
Application Security Tech Lead
Alpharetta, GAJob$60–70/hrSeen 2 days agoSeen in employer's feed 2 days ago
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near Alpharetta, GA, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Job overview
The Application Security Tech Lead defines and delivers application security standards for the BC2 remediation program within Data Engineering. The role translates InfoSec controls into engineering specifications, creates hardened reference implementations, and validates remediation before production. It partners with remediation engineers and teams across security, platform engineering, application development, and operations, while application owners retain sign-off and risk acceptance for their systems.
Skills & qualifications
Skills
Qualifications
Full job description
Job Description
We are seeking a Tech Lead to define and deliver the application security standards used across the BC2 remediation program within Data Engineering. This is a centralized role that translates InfoSec control requirements into executable engineering specifications, establishes hardened reference implementations for each application type in the estate, and validates remediation prior to production implementation.
The role works alongside remediation engineers who execute against those standards, and partners with Information Security, Platform Engineering, application development teams, and operational support. Application owners retain sign-off and risk acceptance for their own systems.
Duties
- Translate InfoSec control requirements into scoped, assignable engineering work with defined acceptance criteria and audit evidence.
- Create and maintain well-defined development tickets with clear requirements and measurable outcomes, enabling effective tracking of developer progress, delivery, and performance.
- Classify the application estate into a small number of types, based on build and runtime characteristics, and maintain that classification as the estate changes.
- Establish, or specify for others to build, the tooling, environments, and pipeline capability required to deliver and validate standards at scale.
- Design, build, and maintain a hardened reference implementation for each type, covering approved base images, required security controls, verification, and evidence generation.
- Define migration paths for end-of-life runtimes and frameworks and identify workloads where retirement or replacement is lower cost than remediation.
- Analyze scan findings and exception requests to determine exploitability, identify false positives, and specify compensating controls where remediation is not viable, including applications where source changes are not possible.
- Define acceptance criteria and rollback procedures with the accountable application owner prior to production implementation, escalating where ownership is unresolved.
- Ensure remediation evidence is generated by the build rather than assembled manually.
- Provide technical direction to remediation engineers executing against published standards.
- Produce standards documentation, migration procedures, developer guidance, and remediation evidence.
The pay rate for this ranges between $60-70/hour based on years of experience and expertise.
Skills and Requirements
- 10+ years of software engineering experience across the full development lifecycle, including Tech Lead roles.
- Experience designing and operating CI/CD, build, or developer platform capability adopted at scale across multiple development teams.
- Experience in Linux environments; Windows exposure preferred.
- Experience delivering in regulated environments with audit and evidence obligations.
- Experience in a shared-services or centralized delivery model supporting multiple application teams with competing priorities.
Required Technical Experience
-
Track record driving adoption of engineering standards across teams outside direct reporting lines.
-
Container build systems, including base images, multi-stage builds, minimal and hardened images, and the runtime impacts of adoption.
-
Vulnerability management, including interpreting scanner findings, exploitability and reachability assessment, prioritization, compensating controls, and exception documentation.
-
Working proficiency in Java, .NET, and Python sufficient to specify and review code changes.
-
Test strategy for request-serving services and for batch and pipeline workloads, including output-correctness verification.
-
Cloud platform depth in AWS or Azure.
-
CI/CD tooling and pipeline automation, such as Jenkins, GitHub Actions, GitLab, or equivalent.
-
Infrastructure as code, such as Terraform, Ansible, or equivalent. Desired Knowledge and Experience
-
Programmatic extraction of inventory, dependency, and configuration data from codebases at scale.
-
Policy as code.
-
Software supply chain controls, including SBOM generation, build provenance, and artifact signing.
-
Secure base image providers, cloud security posture management, or equivalent platforms.
-
Excellent verbal and written communication, with the ability to convey technical detail to audiences at varying technical levels.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to [email protected].
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
Senior Director, Security Engineering - SlackSalesforce · San Francisco, CA · $218–365K/yrPosted 1w agoPosted 1w ago
Vice President, Information SecurityDocebo Inc. · Atlanta, GA (Hybrid)Posted 5 days agoPosted 5 days ago
Director, AgentExchange Security & LabsSalesforce · Remote · US · $197–314K/yrPosted 6 days agoPosted 6 days ago- Security Operations Team LeadnuHarbor · Atlanta, GA (Hybrid) · $130–150K/yrPosted 1w agoPosted 1w ago
Team Lead On-Site Utilization Management RNWellstar Health System · Roswell, GAPosted 4 days agoPosted 4 days ago
You've read the whole posting — now see how you match it.