Senior Product Manager, Appsec

Capital One Capital One · Banking · McLean, VA +3

Senior Product Manager for Application Security (AppSec) at Capital One, focusing on integrating AI into the Software Development Lifecycle (SDLC) for enhanced security. The role involves defining strategy, roadmaps, and partnerships for AppSec scanning tools with a 'shift left' approach, aiming to improve developer experience and security without compromising speed. Key responsibilities include evaluating AI-application security strategies, secure integration of AI agents, prompt engineering guardrails, and automated remediation pipelines, alongside traditional AppSec tool evaluation and governance.

What you'd actually do

  1. Define the product strategy for AI-application security, including the secure integration of AI agents into the SDLC, prompt engineering guardrails, and automated remediation pipelines.
  2. Own the multi-year product roadmap for Application Security ensuring alignment with enterprise risk appetites and the evolving threat landscape.
  3. Lead the strategic evaluation of Appsec security tools (e.g., SAST/DAST/SCA), ensuring we maximize ROI and maintain a best-in-class toolset.
  4. Act as the primary liaison to Security Engineering Enablement and Architecture to translate security requirements into scalable, fix-first developer workflows.
  5. Establish the governance model for vulnerability disposition (SAST/DAST/OffSec, ensuring clear SLAs, audit trails, and exception workflows that don't hinder velocity.

Skills

Required

  • cybersecurity or information technology
  • translating cybersecurity strategy and analysis into product requirements
  • application security experience
  • DevSecOps
  • AppSec
  • product management
  • strategy
  • roadmap definition
  • vendor evaluation
  • stakeholder management
  • governance models

Nice to have

  • Bachelor's degree in Computer Science
  • Application or Product Security or Software Engineering with an emphasis on AppSec and vulnerability management strategy
  • managing AppSec products in a large-scale enterprise
  • defining standards for AI-augmented development and ethical AI usage
  • Professional certifications (CISSP, CISM, OSCP)
  • cloud-native environments (APIs, Web, Mobile, Containers, IaC, and CI/CD)
  • OWASP Top 10
  • software supply chain security
  • automated DAST
  • manual Penetration Testing
  • adversarial-based threat prevention roadmaps

What the JD emphasized

  • AI-application security
  • AI agents
  • prompt engineering guardrails
  • automated remediation pipelines
  • AI-augmented development
  • ethical AI usage

Other signals

  • AI Transformation: Define the product strategy for AI-application security, including the secure integration of AI agents into the SDLC, prompt engineering guardrails, and automated remediation pipelines.
  • 2+ years of experience defining standards for AI-augmented development and ethical AI usage.