Application Security Lead
Team: Information Security
Location: Georgia
Employment type: FullTime
THE ROLE
You'll own application security across our mobile banking platform, payments stack, and a growing set of regulated products. The work is hands-on, you’ll conduct a threat modeling, security reviews, CI/CD tooling - with real process ownership. You'll report to the Group CISO and work closely with both our engineering teams and the Bank IS function.
RESPONSIBILITIES
Risk-driven security ownership
- Identify which systems, data flows, and product changes carry the highest real-world risk and build your work around that, not around tool coverage or compliance checklists
- Decide when a security gate is worth slowing down a release and when it isn't, own that call, and be able to explain it to engineering and the CISO
- Maintain a risk register for application-layer exposures: what's open, what's accepted, what's being fixed, and why in that order
Secure SDLC
- Figure out where in our delivery process security decisions are actually being made and put controls there
- Run threat modeling for high-stakes product changes before design is locked, not after
- Build a mobile security testing baseline that the team runs themselves
CI/CD and supply chain
- Assess what the current pipeline actually catches versus what it produces as noise, and fix the ratio before adding more scanners
- Own supply chain posture: dependency pinning, SBOM, internal registry, and the response process when a package gets compromised
- Own secrets detection and remediation end-to-end
Regulatory and cross-team work
- Translate application security gaps into language that satisfies BSP examiners without over-engineering the evidence