Talent.com
Director, Secure SDLC & Application Security
Director, Secure SDLC & Application SecurityIron Mountain • Boston, MA, United States
Director, Secure SDLC & Application Security

Director, Secure SDLC & Application Security

Iron Mountain • Boston, MA, United States
job_description.job_card.1_day_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

At Iron Mountain we know that work, when done well, makes a positive impact for our customers, our employees, and our planet. That’s why we need smart, committed people to join us. Whether you’re looking to start your career or make a change, talk to us and see how you can elevate the power of your work at Iron Mountain.

Job Summary

We are looking for a highly influential and experienced Director, Secure SDLC & Application Security to mature and establish control gates across our secure software development environments and practices. This strategic role is responsible for embedding security into every stage of our Software Development Lifecycle (SDLC, SP 800-64), guided by the principles of the NIST Secure Software Development Framework (SSDF, SP 800-218). This position bridges our development, IT, and cybersecurity organizations and reports directly to the CTO with a dotted line to the CISO.

Key Responsibilities

Strategic Ownership & Influence : Own the strategy for embedding security within the development lifecycle and act as the primary security partner for development leaders.

Secure SDLC Partnership & Compliance : Drive and manage key functions like threat modeling, automated testing, secure design reviews, and secure deployment practices in partnership with the CISO organization.

FedRAMP Application Compliance & Enablement : Ensure all applications meet FedRAMP technical controls and that all required documentation and evidence are properly created, maintained, and delivered for audits and Authorization to Operate (ATO) packages.

Policy and Process Development : Establish, maintain, and enforce secure coding standards, vulnerability management procedures, and policies for the use of third‑party and open‑source software.

Business Unit Security Leadership : Provide direct leadership for information security compliance across the Digital Business Unit’s development and product functions.

Cross‑Functional Partnership : Serve as the key liaison between the CTO’s engineering teams, the CISO’s security organization, and the broader IT organization.

Tooling and Automation Integration : Drive the strategy for security tooling within the CI / CD pipeline, including compliance with SAST, DAST, and SCA.

Metrics and Dual Reporting : Develop KPIs to measure the effectiveness of the application security program and provide clear, concise reports and updates on our software security posture.

Qualifications and Skills

Experience :

10+ years of experience in software development or information security, with at least 5 years in a leadership, principal, or senior role focused on application / product security.

Demonstrable experience implementing and managing a secure SDLC based on a recognized framework like NIST SSDF (800-218).

Direct, hands‑on experience developing and securing applications within FedRAMP High and / or Moderate compliant cloud environments.

Proven success in a matrixed environment, influencing change and driving initiatives across multiple teams and departments without direct authority.

Work Authorization :

  • Applicants must be legally authorized to work in the United States without the need for current or future visa sponsorship.

Technical Skills :

Expertise in threat modeling (e.g., STRIDE), secure coding practices, and modern application security vulnerabilities (OWASP Top 10).

Hands‑on experience with security testing tools (SAST, DAST, SCA and penetration tests) and their integration into developer workflows (GitLAB and Veracode).

Proven capability to utilize Tenable for enterprise‑wide vulnerability detection and compliance, driving remediation within SLA across diverse DevOps environments.

Strong understanding of DevOps / DevSecOps principles and CI / CD pipelines.

Experience building developer enablement programs covering secure coding, threat modeling, SBOM generation, and vulnerability management requirements.

Define secure baselines for third‑party components, open‑source dependencies and container registries.

Familiarity with cloud‑native security (AWS GovCloud, GCP, Azure Government).

Influence and Communication :

Exceptional stakeholder management skills, with the ability to build consensus between engineering, security, and business leaders.

Excellent ability to articulate complex security risks and concepts to varied audiences, from engineers to senior executives.

Education and Certifications :

Bachelor’s degree in Computer Science, Information Security, or a related field; Master’s degree preferred.

Relevant industry certifications (e.g., CISSP, CSSLP, GCSA) are highly desirable.

#LI-Remote

Reasonably expected salary range : $159,400.00 - $212,500.00

Category : Information Technology

Iron Mountain is a global leader in storage and information management services trusted by more than 225,000 organizations in 60 countries. We safeguard billions of our customers’ assets, including critical business information, highly sensitive data, and invaluable cultural and historic artifacts.

If you have a physical or mental disability that requires special accommodations, please let us know by sending an email to accommodationrequest@ironmountain.com. See the Supplement to learn more about Equal Employment Opportunity.

Iron Mountain is committed to a policy of equal employment opportunity. We recruit and hire applicants without regard to race, color, religion, sex (including pregnancy), national origin, disability, age, sexual orientation, veteran status, genetic information, gender identity, gender expression, or any other factor prohibited by law.

#J-18808-Ljbffr

serp_jobs.job_alerts.create_a_job

Application Security • Boston, MA, United States

Job_description.internal_linking.related_jobs
Sr. Staff Analyst, Information Security

Sr. Staff Analyst, Information Security

1010 Analog Devices Inc. • Wilmington, MA, United States
serp_jobs.job_card.full_time +1
NASDAQ : ADI ) is a global semiconductor leader that bridges the physical and digital worlds to enable breakthroughs at the Intelligent Edge. ADI combines analog, digital, and software technologie...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
Director, Infrastructure & Security Operations

Director, Infrastructure & Security Operations

Brooks Automation • Chelmsford, MA, US
serp_jobs.job_card.full_time
Director, Infrastructure & Security Operations.Brooks is seeking a dynamic and hands-on Director of Infrastructure & Security Operations to lead and mature our global IT infrastructure and SecOps c...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
Workday Application Security & Controls Director

Workday Application Security & Controls Director

PRICE WATERHOUSE COOPERS • Boston, MA, United States
serp_jobs.job_card.full_time
A career in Enterprise Application Risk will allow you to develop and apply strategies that help clients leverage enterprise technologies to get a higher return on their investment, mitigate risks,...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Director, Cloud Security Specialist

Director, Cloud Security Specialist

Fidelity Investments • Boston, MA, United States
serp_jobs.job_card.full_time
The Cloud Security Center of Excellence within Fidelity Enterprise Cyber Security (ECS) is seeking a cloud or data platforms focused security engineer who has broad security domain knowledge includ...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Associate Director, Software Security Architecture and Enablement

Associate Director, Software Security Architecture and Enablement

KPMG US • Boston, MA, United States
serp_jobs.job_card.full_time
Associate Director, Software Security Architecture and Enablement.Associate Director, Software Security Architecture and Enablement. KPMG is currently seeking an Associate Director, Software Securit...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Senior Program Manager, Secret

Senior Program Manager, Secret

DCS Corporation • Bedford, MA, US
serp_jobs.job_card.full_time
DCS has an exciting opportunity for a Senior Program Manager providing support to the Air Force Life Cycle Management Center (AFLCMC / HBD), Theater Battle Control Division.The Theater Battle Control...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
Senior Manager, Solutions Architecture, Data Security Pre-sales- Capital One Software (Remote)

Senior Manager, Solutions Architecture, Data Security Pre-sales- Capital One Software (Remote)

Capital One • BOSTON, Massachusetts, United States
serp_jobs.filters.remote
serp_jobs.job_card.full_time +1
Senior Manager, Solutions Architecture, Data Security Pre-sales- Capital One Software (Remote).Ever since our first credit card customer in 1994, Capital One has recognized that technology and data...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Senior Program Manager, Secret

Senior Program Manager, Secret

Clearance Jobs • Bedford, MA, US
serp_jobs.job_card.full_time
DCS has an exciting opportunity for a Senior Program Manager providing support to the Air Force Life Cycle Management Center (AFLCMC / HBD), Theater Battle Control Division.The Theater Battle Control...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
SOC Manager (Hybrid)

SOC Manager (Hybrid)

WaveStrong, Inc. • Boston, MA, United States
serp_jobs.job_card.full_time
Exciting SOC Manager, 6 plus months (Hybrid), contract opportunity in Boston, MA.Manager / Team Lead to manage a 24 / 7 team of security professionals to detect, monitor, respond, and remediate threats...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
Senior Director, Cyber Security (Hybrid - San Diego, CA or Acton, MA)

Senior Director, Cyber Security (Hybrid - San Diego, CA or Acton, MA)

Insulet Corporation • , MA, United States
serp_jobs.job_card.full_time
Senior Director, Cyber Security (Hybrid - San Diego, CA or Acton, MA) page is loaded## Senior Director, Cyber Security (Hybrid - San Diego, CA or Acton, MA)locations : San Diego, California : Act...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Global Channel MSSP Program Director

Global Channel MSSP Program Director

Right Seat • Boston, MA, United States
serp_jobs.job_card.full_time
Global Channel MSSP Program Director.Our Client is seeking a Channel MSSP Program Director to lead and expand strategic partnerships with top global Managed Security Services Providers (MSSPs), inc...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
Safety and Security Director

Safety and Security Director

Boston Health Care for the Homeless Program • Boston, MA, US
serp_jobs.job_card.full_time +1
We are seeking a Safety and Security Director to join our team at Boston Health Care for the Homeless Program.As a Safety and Security Director, you will be responsible for the overall safety and s...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Executive Director, Security & Information Protection

Executive Director, Security & Information Protection

Odyssey Systems • Wakefield, MA, US
serp_jobs.job_card.full_time
Executive Director Of Security & Information Protection.Odyssey is seeking an Executive Director of Security & Information Protection to lead the recently formed Security & Information Protection g...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
Senior Director, Enterprise Applications

Senior Director, Enterprise Applications

Vertex Pharmaceuticals • Boston, MA, United States
serp_jobs.job_card.full_time
KEY RESPONSIBILITIES : • • Work closely with Information Security, Internal Audit and Quality Assurance groups as needed to ensure compliance with Sarbanes-Oxley (SOX) and GxP regulations, as well as ...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Global Channel MSSP Program Director

Global Channel MSSP Program Director

ZipRecruiter • Boston, MA, United States
serp_jobs.job_card.full_time
Global Channel MSSP Program Director.Role Summary : Our Client is seeking a Channel MSSP Program Director to lead and expand strategic partnerships with top global Managed Security Services Provider...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Managing Director, Cryptography

Managing Director, Cryptography

State Street • Quincy, Massachusetts, United States
serp_jobs.job_card.full_time
This job is with State Street, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.Who we are ...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Senior Program Director Technology Modernisation

Senior Program Director Technology Modernisation

State Street • Quincy, MA, US
serp_jobs.job_card.full_time
Senior Vice President, Technology Modernization & Governance.We are seeking a strategic, execution-oriented technology leader to drive the governance and delivery of a multi-year, enterprise-wide m...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
Safety Director, Advanced Technology

Safety Director, Advanced Technology

Suffolk Construction • Boston, MA, US
serp_jobs.job_card.full_time
Suffolk is seeking people who are bold.Create, communicate, enforce, and identify opportunities for improvements in corporate safety programs. Mentor and supervise Safety Managers as required by Reg...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted