About this role
About the Role As the Lead, Application Security on Prudential’s Attack Surface Management team, you will provide technical and strategic leadership to mature the enterprise application security program. You will partner with senior security leaders, the Information Security Office, the Chief Technology Office, and global engineering teams to drive secure-by-design outcomes and measurable risk reduction across Prudential’s digital ecosystem. You’ll shape security capabilities for modern, cloud-native and DevOps-driven environments, and embed security controls into CI/CD pipelines through automation and self-service enablement.
What You'll Do
- Serve as the technical lead and escalation point for complex operational and project work across the Application Security and Attack Surface Management domains.
- Provide expert-level leadership for application security tools, platforms, and assessment methodologies.
- Lead the design, evolution, and execution of application security assessment, response, and risk governance processes.
- Bridge between AppSec, DevOps, Cloud, and business teams, ensuring security requirements are understood, actionable, and aligned to delivery objectives.
- Partner with senior leadership to define the future-state vision for Prudential’s application security program, informed by hands-on operational insight.
- Lead the maturation of vulnerability and configuration monitoring across first-party, third-party, and open-source software.
- Drive the integration of security controls into CI/CD pipelines, enabling automated enforcement, monitoring, and reporting.
- Design and evolve security policies, standards, and alerting mechanisms aligned to SOX, NIST, PCI DSS, and other regulatory frameworks.
- Evaluate and vet new security technologies, providing strategic recommendations and technical due diligence.
- Apply qualitative and quantitative analysis to improve developer experience, security outcomes, and adoption of secure-by-design practices.
- Champion secure-by-design principles across the SDLC through guidance, standards, tooling, and hands-on engagement.
- Validate and document compensating controls and mitigations to manage risk until remediation is complete.
- Ensure risk and performance metrics accurately represent application security posture for executive and regulatory audiences.
- Author and maintain technical documentation, standards, and SOPs that continuously improve program maturity.
- Develop proof-of-concept exploits in lab environments to demonstrate exploitability and validate remediation effectiveness.
- Provide mentorship and technical guidance to junior team members, raising overall team capability and consistency.
- Define requirements for workflow orchestration and automation to manage application security posture at enterprise scale.
What We're Looking For
- Bachelor’s degree in Computer Science/Engineering or related field.
- Deep familiarity with vulnerability/security frameworks and data sources (CVE, CVSS, EPSS, CWE).
- Proven experience leading and maturing application security and vulnerability management programs.
- Strong ability to partner with engineering teams to validate findings, reduce false positives, and drive remediation.
- Engineering mindset with systems thinking and problem-solving skills.
- Excellent written and verbal communication, with the ability to articulate technical and business risk to varied audiences.
- Experience working in agile and DevSecOps environments.
- Hands-on experience with OWASP Top 10, OWASP WSTG, PTES, MITRE ATT&CK.
- Deep experience with SAST, SCA, DAST, and ASPM tooling.
- Strong understanding of SBOMs, software composition analysis (SCA), and supply chain risk.
- Preferred qualifications: scripting and automation experience (Python, PowerShell, Bash).
- Experience performing exploit validation and web application penetration testing.
- Strong understanding of threat actors and real-world attack techniques.
- Knowledge of security standards and frameworks (NIST, CIS, PCI DSS).
- Experience applying AI-assisted approaches to security use cases.
- Advanced security certifications (OSCP, GPEN, GWAPT, CASP+, GCSA, GCFA, GCIH).
- Cloud certifications (AWS, Azure, GCP).
- Demonstrated ability to influence without authority and lead through expertise.
Nice to Have
- Scripting and automation experience (Python, PowerShell, Bash).
- Experience applying AI-assisted approaches to security use cases.
- Cloud certifications (AWS, Azure, GCP).
- Demonstrated ability to influence without authority and lead through expertise.