Manager, Application Security

Salesloft Salesloft · Enterprise · United States · Corporate Services

Manager, Application Security role at Salesloft, focusing on building and leading an AppSec engineering team, designing the AppSec roadmap, and managing security programs like SDLC, threat modeling, and bug bounties. The role requires independent execution, technical depth in web application security, and leadership skills in a high-autonomy environment. A key responsibility includes finding and implementing AI solutions to enhance security capabilities.

What you'd actually do

  1. Lead & Scale: Recruit, mentor, and manage a high-performing team of Application Security Engineers.
  2. Program Ownership: Design and execute the long-term AppSec roadmap, including Secure SDLC, threat modeling, and automated guardrails.
  3. Strategic Influence: Serve as a peer to Engineering Leaders, ensuring security is a first-class citizen in the product roadmap.
  4. Incident Management: Act as the primary escalation point for application-level security events, leading the team through containment and root-cause analysis.
  5. Vendor & Community Management: Oversee our Bug Bounty program, external penetration testing partners, and security tooling vendors (SAST, DAST, SCA).

Skills

Required

  • 8+ years of overall experience in Information Security with an emphasis on Application Security.
  • Strong understanding of web application security (OWASP Top 10), common attack vectors, and modern CI/CD pipelines.
  • Ability to make high-stakes decisions and prioritize the team's workload based on business risk, even with incomplete data.
  • Demonstrated ability to manage upward effectively, providing proactive results and strategic updates rather than requiring step-by-step guidance.
  • A "Team Over Self" mentality with the ability to influence senior engineering leadership without formal authority.
  • Find and implement AI solutions to enhance the Application Security and Engineering Teams capabilities and ability to execute.

Nice to have

  • CSSLP, CISSP, or GWEB are highly desirable.

What the JD emphasized

  • architect a secure-by-default culture
  • radical ownership
  • manager-of-one
  • navigate ambiguity
  • execute a long-term vision without needing a playbook provided for them
  • player-coach
  • high-trust, high-autonomy environments
  • been in the trenches
  • building systems and people
  • defines the "how" once we’ve agreed on the "what"
  • operating with minimal oversight
  • drive measurable risk reduction and program execution
  • bias-towards-action leader
  • own a function end-to-end
  • Independent Execution
  • Proven track record of taking messy, undefined security challenges and turning them into streamlined, repeatable processes without hand-holding.
  • Navigating Ambiguity
  • Ability to make high-stakes decisions and prioritize the team's workload based on business risk, even with incomplete data.
  • Low-Friction Leadership
  • Demonstrated ability to manage upward effectively, providing proactive results and strategic updates rather than requiring step-by-step guidance.