Lead Application Security/DevSecOps Engineer
Indexed description
Our product family includes ManageBac (curriculum, assessment & reporting for international schools), OpenApply (admissions management & CRM, used by 600+ leading international and independent schools), SchoolsBuddy (co-curricular & activity management), and Vectare (school transport management).
We are looking for a Lead Security/DevSecOps Engineer on the Product Engineering team, with a great opportunity to be self-directed and level up security practices and capabilities. We expect this to be a hands-on leadership role with a potential opportunity to build/upskill a small team. The person will report to the VP of Engineering and work in partnership with the vCISO, DevOps team, and engineering teams.
Key Responsibilities
- Do an initial deep-dive assessment and evaluation to drive risk-based prioritisation of the following responsibilities
- Stand up and own the application security program across all five products — this is effectively greenfield.
- Define and embed a secure SDLC (shift-left): security requirements, design reviews, guardrails, and coding standards for an AI engineering reality.
- Select, deploy, and operationalise AppSec tooling (SAST, DAST, SCA/dependency and secrets scanning) integrated into CI/CD.
- Implement and operationalise secrets management: detection, rotation, and vault integration across CI/CD pipelines.
- Build risk-based vulnerability management: triage, prioritise, and drive remediation across teams and stacks. Lead remediation of some vulnerabilities as necessary in support of the software engineering team
- Run threat modeling and security reviews for new architecture and significant features.
- Improve cloud security posture across AWS (primary) and Azure, partnering with platform/infra.
- Lead technical incident response for application-layer incidents; coordinate with SOC and vCISO on cross-domain incidents.
- Build security awareness and a security-champions network to upskill engineers.
- Uphold student-data privacy and regulatory obligations.
- Contribute technical evidence and metrics to support the security roadmap and future hiring decisions
- 7+ years in application/product security, ideally including standing up or substantially maturing an AppSec program (ideally near-zero to functioning).
- Strong AI knowledge and curiosity in the space, with the aim of proactive protection, as well as approaching problem-solving AI-first
- Comfortable as a founding, hands-on, solo function — self-directed and pragmatic under ambiguity
- Breadth across stacks: able to work across Ruby on Rails, PHP/Laravel, .NET/C#, and Python (deep in one or two, competent across the rest).
- Strong cloud security across AWS (primary) and Azure.
- Deep grasp of common vulnerability classes and secure coding practices.
- Hands-on with AppSec tooling and DevSecOps / CI/CD integration.
- Threat-modeling experience.
- Excellent communication and influencing skills — able to drive change in an engineering org, new to formal security.
- GitHub Advanced Security experience is a strong nice-to-have.
- The candidate has worked with student data or PII-heavy regulated environments (FERPA, COPPA, GDPR for UK/EU students).
- Proven experience managing large vulnerability backlogs: ability to classify, deduplicate, and drive burn-down across hundreds of repositories.
Please note: Only shortlisted candidates will be contacted due to a high volume of applicants.
What We Offer
- Compensation - Competitive compensation and opportunities for career development
- Learning - We encourage continued education, providing an online learning platform, unlimited book purchases, and diverse internal and external training programs.
- Team - Friendly atmosphere, group activities, and corporate events
- Equipment - MacBook Pro or another laptop of your specification, peripherals, and displays included
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search