Director, Application Security
Posted 7hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Zillow security director leading Application Security and Security Architecture for a major U.S. real estate platform. Driving secure software, cloud security, and executive risk strategy.
Responsibilities:
- Lead and develop a multi-manager organization across Application Security and Security Architecture
- Establish and execute a 2–3-year strategic roadmap aligned with product and platform engineering priorities
- Own workforce planning, organizational design, talent acquisition, and development of future security leaders
- Manage budget, tooling portfolio, and vendor relationships
- Represent Application Security at executive and leadership levels and translate technical risk into business impact
- Lead an AppSec organization partnering with product engineering
- Build security capabilities into CI/CD pipelines, frameworks, and developer tooling
- Create security enablement programs, secure coding training, and internal tooling
- Ensure application portfolio coverage including secure design review, DAST/SAST integration, dependency management, and API security
- Own product security strategy and embed security in product design
- Build and maintain a vulnerability management program with SLAs, risk-based prioritization, and executive reporting
- Establish enterprise security patterns, reference architectures, and guardrails for cloud-native AWS-centric infrastructure
- Drive Zero Trust principles and identity-driven access
- Embed security patterns into infrastructure-as-code and platform primitives
- Partner in platform and product design reviews
- Evaluate emerging threats and technology shifts and evolve controls
Requirements:
- 12+ years of progressive security experience
- At least 5 years in leadership roles managing managers and multifunctional security teams
- Experience in a high-growth consumer technology or fintech company strongly preferred
- Background in security engineering, software development, or platform engineering
- Experience owning multiple security domains simultaneously
- Track record building Application Security programs integrated into SDLC, CI/CD, and developer workflows
- Deep expertise in multi-cloud security, preferably AWS
- Experience with IaC security using Terraform or CloudFormation
- Kubernetes and container security knowledge
- Zero Trust architecture experience
- Detection engineering experience, including custom detection pipelines, SOAR automation, and threat-model-driven coverage
- Ability to quantify and communicate security risk in business and financial terms
- Experience presenting to executive leadership and ideally board-level audiences
- Experience hiring and developing elite security engineers
- Familiarity with SIEM, SOAR, DLP, EDR, EPM, CSPM/CWPP, SAST/DAST, IaC, and container security tooling
- Proficiency in at least one scripting or programming language such as Python or Go
Benefits:
- Equity awards based on experience, performance, and location
- Remote work from a physical location of the employee’s choice
- Flexible work from wherever employees are most productive through Cloud HQ
- Equal employment opportunity and accommodation support



















