Skip to content

Open nowPosted 65 days ago

Department Manager - Application Security

Workable (global search)108,016 open roles

Where
Bangkok, Thailand
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowDepartment Manager - Application SecurityWorkable (global search) · Bangkok, Thailand
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 65 days ago

Workable (global search) median: 7 days open

The posting

You will lead CP Axtra's Application Security program end-to-end — from defining secure SDLC policies to managing the toolchain that enforces them. You'll own the SAST, SCA, DAST, and secrets scanning platforms (Checkmarx, SonarQube, Qualys WAS, Spectral, OWASP ZAP) and ensure they're integrated into every CI/CD pipeline, producing actionable results rather than alert fatigue.

This is a leadership role with deep technical expectations. You'll manage the SAST/SCA/DAST/IaC Security Manager, consult directly with development teams on secure design and remediation, and represent application security in architecture reviews. You'll need to balance enforcement with enablement — developers should see your team as a resource that helps them ship securely, not a gate that slows them down.

The right person combines strong application security expertise with the communication skills to influence development culture across a large, diverse engineering organization.

KEY RESPONSIBILITIES

· Own and evolve CP Axtra's Secure SDLC framework — defining security requirements, review gates, and testing standards for all software development projects

· Manage and optimize the AppSec toolchain (Checkmarx, SonarQube, Qualys WAS, Spectral, OWASP ZAP), ensuring high detection rates with low false positive noise

· Drive CI/CD pipeline security integration across GitHub Actions, Azure DevOps, and Jenkins — making security checks automated, fast, and non-bypassable

· Lead threat modeling and secure design reviews for high-risk applications, including e-commerce platforms, payment integrations, and customer data systems

· Consult with development teams on vulnerability remediation — not just telling them what's broken, but helping them understand the fix and the 'why' behind it

· Define and enforce security quality gates: what blocks a release, what generates a warning, and what gets tracked for future remediation

· Manage the SAST/SCA/DAST/IaC Security Manager, providing technical direction and ensuring operational excellence across the scanning platforms

· Report application security posture metrics to the Associate Director and CISO — trends in vulnerability density, remediation velocity, and coverage gaps

· Evaluate emerging AppSec technologies including AI-assisted code review and automated fix suggestion tools

· Coordinate with the Offensive Security team to align penetration testing priorities with application risk profiles

Requirements

TECHNICAL REQUIREMENTS

· Checkmarx (SAST/SCA), SonarQube, Qualys WAS, Spectral, OWASP ZAP

· CI/CD platforms: GitHub Actions, Azure DevOps, Jenkins

· Code review in Java, Python, JavaScript/TypeScript, or similar

· Threat modeling frameworks: STRIDE, PASTA, or equivalent

MUST-HAVE REQUIREMENTS

These are non-negotiable. If you do not meet all of these, this role is not the right fit.

· 5+ years in application security — secure SDLC, code review, vulnerability management, or AppSec tooling management

· Hands-on experience with at least 2 of: SAST, SCA, DAST, or secrets scanning tools (Checkmarx, SonarQube, Snyk, Qualys WAS, or equivalent)

· Strong understanding of CI/CD pipelines and how to integrate security checks without breaking developer velocity (GitHub Actions, Azure DevOps, Jenkins)

· Ability to review code for security issues in at least 2 programming languages (Java, Python, JavaScript/TypeScript, Go, or C#)

· Experience leading or mentoring a team — you'll manage at least one direct report and influence a broader developer community

· Excellent communication skills — you'll spend significant time consulting with developers who may not have security backgrounds

· Understanding of OWASP Top 10, SANS Top 25, and modern application attack patterns

NICE-TO-HAVE

These will set you apart from other candidates:

· Experience with container security scanning (Trivy, Prisma Cloud, Aqua) and IaC security (Checkov, tfsec)

· Background in software development — candidates who've written production code understand developer pain points better

· Familiarity with AI/LLM security risks and secure development practices for AI-integrated applications

· CSSLP, GWEB, or CASE certification

· Experience in retail or e-commerce application security, especially PCI DSS-relevant environments

· Thai language proficiency for developer training and stakeholder communication

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.