SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 228,000 - 333,150 / annual
Moody's is seeking a Senior Vice President of Application Security to lead enterprise-wide application security strategy and posture management. This is a strategic leadership role reporting to senior cybersecurity leadership, responsible for defining and executing the application security roadmap, building and developing a global team of application security and DevSecOps professionals, and embedding security throughout the software development lifecycle.
Key responsibilities include: leading enterprise application security strategy aligned with business objectives; building and mentoring a global organization of Application Security, Product Security, and DevSecOps professionals; establishing secure-by-design and secure-by-default practices across engineering teams; driving adoption of threat modeling, secure coding standards, secure design reviews, and automated security testing; overseeing Vulnerability Management, Detection and Response (VMDR) programs with risk-based prioritization and remediation governance; guiding Cloud Security Posture Management (CSPM) and SaaS Security Posture Management (SSPM) capabilities; consolidating application, cloud, and SaaS security findings into unified enterprise risk views; and partnering with Engineering, Product, Infrastructure, Risk, Legal, Privacy, Compliance, and executive stakeholders.
Required qualifications: 15+ years of progressive cybersecurity experience with significant leadership in Application Security or Product Security; deep expertise in secure software development lifecycle, threat modeling, secure architecture, OWASP Top 10, and modern application security programs; strong software engineering background with ability to review production code and influence engineering organizations; proven experience implementing and scaling DevSecOps practices including SAST, DAST, IAST, SCA, and CI/CD security integration; knowledge of cloud-native environments, microservices, containers, Kubernetes, APIs, and SaaS platforms; demonstrated success building and leading high-performing global teams; exceptional executive communication and stakeholder management skills; Bachelor's degree in Computer Science, Engineering, Information Security, or related field (or equivalent).
Preferred: Advanced degree (Master's or MBA); relevant certifications (CISSP, CSSLP, CISM, GWAPT, OSCP); experience with VMDR, CSPM, SSPM programs in large regulated organizations; AI-enabled security capabilities experience.