Head of Application Security
Job Description
Job Title: Head of Application Security
Job Location: Los Angeles, CA OR San Francisco, CA
Reports to: Head of R&D, US
Job Status: Exempt
About SHEIN
SHEIN is a global fashion and lifestyle e-retailer committed to making the beauty of fashion accessible to all. We use on-demand manufacturing technology to connect suppliers to our agile supply chain, reducing inventory waste and enabling us to deliver a variety of affordable products to customers around the world. From our global offices, we reach customers in more than 150 countries.
Founded in 2012, SHEIN has nearly 10,000 employees operating from offices around the world, with U.S. Headquarters located in Los Angeles and Global Headquarters located in Singapore. In SHEIN, we work with outstanding, creative, and capable peers. We share an energetic and open culture for capable people to discern, work and ignite as a team.
Position Summary
SHEIN Global Security and Risk Management (GSRM) is a global security organization that oversees security infrastructure, risk management, data privacy, business fraud, governance, and regulatory compliance across SHEIN's global footprint. It is composed of a team of security professionals, innovators and thought leaders that have had decades of global security experience, led large scale transformations, and served in Fortune 500 executive roles.
We're seeking a full-time Head of Application Security for our Los Angeles-based corporate office or our San Francisco (Palo Alto) hub.
Here, innovation isn't simply about protecting and empowering our company. We develop solutions that are practical today and scalable tomorrow; and we create collaborative teams dedicated to innovation across each of our businesses to share our common values and vision. The Head of Application Security, a senior executive residing within GSRM, is responsible for leading the overall strategy, execution and roadmaps of application security and the entire secure software development lifecycle. This position will lead the team of engineering and SDL experts and work with technology and business partners and units to mitigate application risks.
This leader should have a deep technical understanding of the full SDL lifecycle and extensive experiences in code audit and application security testing. He or she must be familiar with industry standards and best practices, and must be able to effectively work with development, engineering, and business counterparts, across a broad deeply technical environment in the development world. This role will coordinate with application and system developers and owners on all aspects of SDL lifecycle through planning, feasibility analysis, design, development, testing to implementation and operations. This leader will also assist their leadership with ensuring all solutions and technologies are properly supported, implemented, and sufficiently met the needs for which they are deployed to protect SHEIN application footprint and its integrity.
Job Responsibilities
Job Requirements
Pay
$179,700 - $333,300 max annually. Bonus & RSU offered.
Benefits and Culture
Healthcare (medical, dental, vision, prescription drugs)
Health Savings Account with Employer Funding
Flexible Spending Accounts (Healthcare and Dependent care)
Company-Paid Basic Life/AD&D insurance
Company-Paid Short-Term and Long-Term Disability
Voluntary Benefit Offerings (Voluntary Life/AD&D, Hospital Indemnity, Critical Illness, and Accident)
Employee Assistance Program
Business Travel Accident Insurance
401(k) savings plan with discretionary company match and access to a financial advisor
Vacation, Paid holidays and sick days
Employee Discounts
Perks (HQ Location)
Free weekly catered lunch at HQ
Dog-Friendly office
Free Gym Access at HQ
Free Swag Giveaways
Annual Holiday Party
Invitations to pop-ups and other company events
Complimentary daily office snacks and beverages
Free Shuttle Service from HQ to LA Union Station
SHEIN Technology is an equal opportunity employer committed to a diverse workplace environment.
Job Location: Los Angeles, CA OR San Francisco, CA
Reports to: Head of R&D, US
Job Status: Exempt
About SHEIN
SHEIN is a global fashion and lifestyle e-retailer committed to making the beauty of fashion accessible to all. We use on-demand manufacturing technology to connect suppliers to our agile supply chain, reducing inventory waste and enabling us to deliver a variety of affordable products to customers around the world. From our global offices, we reach customers in more than 150 countries.
Founded in 2012, SHEIN has nearly 10,000 employees operating from offices around the world, with U.S. Headquarters located in Los Angeles and Global Headquarters located in Singapore. In SHEIN, we work with outstanding, creative, and capable peers. We share an energetic and open culture for capable people to discern, work and ignite as a team.
Position Summary
SHEIN Global Security and Risk Management (GSRM) is a global security organization that oversees security infrastructure, risk management, data privacy, business fraud, governance, and regulatory compliance across SHEIN's global footprint. It is composed of a team of security professionals, innovators and thought leaders that have had decades of global security experience, led large scale transformations, and served in Fortune 500 executive roles.
We're seeking a full-time Head of Application Security for our Los Angeles-based corporate office or our San Francisco (Palo Alto) hub.
Here, innovation isn't simply about protecting and empowering our company. We develop solutions that are practical today and scalable tomorrow; and we create collaborative teams dedicated to innovation across each of our businesses to share our common values and vision. The Head of Application Security, a senior executive residing within GSRM, is responsible for leading the overall strategy, execution and roadmaps of application security and the entire secure software development lifecycle. This position will lead the team of engineering and SDL experts and work with technology and business partners and units to mitigate application risks.
This leader should have a deep technical understanding of the full SDL lifecycle and extensive experiences in code audit and application security testing. He or she must be familiar with industry standards and best practices, and must be able to effectively work with development, engineering, and business counterparts, across a broad deeply technical environment in the development world. This role will coordinate with application and system developers and owners on all aspects of SDL lifecycle through planning, feasibility analysis, design, development, testing to implementation and operations. This leader will also assist their leadership with ensuring all solutions and technologies are properly supported, implemented, and sufficiently met the needs for which they are deployed to protect SHEIN application footprint and its integrity.
Job Responsibilities
- Oversee the application security team, consisting of direct and indirect reports (including full time employees, contractors, MSS staff and external service providers personnel). This includes hiring, training, career development, and performance management.
- Lead all aspects of SDL and application testing disciplines, including but not limited to threat modeling, application risk assessment, vulnerability management, SAST and DAST tooling, attack surface monitoring, and application penetration testing.
- Create and update new strategies, project plans and policy documents based on compliance and operational requests that map to SHEIN's business requirements
- Develop and manage security budget forecast, expense, and technology, service and vendor roadmaps.
- Liaise with external agencies, such as law enforcement, standards and technology organization, advisory bodies and industry and peer working groups as necessary, to ensure that the organization maintains a strong application security posture and technical congruency.
- Work directly with development teams to facilitate code audit, solution requirements and technology roadmaps to ensure compliance with industry and regulatory standards.
- Establish credibility throughout the organization by earning the reputation for being a proactive senior leader and change agent.
- Sustain high-availability service levels and ensure fulfillment of business-wide service levels and operational support objectives.
Job Requirements
- A minimum of 10 years of experience in global scale cyber security and development environment with strong focus in a DevSecOps eco-system and building security into the CI/CD pipeline, with at least 5 years of direct people management experience.
- Possess a Bachelor's degree or higher in the field of Engineering, Computer Science, Business Analytics, or equivalent advance technology field of study
- Must be skilled at mentoring and motivating staff, communicating goals and other corporate initiatives and driving to results
- Strong knowledge of programming languages, software development lifecycle, and security testing skills with ability to work through complex application footprint and derive characteristics of risk scenarios
- Experience building application security metrics, attack surface monitoring, and incident response strategies and playbooks in the technology industry.
- Experience with change management lifecycle, development and regular preparation of management status and key metrics reports
- Should have strong experience working with technical teams on developing advanced risk engines, algorithms and models for threat detection
- Ability to translate complex application security threats from a technical perspective to business-line understanding and execution
- Ability to manage extremely technical staff and work in a matrix organization
- High level of personal integrity, with the ability to professionally handle confidential matters and exudes the appropriate level of judgment and maturity
- Must have strong business and financial acumen to make sound business and budgeting decisions.
- Must be a strong communicator with exceptional verbal and written communication skills to translate the vision and strategy into clear priorities and direction, both internally and externally.
Pay
$179,700 - $333,300 max annually. Bonus & RSU offered.
Benefits and Culture
Healthcare (medical, dental, vision, prescription drugs)
Health Savings Account with Employer Funding
Flexible Spending Accounts (Healthcare and Dependent care)
Company-Paid Basic Life/AD&D insurance
Company-Paid Short-Term and Long-Term Disability
Voluntary Benefit Offerings (Voluntary Life/AD&D, Hospital Indemnity, Critical Illness, and Accident)
Employee Assistance Program
Business Travel Accident Insurance
401(k) savings plan with discretionary company match and access to a financial advisor
Vacation, Paid holidays and sick days
Employee Discounts
Perks (HQ Location)
Free weekly catered lunch at HQ
Dog-Friendly office
Free Gym Access at HQ
Free Swag Giveaways
Annual Holiday Party
Invitations to pop-ups and other company events
Complimentary daily office snacks and beverages
Free Shuttle Service from HQ to LA Union Station
SHEIN Technology is an equal opportunity employer committed to a diverse workplace environment.
Apply Now
Back to Job Listings
Add To Job List
Company Profile
View Company Reviews
Date Posted
10/25/2023
Views
7
Positive
Subjectivity Score: 0.9
Similar Jobs
Product Marketing Manager - Wearables, Connectivity - Meta
Views in the last 30 days - 0
View Details