J
Posted 1mo agoBangkok, Bangkok, Thailand

Department Manager - Application Security

MiddleOn-site (Bangkok)Salary undisclosed
Required Skills
TypeScriptJavaScriptPythonJavaAzureCI/CDLLMs
Job Description

You will lead CP Axtra's Application Security program end-to-end — from defining secure SDLC policies to managing the toolchain that enforces them. You'll own the SAST, SCA, DAST, and secrets scanning platforms (Checkmarx, SonarQube, Qualys WAS, Spectral, OWASP ZAP) and ensure they're integrated into every CI/CD pipeline, producing actionable results rather than alert fatigue.

This is a leadership role with deep technical expectations. You'll manage the SAST/SCA/DAST/IaC Security Manager, consult directly with development teams on secure design and remediation, and represent application security in architecture reviews. You'll need to balance enforcement with enablement — developers should see your team as a resource that helps them ship securely, not a gate that slows them down.

The right person combines strong application security expertise with the communication skills to influence development culture across a large, diverse engineering organization.

KEY RESPONSIBILITIES

·       Own and evolve CP Axtra's Secure SDLC framework — defining security requirements, review gates, and testing standards for all software development projects

·       Manage and optimize the AppSec toolchain (Checkmarx, SonarQube, Qualys WAS, Spectral, OWASP ZAP), ensuring high detection rates with low false positive noise

·       Driv

Similar Openings in DevOps & Cloud

View all in category