Sr. Application Security Manager
DoubleVerify
| Company | DoubleVerify |
| Category | Engineering |
| Location | NYC Global HQ |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Manager |
| Salary | Not stated by the employer |
| Posted | 14 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (greenhouse) |
Description
Who we are
DoubleVerify is the leading independent provider of marketing measurement software, data, and analytics that authenticates the quality and effectiveness of digital media for the world's largest brands and media platforms. DV provides media transparency and accountability to deliver the highest level of impression quality for maximum advertising performance. Since 2008, DV has helped hundreds of Fortune 500 companies gain the most from their media spend by delivering best-in-class solutions across the digital ecosystem, helping to build a better industry. Learn more at www.doubleverify.com .
Role Summary
As Application & AI Security leadership within DV InfoSec, you will own and evolve DoubleVerify's Secure Software Development Lifecycle (SSDLC), application security, API security, and AI/LLM security. You will lead the people, processes, and tooling that keep DV's code, pipelines, cloud workloads, APIs, and AI systems secure, partnering across the engineering organization. (This role replaces and expands the scope of DV's Senior Application Security Manager position to formally include AI security ownership.)
Responsibilities
Application & Product Security
Own and evolve DV's application security program, including SAST, SCA, DAST, and Application Security Posture Management (ASPM) tooling (e.g., Ox Security) — advancing findings from non-blocking warnings toward enforced, risk-based merge gates.
Drive the OWASP Application Security Verification Standard (ASVS) adoption program across engineering repositories, including reporting, dashboards, and branch-level coverage.
Drive SBOM management, license compliance, and software supply chain security practices across development teams.
Partner with DevOps and engineering to embed security across the CI/CD pipeline and Secure SDLC (SSDLC).
Develop and maintain application security metrics and reporting for engineering leadership, including vulnerability burn-down and mean-time-to-remediate (MTTR).
Lead the bi-weekly vulnerability remediation touchpoints and the monthly Application Security Leadership Forums with engineering organizations (Pinnacle, Measurement, Programmatic, Architecture, Publisher, Social, QA, TechOps/SRE, CorpIT, DevOps, and M&A) to drive progress and accountability.
Oversee DV's API security program (OWASP API Security Top 10, e.g., Escape API Security) and attack surface management (ASM) capabilities, including discovery of shadow/zombie APIs.
Assist with Web Application Firewall (WAF) configuration, deployment, and monitoring.
Partner with DevOps/SRE on cloud and container security (e.g., Wiz) to deliver code-to-cloud coverage.
AI & Emerging Technology Security
Lead AI security governance, engineering, and threat assessment functions across DV's AI/ML ecosystem.
Secure AI agents, LLM-based applications, MCP gateway, and agentic SDLC workflows against threats such as prompt injection, jailbreaking, excessive agency, and supply chain compromise — including guardrails, telemetry, logging, and detections for developer AI tooling (Cursor, Claude Code, VS Code).
Evaluate and operationalize AI security platforms to provide detection, response, and AI supply chain governance across teams building or operating AI systems (e.g., AI security gateway, shadow-AI discovery/DLP, AI identity and software management).
Build threat models and controls for first- and third-party AI/ML workloads, including data pipelines, model provenance, and RAG architectures.
Advance AI-assisted security testing (e.g., DV's PromptFlow-driven web/API security test generation) to scale coverage across teams.
Security Engineering, Offensive Security & DevSecOps Enablement
Lead DV's offensive security and penetration testing program, working with external vendors and conducting internal security assessments.
Build and maintai