Lead, Application Security

Prudential Financial

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Newark, NJ
Salary
$123,700–$204,100 / yr
Posted
11 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $180k
This role $164k
$112k most similar roles pay here $234k

This role pays less than 60% of similar roles. Most pay $151,643–$208,800 — the shaded band above. At the midpoint, this role pays about $164k versus about $180k for comparable roles.

Based on 240 similar postings.

Employer

About Prudential Financial

Prudential Financial is a global financial services leader and premier active global investment manager.

Prudential Financial currently has 32 open roles on FindRole.

Listed pay typically runs $123,700–$202,050 across 32 roles with salary data.

Most-posted roles

View all roles at Prudential Financial

At a glance

TL;DR · Lead, Application Security

Lead, Application Security joins the Attack Surface Management team to provide technical leadership in advancing the enterprise application security program. This role involves governing and maturing capabilities for cloud-native and DevOps-driven environments while ensuring secure-by-design outcomes across the digital ecosystem. Key responsibilities include integrating security controls into CI/CD pipelines through automation, managing vulnerability and configuration monitoring for first-party and third-party software, and developing policy-as-code solutions. The candidate will utilize expertise in SAST, SCA, DAST, and ASPM tools to manage risk across various platforms. Required skills include familiarity with OWASP Top 10, MITRE ATT&CK, and vulnerability frameworks like CVE and CVSS. Technical proficiency in Python, PowerShell, or Bash is preferred to support automation efforts while ensuring compliance with NIST, PCI DSS, and SOX standards within a complex financial services environment.

What you'll do

  • Serve as the technical lead and escalation point for complex application security and attack surface management issues.
  • Integrate automated security controls into CI/CD pipelines to enable self-service enforcement and monitoring.
  • Manage vulnerability and configuration monitoring across first-party, third-party, and open-source software components.
  • Design and evolve security policies, standards, and alerting mechanisms aligned with regulatory frameworks like NIST and PCI DSS.
  • Evaluate and vet new security technologies while providing technical due diligence and strategic recommendations.
  • Develop proof-of-concept exploits in lab environments to validate remediation effectiveness and demonstrate risk.
  • Provide mentorship and technical guidance to junior team members to improve overall team capability.
  • Define requirements for workflow orchestration and automation to manage application security at enterprise scale.

What we're looking for

  • Bachelor of Computer Science/Engineering or formal experience in related fields.
  • Proven experience leading and maturing application security and vulnerability management programs.
  • Deep experience with SAST, SCA, DAST, and ASPM tooling.
  • Familiarity with vulnerability and security frameworks including CVE, CVSS, EPSS, CWE, OWASP Top 10, and MITRE ATT&CK.
  • Experience working in agile and DevSecOps environments to integrate security into CI/CD pipelines.
  • Strong understanding of software composition analysis (SCA), SBOMs, and supply chain risk.
  • Proficiency with scripting and automation tools such as Python, PowerShell, or Bash.
  • Knowledge of security standards and frameworks including NIST, CIS, and PCI DSS.

More like this

Similar roles

Head of Application Security

Analog Devices

Wilmington, MA 18 days ago $219,200$301,400
DevSecOps SAST SCA DAST CI/CD SBOM LLM NIST AI RMF ISO/IEC 42001 OWASP LLM Top 10 MITRE ATLAS PSIRT CVE CVSS IEC 62443 ISO/SAE 21434 ISO 26262 IEC 62304 CMMC ITAR EAR
10+ yrs exp

Lead Information Security GRC Automation

Prudential Financial

Newark, NJ 24 days ago $114,500$188,900
GRC CI/CD Azure DevOps ServiceNow API GitHub Jenkins Jira Power Automate Control-as-Code Policy-as-Code Cybersecurity Information Security Software Development Scripting
Hybrid

Distinguished Engineer, Application Security

CVS Health

Remote (AZ) 9 days ago $175,100$334,750
SAST DAST SCA IAST RASP ASPM CI/CD Kubernetes Python Go Java TypeScript JavaScript C# REST GraphQL gRPC eBPF OWASP ASVS NIST SSDF SBOM SLSA GitHub Actions GitLab CI Jenkins Argo
10+ yrs exp Remote

Lead InfoSec Engineer, DevSecOps

S&P Global

New York, NY +1 53 days ago $100,000$130,000
DevSecOps CI/CD SAST DAST SCA AWS Azure Cloud Platform Kubernetes Docker OpenShift Terraform CloudFormation Pulumi Python Go Git HashiCorp Vault CSPM CNAPP
8+ yrs exp

Senior Application Security Engineer

AbbVie

Irvine, CA 42 days ago $109,500$208,500
SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python AWS Azure Terraform CloudFormation CSPM Snyk Endor Labs OWASP Top 10 CWE
7+ yrs exp

Senior Application Security Engineer

AbbVie

Chicago, IL 42 days ago $109,500$208,500
SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python AWS Azure Terraform CloudFormation OWASP Top 10 CWE CSPM Snyk Endor Labs
7+ yrs exp