Director, Application Security
- Full-time
Company Description
Therapy Brands is the leading healthcare technology partner for mental, behavioral, and rehabilitative therapy. Our purpose-built and all-in-one practice management, data, and billing solutions drive exceptional clinical and financial outcomes.
Thousands of therapy practices rely on us as a trusted partner, to make their lives simpler and more efficient, improve revenue, and enable them to focus on patient care.
For more information, explore our solutions at therapybrands.com.
Job Description
We're seeking a Director of Application Security to lead our application security initiatives, interacting closely with software development and product teams to integrate secure practices within the SDLC. Key responsibilities include managing the application security program, collaborating with engineers and leadership to mitigate risks, and setting strategies for security testing operations. You will guide teams on security best practices, oversee vulnerability management, and provide strategic insights on security risks to senior management. The role also entails collaboration on compliance audits, leading security technology projects across the enterprise, and developing educational programs for the development community. This position requires a blend of expertise in application, network, and cloud security, along with a strong ability to integrate security measures into our CI/CD pipelines and development processes.
Responsibilities:
- Interact with Company's software development and product teams to advocate secure SDLC activities. Operate as an advocate for Security in interactions with internal and external teams.
- Collaborate with software engineers and leadership to address security risks and provide mitigation recommendations within the Secure Development Lifecycle (SDLC).
- Work with security champions to build relationships and ensure key activities are supported and deliverables are achieved in a timely manner.
- Manage and mature the application security program through direct interactions.
- Identify improvement opportunities in all processes and activities involved.
- Work with architects and engineers to review and design security requirements.
- Participate in security and technology strategic planning to ensure identified risk governance is incorporated into the enterprise strategy.
- Appropriately assess risk and provide software security advice when business decisions are made.
- Set strategies, processes and oversee the management and operations of SAST, SCA, DAST, and penetration testing operations to provide coverage for the application portfolio.
- Function as a subject matter expert in application, network and cloud penetration testing, scanning platforms, exploits, tools, and techniques.
- Building and executing a security testing strategy.
- Oversee vulnerability identification and measurement. Help the enterprise manage vulnerabilities across automated tooling and manual security assessments.
- Guide development teams through a review of their applications and risks against common application flaws like OWASP Top 10 and others
- Provide visibility to senior management along with context and prioritization of the issues.
- Work with Risk & Compliance teams on PCI-DSS, HIPAA, and other audits as needed
- Research and recommend policy and procedures as they relate to Application Security
- Lead projects to implement security technologies for the entire enterprise.
- Integrates 3rd party and builds custom solutions into our CI/CD pipelines and development cycles.
- Define security guardrails through automated tool policies, SLAs, custom rules, and support the developer community.
- Support education and awareness strategy, rollout for software development community.
Qualifications
- Proven experience in leading application security programs and initiatives in a large-scale environment.
- Deep understanding and practical experience with Secure Software Development Life Cycle (SDLC) practices.
- Strong technical expertise in SAST, SCA, DAST, and penetration testing methodologies.
- Familiarity with common application security risks, such as the OWASP Top 10, and experience in guiding teams to mitigate these risks.
- Knowledge of compliance and regulatory frameworks, such as PCI-DSS and HIPAA, and experience in managing related audits.
- Proficiency in integrating security tools and practices into CI/CD pipelines and development processes.
- Excellent leadership, communication, and project management skills, with a track record of driving security awareness and education initiatives within software development teams.
Additional Information
While we've outlined some key qualities we typically seek, it's essential to remember that there might be additional unique strengths and talents you possess that would make you an exceptional match for us, even if they're not explicitly mentioned. Studies have consistently highlighted the significance of this principle, particularly for individuals from disenfranchised backgrounds, including women and other marginalized groups. These individuals often hesitate to apply unless they meet every single requirement, unlike their male counterparts who are more inclined to apply when they meet around 60% of the criteria.
The message we want to convey is that taking a leap of faith and applying can be incredibly rewarding. Your distinct abilities and perspectives could be exactly what we need to create a more diverse and inclusive team. So, don't hesitate—apply today and let's explore the exciting possibilities together!
All your information will be kept confidential according to EEO guidelines.
At Therapy Brands, Diversity, Equity, Inclusion, and Belonging aren’t just words. We celebrate what makes us unique, foster an ecosystem of inclusion for all and harness our talents to promote diversity of thought and action in everything we do.
We instill Diversity, Equity, Inclusion, and Belonging into the fabric of our CARING culture and business, as we strive to be recognized not only as the leader in healthcare technology, but also for our intentional efforts to promote a diverse community.
We will champion non-discriminatory practices throughout the employee and customer lifecycle; caring for every person regardless of race, national origin, color, religion, disability, sex, orientation, or familial status.
Therapy Brands is an equal opportunity employer.
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply