Senior Manager, Application Vulnerability Validation & Verification - USDS
- 🇺🇸 United States
- On-site
- Manager or above
- 3 months ago
- SAST
- DAST
- triage
- AppSec
- iOS
- Android
- Python
- Java
- JavaScript
- Burp Suite
- Snyk
- GitHub
- Microservices
- CI/CD
- Kubernetes
- Docker
- OSWE
- CSSLP
- Threat Modeling
About the Team
The Validation and Verification (VnV) organization ensures the security and reliability of our products by validating that security controls are implemented correctly, operating effectively, and delivering measurable risk reduction across the enterprise.
VnV operates across a continuous security lifecycle: Prevent → Assure → Test → Fix → Prove, ensuring that security posture is not only designed and tested, but continuously validated in real-world conditions.
We are seeking a Senior Manager to architect, scale, and lead our Application Vulnerability Validation team based in San Jose.
This is a highly strategic leadership position, moving far beyond administrative backlog management. Your organization serves as the definitive validation layer for code safety. Your team will ingest raw telemetry from SAST, DAST, and SCA tooling to answer the critical questions: Is this vulnerability exploitable in production, and does it present a viable path for an attacker?
In this role, you will balance two primary strategic pillars
- Deep Technical Execution: Leading a specialized engineering team in manual vulnerability validation, proof-of-concept development, and complex attack-path mapping across web, mobile, and API surfaces.
- Engineering & Automation: Designing the automation and tooling strategy required to scale this function. Leveraging advanced workflows and agentic AI to minimize false positives at the source and convert expert human judgment into reusable code.
You will report directly to Validation and Verification leadership, maintain full ownership of the strategy and headcount for this software assurance function, and partner across U.S. and global engineering product lines.
Responsibilities
- Team Leadership & Capability Building: Hire, mentor, and technically direct a high-performing team of Application Security engineers. Establish rigorous operational standards and define the benchmark for technical excellence within the function.
- Automation & Next-Generation Triage: Drive the strategy and hands-on development of our automated AppSec pipeline. Architect custom tooling, scanner-API integrations, and LLM-assisted triage systems to drastically accelerate analysis and eliminate false positives before they require human intervention.
- Advanced Vulnerability Verification: Oversee deep-dive technical analysis across web, mobile (iOS/Android), and API endpoints, ensuring the team moves beyond automated scanner outputs to confirm true production exploitability.
- Attack Path & Blast Radius Analysis: Drive contextual, systemic analysis of how vulnerabilities chain across a massive software supply chain, proactively identifying risks to sensitive data or critical infrastructure.
- Cross-Functional Collaboration: Build durable, collaborative relationships with U.S. and global engineering product teams to implement strategic, systemic mitigations rather than temporary patches.
- Technical Advisory: Serve as a principal internal consultant, providing precise, actionable, and architecturally sound secure-coding guidance to product and platform teams.
Minimum Qualifications
- Proven AppSec Leadership: A demonstrable track record of leadership within Application Security, Product Security, or Software Security Engineering. We prioritize the depth, technical complexity, and impact of what you have built over strict year counts; however, successful candidates typically bring 5 years of domain experience, including formal team management.
- Engineering & Scripting Fluency: Strong proficiency in software development and scripting (Python, Go, Java, or JavaScript) to interface with scanner APIs and build scalable internal automation platforms.
- Tooling & Ecosystem Expertise: Deep familiarity with orchestrating and optimizing enterprise SAST/DAST/SCA platforms (e.g., Checkmarx, Veracode, Burp Suite Enterprise, Snyk, GitHub Advanced Security).
- Modern Architecture Literacy: A strong conceptual and practical understanding of microservices, service mesh, CI/CD pipelines, Kubernetes, Docker, and API gateways.
Preferred Qualifications
- Advanced technical certifications demonstrating deep hands-on expertise (e.g., OSWE, OSWA, GWE, CASE, CSSLP).
- Experience navigating massive, highly distributed architectures and coordinating remediation across multi-national engineering organizations.
- Experience utilizing formal threat modeling frameworks on complex features to proactively map systemic risk.
- Exceptional communication and influence skills—the ability to resolve engineering misalignment by presenting objective, contextualized threat evidence.
Senior Manager, Application Vulnerability Validation & Verification - USDS · TikTok USDS