Praxy
← Back to jobs

Sr. Application Security Manager

Doubleverify

Location
NYC Global HQ
Posted
24d ago
Finance RiskFinance Business ControlRisk Security Compliance

About this role

<h3><span style="font-family: helvetica, arial, sans-serif; font-size: 12pt;">Who we are</span></h3> <p><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">DoubleVerify is the leading independent provider of marketing measurement software, data, and analytics that authenticates the quality and effectiveness of digital media for the world's largest brands and media platforms. DV provides media transparency and accountability to deliver the highest level of impression quality for maximum advertising performance. Since 2008, DV has helped hundreds of Fortune 500 companies gain the most from their media spend by delivering best-in-class solutions across the digital ecosystem, helping to build a better industry. Learn more at<u> <a href="https://www.doubleverify.com">www.doubleverify.com</a></u>.<br><br></span></p> <h3><span style="font-size: 12pt;">Role Summary</span></h3> <p><span style="font-size: 10pt;">As Application & AI Security leadership within DV InfoSec, you will own and evolve DoubleVerify's Secure Software Development Lifecycle (SSDLC), application security, API security, and AI/LLM security. You will lead the people, processes, and tooling that keep DV's code, pipelines, cloud workloads, APIs, and AI systems secure, partnering across the engineering organization. <em>(This role replaces and expands the scope of DV's Senior Application Security Manager position to formally include AI security ownership.)<br><br></em></span></p> <h2><span style="font-size: 12pt;">Responsibilities</span></h2> <h3><span style="font-size: 10pt;">Application & Product Security</span></h3> <ul> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Own and evolve DV's application security program, including SAST, SCA, DAST, and Application Security Posture Management (ASPM) tooling (e.g., Ox Security) — advancing findings from non-blocking warnings toward enforced, risk-based merge gates.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Drive the OWASP Application Security Verification Standard (ASVS) adoption program across engineering repositories, including reporting, dashboards, and branch-level coverage.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Drive SBOM management, license compliance, and software supply chain security practices across development teams.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Partner with DevOps and engineering to embed security across the CI/CD pipeline and Secure SDLC (SSDLC).</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Develop and maintain application security metrics and reporting for engineering leadership, including vulnerability burn-down and mean-time-to-remediate (MTTR).</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Lead the bi-weekly vulnerability remediation touchpoints and the monthly Application Security Leadership Forums with engineering organizations (Pinnacle, Measurement, Programmatic, Architecture, Publisher, Social, QA, TechOps/SRE, CorpIT, DevOps, and M&A) to drive progress and accountability.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Oversee DV's API security program (OWASP API Security Top 10, e.g., Escape API Security) and attack surface management (ASM) capabilities, including discovery of shadow/zombie APIs.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Assist with Web Application Firewall (WAF) configuration, deployment, and monitoring.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Partner with DevOps/SRE on cloud and container security (e.g., Wiz) to deliver code-to-cloud coverage.</span></li> </ul> <h3><span style="font-size: 10pt;">AI & Emerging Technology Security</span></h3> <ul> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Lead AI security governance, engineering, and threat assessment functions across DV's AI/ML ecosystem.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Secure AI agents, LLM-based applications, MCP gateway, and agentic SDLC workflows against threats such as prompt injection, jailbreaking, excessive agency, and supply chain compromise — including guardrails, telemetry, logging, and detections for developer AI tooling (Cursor, Claude Code, VS Code).</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Evaluate and operationalize AI security platforms to provide detection, response, and AI supply chain governance across teams building or operating AI systems (e.g., AI security gateway, shadow-AI discovery/DLP, AI identity and software management).</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Build threat models and controls for first- and third-party AI/ML workloads, including data pipelines, model provenance, and RAG architectures.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Advance AI-assisted security testing (e.g., DV's PromptFlow-driven web/API security test generation) to scale coverage across teams.</span></li> </ul> <h3><span style="font-size: 10pt;">Security Engineering, Offensive Security & DevSecOps Enablement</span></h3> <ul> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Lead DV's offensive security and penetration testing program, working with external vendors and conducting internal security assessments.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Build and maintain security automation capabilities to reduce manual effort and increase detection coverage.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Partner with the DevOps and CloudOps organizations on cloud security (primarily GCP/Kubernetes), shared responsibility model execution, and infrastructure-as-code security.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Own and conduct threat modeling for DV products and infrastructure.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Deliver secure coding training and developer enablement programs across global engineering teams.</span></li> </ul> <h3><span style="font-size: 10pt;">Team Leadership & Management</span></h3> <ul> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Recruit, onboard, and manage a team of security engineers and contractors, including software security developers and offensive security testers.</span></li> <li style="font-size: 10pt;"><span style="

If this role is no longer available, it will disappear from Praxy automatically.