply chain security

AI-assisted software development ("vibe coding") governance and secure use

Application vulnerability management

Possesses at least one of the following certifications (o4 comparable alternative):

CISSP

CSSLP

GIAC Secure Software Programmer (GSSP)

GIAC Cloud Security Automation (GCSA)

  • What Success Looks Like:
  • Within the first 12–18 months, this leader will

Complete a comprehensive assessment of the organization's Application Security maturity.

Develop and execute a multi-year Application Security transformation roadmap.

Fully integrate security into CI/CD pipelines across major engineering organizations.

Implement meaningful risk-based application security metrics and executive dashboards.

Reduce application vulnerability remediation times while improving engineering satisfaction.

Standardize threat modeling, secure code review, and security testing practices.

Develop measurable improvements in software security posture without negatively impacting developer productivity.

Work Shift - HYBRID

Benefits

You will also have access to short-term incentives, multiple health insurance options, accident and life insurance, and access to best-in-class development platforms, to name a few. Please see the benefits below specific to your country. If applicable, additional role-specific benefits will be mentioned during your interview process or in an offer of employment.

Your United States specific benefits include:

Parental Leave

Family First Programs

Medical, Dental, and Life Insurance

Tuition Repayment Assistance Program

For residents of Colorado, California, Connecticut, Delaware, Minnesota, and Pennsylvania: Please do not respond to any questions on this initial application that may seek age-identifying information such as age, date of birth, or dates of school attendance or graduation. You may also redact this information from any materials you submit during the application process. You will not be penalized for redacting or removing this information.

Salary

The base salary range is $200,000 - $215,000 USD per year, total on target compensation includes a base salary plus a variable target incentive that aligns with individual and company performance.

Other Details

As part of the application process, all applicants are required to take assessments. Western Union has partnered with a 3rd party provider to administer these tests. Applicants will need to provide their name and email address in order to process the assessments. If you have any questions, you may reach out to careers@westernunion.com .

We are passionate about honoring our employee's identity and fostering a feeling of belonging. Our commitment is to provide an inclusive culture that celebrates the unique backgrounds and perspectives of our global teams while reflecting the communities we s

Original posting on Western Union's site ↗

Listed on hirly, a job board. hirly is not the employer: Western Union is hiring for this role.

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job