What are the responsibilities and job description for the Application Security Assurance Manager position at The Depository Trust & Clearing Corporation (DTCC)?
Are you ready to make an impact at DTCC?
Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.
Pay And Benefits
As a member of the CISO organization, this role provides strategic leadership for application security governance across DTCC’s container platforms by unifying container security and vulnerability management into a cohesive, risk‑driven control framework. The leader owns the design, delivery, and continuous improvement of platform‑native AppSec controls—spanning build, deployment, and runtime—ensuring security is embedded through automation, policy‑as‑code, and standardized guardrails. By partnering closely with Cloud, Platform, and Application teams, this role enables secure scaling of containerized workloads while reducing material risk, improving vulnerability signal quality, and ensuring controls are audit‑ready, measurable, and aligned to DTCC’s regulatory and risk management expectations.
Your Primary Responsibilities
Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.
Pay And Benefits
- Competitive compensation, including base pay and annual incentive
- Comprehensive health and life insurance and well-being benefits, based on location
- Pension / Retirement benefits
- Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
- DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).
As a member of the CISO organization, this role provides strategic leadership for application security governance across DTCC’s container platforms by unifying container security and vulnerability management into a cohesive, risk‑driven control framework. The leader owns the design, delivery, and continuous improvement of platform‑native AppSec controls—spanning build, deployment, and runtime—ensuring security is embedded through automation, policy‑as‑code, and standardized guardrails. By partnering closely with Cloud, Platform, and Application teams, this role enables secure scaling of containerized workloads while reducing material risk, improving vulnerability signal quality, and ensuring controls are audit‑ready, measurable, and aligned to DTCC’s regulatory and risk management expectations.
Your Primary Responsibilities
- Lead SCA, SAST, and DAST programmes to provide scalable application security coverage across DTCC.
- Manage application security risk by driving vulnerability identification, prioritisation, remediation, and escalation.
- Partner with engineering teams to improve security outcomes and reduce application risk.
- Own AppSec platforms and services ensuring reliability, optimisation, adoption, and effective integration.
- Establish security standards and governance for secure development and testing practices.
- Drive programme maturity through metrics, reporting, automation, and continuous improvement.
- Advance detection capabilities by evaluating emerging technologies, tooling, and AI-driven security solutions.
- Maintain strong risk and control oversight through compliance with policies, standards, and regulatory expectations.
- Minimum of 8 years of related experience
- Bachelor's degree preferred or equivalent experience
- Highlights the expected benefits of new actions and strategies to help others overcome fears of change.
- Fosters a culture where honesty and transparency are expected.
- Proactively seeks feedback from others on his/her own performance.
- Ensures that regular feedback is given in a constructive and behaviorally oriented manner.
- Supports an environment where individuals are respected for their contributions.