Tech Stack
SDLC
Job Description, Responsibilities & Requirements
About the Position
We are seeking a Head of Application Security Team with 8+ years of experience in Product Security to lead our security initiatives remotely.
Responsibilities
- Build and own the end-to-end Product Security lifecycle across all company products.
- Define, implement, and enforce Secure SDLC, embedding security from design through production.
- Lead and manage Product Security teams including Pentesting, Application Security, Application Security Architecture, DevSecOps, and Cloud Security Operations.
- Drive security architecture reviews and threat modeling for new and existing products.
- Own product vulnerability management, including discovery, triage, prioritization, remediation tracking, and verification.
- Define and oversee pentesting and offensive security strategy, scope, cadence, and remediation follow-up.
- Ensure secure usage of cloud-native services, APIs, and third-party dependencies within products.
- Partner with Engineering, Product, and Infrastructure leadership to align security with business objectives.
- Lead product-related security incidents, including root cause analysis and long-term corrective actions.
- Define and report Product Security KPIs and metrics to executive stakeholders.
Requirements
- 8+ years of experience in Product Security, Application Security, or DevSecOps.
- Proven experience building or scaling a Product Security function in a product-based organization.
- Strong expertise in Secure SDLC and security integration into modern development workflows.
- Hands-on experience with application security testing, threat modeling, and secure architecture reviews.
- Strong understanding of cloud-native architectures and product-related cloud security risks.
- Experience managing multi-disciplinary security teams across AppSec, Pentest, DevSecOps, and Cloud Security.
- Experience owning vulnerability lifecycle management with risk-based prioritization.
- Ability to translate technical security risks into business impact and decisions.
- Strong written and verbal communication skills in English.
Nice to Have
- Experience in iGaming, FinTech, SaaS, or other regulated industries.
- Hands-on experience with Kubernetes and containerized environments.
- Exposure to red teaming or adversary simulation.
- Familiarity with security-related compliance frameworks (e.g. ISO 27001, PCI DSS, SOC 2).
We Offer
- An exciting and challenging job in a fast-growing business group.
- The opportunity to be part of a multicultural team of top professionals in Development, Architecture, Management, Operations, Marketing, Legal, Finance, and more.
- Great working atmosphere with passionate experts and leaders, sharing a friendly culture and a success-driven mindset.
- Beautiful offices in Warsaw, Limassol, Yerevan; work remotely or on-site with comfort and enjoy the opportunity to build a network of connections with professionals day by day.
- Modern corporate equipment based on macOS or Windows and additional equipment are provided.
- Paid vacations, sick leave, personal events days, days off.
- Corporate health insurance program for your well-being.
- Referral program: enjoy cooperation with your colleagues and get the bonus.
- Educational programs: regular internal training sessions, compensation for external education, attendance of specialized global conferences.
- Rewards program for mentoring and coaching colleagues.
- Free internal English courses.
- In-house Travel Service.
- Multiple internal activities: online platform for employees with quests, gamification, presents, and news, RedCore clubs for movie/book/pets lovers, special office days dedicated to holidays.
- Company events, team buildings.
About the Company
[Company description if present]
---
**Note:** This description has been formatted to enhance readability and organization while preserving the original content and context.