Description
Gett is hiring an Application Security Lead to own product and infrastructure security, with primary responsibility for application security and leading the organization’s transition to a mature DevSecOps model. Reporting to the CISO with a dotted line to the CTO, the role embeds security across the SDLC, leads threat modeling, AppSec automation, mobile and API security, penetration testing, vulnerability and incident management, cloud security posture, secrets and CI/CD security, resilience planning, security governance, compliance, metrics, and a Security Champions program. The position requires 5+ years of application/product security experience, strong developer collaboration, hands-on AppSec tooling, mobile and API security expertise, cloud knowledge, and familiarity with OWASP SAMM, NIST, STRIDE, PCI-DSS, and GDPR.
