Senior Manager, Security Engineering, Application Security

Snap Snap · Consumer · Bellevue, WA +2

Senior Manager to lead the Application Security team at Snap, focusing on defining and driving a multi-year security strategy, identifying and reducing systemic product security risks, establishing scalable practices for secure design and testing, and leading security architecture reviews. The role emphasizes automation, influencing senior leadership, and recruiting/developing security engineers. It also involves utilizing AI tools to streamline development while ensuring code correctness and security.

What you'd actually do

  1. Define and drive a multi-year application security strategy aligned to Snap’s product roadmap and company priorities
  2. Identify systemic product security risks and assume direct ownership of high-impact initiatives that reduce risk at scale across Snap’s application ecosystem
  3. Establish scalable practices for secure design reviews, threat modeling, code review, and security testing (SAST, DAST, SCA, fuzzing, etc.)
  4. Lead application security architecture reviews for high-risk or high-impact product initiatives
  5. Drive automation-first approaches that increase security coverage while minimizing friction for engineering teams

Skills

Required

  • Deep expertise in application security, including secure architecture, common vulnerability classes (OWASP Top 10), mobile security, and modern attack techniques
  • Experience building and scaling secure SDLC programs across large engineering organizations
  • Proficiency in, or a strong aptitude for, leveraging AI tools to streamline development, paired with the critical judgment to audit generated output for architectural integrity, performance bottlenecks, and security risks.
  • Adaptability in learning and applying evolving AI systems and tools to remain at the forefront of engineering trends and modern development practices.
  • Strong understanding of web, mobile, and backend application architectures
  • Familiarity with security testing methodologies including SAST, DAST, IAST, SCA, fuzzing, and manual code review
  • Experience partnering with product engineering teams in fast-paced, consumer-scale environments
  • Demonstrated ability to operate strategically while staying connected to technical details
  • Bachelors in technical field such as computer science, mathematics, statistics or equivalent years of experience
  • 9+ years of post-Bachelor’s security experience; or a Master’s degree in a technical field + 8+ year of post-grad security experience; or a PhD in a related technical field + 5+ years of security experience
  • 2+ years of experience managing high-performing managers or providing technical and strategic leadership for engineering teams focused on advertising applications.
  • Proven experience in managing, mentoring, and scaling diverse engineering teams to consistently deliver complex, high-impact projects.

Nice to have

  • Experience leading application security in a large consumer technology company
  • Demonstrated success embedding security into high-velocity product organizations
  • Experience operating in zero-trust or BeyondCorp-inspired environments

What the JD emphasized

  • application security strategy
  • reduce risk at scale
  • security testing
  • AI tools