Jobedly Post a Job

Lead Application Security/DevSecOps Engineer

Faria Education Group · Remote
RemoteFull-timeEducationLead$179,000–$241,000/yr
Apply on Jobedly ⚡ One-click AI Apply

About the Lead Application Security Devsecop Engineer role

Lead Application Security Devsecop Engineer positions focus on delivering results in their domain. This page aggregates open Lead Application Security Devsecop Engineer roles and what employers typically expect.

Faria is a leader in international education systems & services, offering an integrated suite across learning, admissions, school-to-home, and online courses — trusted by 10,000+ schools and 4 million students across 155 countries. Our product family includes ManageBac (curriculum, assessment & reporting for international schools), OpenApply (admissions management & CRM, used by 600+ leading international and independent schools), SchoolsBuddy (co-curricular & activity management), and Vectare (school transport management). We are looking for a Lead Security/DevSecOps Engineer on the Product Engineering team, with a great opportunity to be self-directed and level up security practices and capabilities. We expect this to be a hands-on leadership role with a potential opportunity to build/upskill a small team. The person will report to the VP of Engineering and work in partnership with the vCISO, DevOps team, and engineering teams. Key Responsibilities - Do an initial deep-dive assessment and evaluation to drive risk-based prioritisation of the following responsibilities - Stand up and own the application security program across all five products — this is effectively greenfield. - Define and embed a secure SDLC (shift-left): security requirements, design reviews, guardrails, and coding standards for an AI engineering reality. - Select, deploy, and operationalise AppSec tooling (SAST, DAST, SCA/dependency and secrets scanning) integrated into CI/CD. - Implement and operationalise secrets management: detection, rotation, and vault integration across CI/CD pipelines. - Build risk-based vulnerability management: triage, prioritise, and drive remediation across teams and stacks. Lead remediation of some vulnerabilities as necessary in support of the software engineering team - Run threat modeling and security reviews for new architecture and significant features. - Improve cloud security posture across AWS (primary) and Azure, partnering with platform/infra. - Lead technical incident response for application-layer incidents; coordinate with SOC and vCISO on cross-domain incidents. - Build security awareness and a security-champions network to upskill engineers. - Uphold student-data privacy and regulatory obligations. - Contribute technical evidence and metrics to support the security roadmap and future hiring decisions Requirements (must have) - 7+ years in application/product security, ideally including standing up or substantially maturing an AppSec program (ideally near-zero to functioning). - Strong AI knowledge and curiosity in the space, with the aim of proactive protection, as well as approaching problem-solving AI-first - Comfortable as a founding, hands-on, solo function — self-directed and pragmatic under ambiguity - Breadth across stacks: able to work across Ruby on Rails, PHP/Laravel, .NET/C#, and Python (deep in one or two, competent across the rest). - Strong cloud security across AWS (primary) and Azure. - Deep grasp of common vulnerability classes and secure coding practices. - Hands-on with AppSec tooling and DevSecOps / CI/CD integration. - Threat-modeling experience. - Excellent communication and influencing skills — able to drive change in an engineering org, new to formal security. Nice to have - GitHub Advanced Security experience is a strong nice-to-have. - The candidate has worked with student data or PII-heavy regulated environments (FERPA, COPPA, GDPR for UK/EU students). - Proven experience managing large vulnerability backlogs: ability to classify, deduplicate, and drive burn-down across hundreds of repositories. All qualified applicants will be considered for employment without regard to age, race, creed, color, national origin, ancestry, marital status, affectional or sexual orientation, gender identity or expression, disability, nationality, or sex. Faria operates a safer recruitment policy, and the successful applicant may be required to complete an enhanced DBS disclosure and an Enhanced Check for…

Salary estimate

$179,000 – $241,000/yr
Provided by the employer.

Skills for this role

PythonC#.NETRUBYRailsPHPLaravelRESTAWSAzureCi/CdCommunicationLeadershipDevopsSecurity

Resume tips for Lead Application Security Devsecop Engineer applicants

Interview preparation

Prepare concrete STAR-format stories that show Lead Application Security Devsecop Engineer outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical Lead Application Security Devsecop Engineer problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About Faria Education Group

Faria Education Group is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles