Sr. Application Security Manager
doubleverify · NYC Global HQ
Posted Sep 11, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Who We Are
DV is the leader in digital performance solutions, helping our advertiser and agency partners Verify the quality of their digital campaigns, Optimise to improve performance and Prove that they’re achieving their business outcomes, through unbiased 3rd party data and analytics. DV’s mission is to be the definitive source of transparency and data-driven insights into the quality and effectiveness of digital advertising for the world’s largest brands, agencies, publishers, and digital ad platforms. Since 2008, DV has helped hundreds of Fortune 500 companies gain the most from their media spend by delivering best-in-class solutions across the digital advertising ecosystem, helping to build a better industry. Learn more at www.doubleverify.com .
About the Role
Role Summary
As Application & AI Security leadership within DV InfoSec, you will own and evolve DoubleVerify's Secure Software Development Lifecycle (SSDLC), application security, API security, and AI/LLM security. You will lead the people, processes, and tooling that keep DV's code, pipelines, cloud workloads, APIs, and AI systems secure, partnering across the engineering organization. DV protects the integrity of digital advertising for the world's biggest brands. Securing the applications, APIs, pipelines, and AI systems behind that mission directly protects DV's customers, revenue, and reputation. You'll have executive support, real budget, modern tooling, and the mandate to build a best-in-class Application, AI, and Security Engineering program.
Key Responsibilities
Application & Product Security
Own and evolve DV's application security program, including SAST, SCA, DAST, and Application Security Posture Management (ASPM) tooling (e.g., Ox Security) — advancing findings from non-blocking warnings toward enforced, risk-based merge gates.
Drive the OWASP Application Security Verification Standard (ASVS) adoption program across engineering repositories, including reporting, dashboards, and branch-level coverage.
Drive SBOM management, license compliance, and software supply chain security practices across development teams.
Partner with DevOps and engineering to embed security across the CI/CD pipeline and Secure SDLC (SSDLC).
Develop and maintain application security metrics and reporting for engineering leadership, including vulnerability burn-down and mean-time-to-remediate (MTTR).
Lead the bi-weekly vulnerability remediation touchpoints and the monthly Application Security Leadership Forums with engineering organizations (Pinnacle, Measurement, Programmatic, Architecture, Publisher, Social, QA, TechOps/SRE, CorpIT, DevOps, and M&A) to drive progress and accountability.
Oversee DV's API security program (OWASP API Security Top 10, e.g., Escape API Security) and attack surface management (ASM) capabilities, including discovery of shadow/zombie APIs.
Assist with Web Application Firewall (WAF) configuration, deployment, and monitoring.
…