# Department Manager - Application Security

**Company:** [CP Axtra](http://jobs.workable.com/companies/1cWkogd8purSPWZfcuHmCe.md)
**Location:** Bangkok, Thailand
**Workplace:** on site
**Department:** Technology

[Apply for this job](http://jobs.workable.com/view/12071d0c-526d-4920-be21-d2675a8f7c30)

## Description

You will lead CP Axtra's Application Security program end-to-end — from defining secure SDLC policies to managing the toolchain that enforces them. You'll own the SAST, SCA, DAST, and secrets scanning platforms (Checkmarx, SonarQube, Qualys WAS, Spectral, OWASP ZAP) and ensure they're integrated into every CI/CD pipeline, producing actionable results rather than alert fatigue.

This is a leadership role with deep technical expectations. You'll manage the SAST/SCA/DAST/IaC Security Manager, consult directly with development teams on secure design and remediation, and represent application security in architecture reviews. You'll need to balance enforcement with enablement — developers should see your team as a resource that helps them ship securely, not a gate that slows them down.

The right person combines strong application security expertise with the communication skills to influence development culture across a large, diverse engineering organization.

**KEY RESPONSIBILITIES**

·       Own and evolve CP Axtra's Secure SDLC framework — defining security requirements, review gates, and testing standards for all software development projects

·       Manage and optimize the AppSec toolchain (Checkmarx, SonarQube, Qualys WAS, Spectral, OWASP ZAP), ensuring high detection rates with low false positive noise

·       Drive CI/CD pipeline security integration across GitHub Actions, Azure DevOps, and Jenkins — making security checks automated, fast, and non-bypassable

·       Lead threat modeling and secure design reviews for high-risk applications, including e-commerce platforms, payment integrations, and customer data systems

·       Consult with development teams on vulnerability remediation — not just telling them what's broken, but helping them understand the fix and the 'why' behind it

·       Define and enforce security quality gates: what blocks a release, what generates a warning, and what gets tracked for future remediation

·       Manage the SAST/SCA/DAST/IaC Security Manager, providing technical direction and ensuring operational excellence across the scanning platforms

·       Report application security posture metrics to the Associate Director and CISO — trends in vulnerability density, remediation velocity, and coverage gaps

·       Evaluate emerging AppSec technologies including AI-assisted code review and automated fix suggestion tools

·       Coordinate with the Offensive Security team to align penetration testing priorities with application risk profiles

## Requirements

**TECHNICAL REQUIREMENTS**

·       Checkmarx (SAST/SCA), SonarQube, Qualys WAS, Spectral, OWASP ZAP

·       CI/CD platforms: GitHub Actions, Azure DevOps, Jenkins

·       Code review in Java, Python, JavaScript/TypeScript, or similar

·       Threat modeling frameworks: STRIDE, PASTA, or equivalent

**MUST-HAVE REQUIREMENTS**

These are non-negotiable. If you do not meet all of these, this role is not the right fit.

·       5+ years in application security — secure SDLC, code review, vulnerability management, or AppSec tooling management

·       Hands-on experience with at least 2 of: SAST, SCA, DAST, or secrets scanning tools (Checkmarx, SonarQube, Snyk, Qualys WAS, or equivalent)

·       Strong understanding of CI/CD pipelines and how to integrate security checks without breaking developer velocity (GitHub Actions, Azure DevOps, Jenkins)

·       Ability to review code for security issues in at least 2 programming languages (Java, Python, JavaScript/TypeScript, Go, or C#)

·       Experience leading or mentoring a team — you'll manage at least one direct report and influence a broader developer community

·       Excellent communication skills — you'll spend significant time consulting with developers who may not have security backgrounds

·       Understanding of OWASP Top 10, SANS Top 25, and modern application attack patterns

**NICE-TO-HAVE**

These will set you apart from other candidates:

·       Experience with container security scanning (Trivy, Prisma Cloud, Aqua) and IaC security (Checkov, tfsec)

·       Background in software development — candidates who've written production code understand developer pain points better

·       Familiarity with AI/LLM security risks and secure development practices for AI-integrated applications

·       CSSLP, GWEB, or CASE certification

·       Experience in retail or e-commerce application security, especially PCI DSS-relevant environments

·       Thai language proficiency for developer training and stakeholder communication
