Director, Application Security

Posted 7hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Zillow security director leading Application Security and Security Architecture for a major U.S. real estate platform. Driving secure software, cloud security, and executive risk strategy.

Responsibilities:

  • Lead and develop a multi-manager organization across Application Security and Security Architecture
  • Establish and execute a 2–3-year strategic roadmap aligned with product and platform engineering priorities
  • Own workforce planning, organizational design, talent acquisition, and development of future security leaders
  • Manage budget, tooling portfolio, and vendor relationships
  • Represent Application Security at executive and leadership levels and translate technical risk into business impact
  • Lead an AppSec organization partnering with product engineering
  • Build security capabilities into CI/CD pipelines, frameworks, and developer tooling
  • Create security enablement programs, secure coding training, and internal tooling
  • Ensure application portfolio coverage including secure design review, DAST/SAST integration, dependency management, and API security
  • Own product security strategy and embed security in product design
  • Build and maintain a vulnerability management program with SLAs, risk-based prioritization, and executive reporting
  • Establish enterprise security patterns, reference architectures, and guardrails for cloud-native AWS-centric infrastructure
  • Drive Zero Trust principles and identity-driven access
  • Embed security patterns into infrastructure-as-code and platform primitives
  • Partner in platform and product design reviews
  • Evaluate emerging threats and technology shifts and evolve controls

Requirements:

  • 12+ years of progressive security experience
  • At least 5 years in leadership roles managing managers and multifunctional security teams
  • Experience in a high-growth consumer technology or fintech company strongly preferred
  • Background in security engineering, software development, or platform engineering
  • Experience owning multiple security domains simultaneously
  • Track record building Application Security programs integrated into SDLC, CI/CD, and developer workflows
  • Deep expertise in multi-cloud security, preferably AWS
  • Experience with IaC security using Terraform or CloudFormation
  • Kubernetes and container security knowledge
  • Zero Trust architecture experience
  • Detection engineering experience, including custom detection pipelines, SOAR automation, and threat-model-driven coverage
  • Ability to quantify and communicate security risk in business and financial terms
  • Experience presenting to executive leadership and ideally board-level audiences
  • Experience hiring and developing elite security engineers
  • Familiarity with SIEM, SOAR, DLP, EDR, EPM, CSPM/CWPP, SAST/DAST, IaC, and container security tooling
  • Proficiency in at least one scripting or programming language such as Python or Go

Benefits:

  • Equity awards based on experience, performance, and location
  • Remote work from a physical location of the employee’s choice
  • Flexible work from wherever employees are most productive through Cloud HQ
  • Equal employment opportunity and accommodation support