Imprivata Logo

Imprivata

Sr. Manager, DevSecOps and Application Security

Posted 52 Minutes Ago
Be an Early Applicant
Hybrid
Austin, TX
184K-228K Annually
Senior level
Hybrid
Austin, TX
184K-228K Annually
Senior level
Leads the DevSecOps and application security function, managing the team, program strategy, roadmap, tooling, vendors, and budget. Establishes security-by-design practices, threat modeling, secure development guidance, and training. Governs application and software supply-chain security across CI/CD, cloud, containers, infrastructure, APIs, and on-premises environments. Oversees vulnerability management, security testing, remediation, reporting, and risk processes while partnering with engineering, IT, cloud, SecOps, GRC, and architecture teams.
The summary above was generated by AI

Ready to join a team that’s all in? At Imprivata, we deliver unified access and security management programs that eliminate friction, empowering healthcare and mission-critical organizations to work smarter, faster, and more securely.

We believe work can be more than a job or task—it’s a collective spirit; the type that emboldens creativity, embraces challenge, and fosters excitement. We are constantly raising the bar on what’s possible, owning the outcome of our triumphs and trials, staying nimble amidst change, and cultivating an environment where we win together. Here, your ideas matter, your differences are celebrated, and your work drives real results—for your career, your teammates, and our customers.

When you join Imprivata, you embark on a shared journey of ambition and growth. We’re committed to building an inclusive workplace where everyone feels valued and supported. If you’re looking for a place to match your passion with purpose—and where every day you can make an impact—you’ll find it here.

We are seeking a Sr. Manager, DevSecOps and Application Security to join our team. This is a hybrid opportunity based out of our Waltham, MA; Austin, TX; or St. Petersburg, FL office.

Job Summary

The Sr. Manager of DevSecOps and Application Security leads Imprivata’s unified DevSecOps and application security function. This role embeds security throughout the software and infrastructure lifecycle, from design through retirement. The manager leads the team and partners with Engineering, Product, IT, Cloud and Infrastructure, Quality, SecOps, GRC, and Architecture. The role supports cloud, on-premises, hybrid, API, traditional software, and agentic AI environments.

Duties and Responsibilities

  • Lead, coach, and develop the DevSecOps and Application Security team while establishing clear goals, performance expectations, and development opportunities. 
  • Lead the transition of DevSecOps and Application Security into the Security organization, including the operating model, staffing, governance, processes, tools, and stakeholder communications. 
  • Own the program strategy, roadmap, staffing plan, vendor relationships, tooling decisions, budget recommendations, intake processes, service expectations, and escalation paths. 
  • Establish security-by-design practices, threat modeling, architecture reviews, policy-as-code, reusable engineering patterns, developer guidance, and security training across the software development lifecycle. 
  • Mature application security practices, including secure design and code reviews, security testing, penetration testing, bug bounty intake, vulnerability management, and risk-based remediation. 
  • Implement and govern SAST, DAST, SCA, secrets detection, container and image scanning, infrastructure-as-code scanning, API testing, license analysis, and risk-based pipeline controls. 
  • Strengthen software supply-chain and platform security by protecting repositories, build systems, deployment identities, credentials, release artifacts, cloud services, and on-premises infrastructure. 
  • Address security risks involving agentic AI and Model Context Protocol servers and clients, and partner with SecOps on monitoring, incident response, tabletop exercises, and post-incident reviews. 
  • Establish ownership, severity criteria, remediation expectations, exception processes, executive reporting, and metrics for security findings and program performance. 
  • Other duties as assigned and required. 

Required Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent practical experience. 
  • 7+ years of experience in DevOps, cloud engineering, software engineering, application security, infrastructure security, or a related discipline. 
  • Three or more years leading, managing, or mentoring security engineering, DevSecOps, or AppSec professionals, with experience building or maturing programs across multiple products or engineering organizations. 
  • Experience embedding security into CI/CD pipelines, software development workflows, cloud platforms, infrastructure as code, containers, Kubernetes, Git-based source control, and CI/CD platforms such as GitHub Actions, GitLab, or Jenkins. 
  • Experience with SAST, DAST, SCA, secrets detection, container security, IaC security, vulnerability management, threat modeling, and secure software supply-chain practices. 
  • Strong scripting or programming experience and working knowledge of IAM, least privilege, authentication, authorization, encryption, certificates, logging, and secure network design. 
  • Demonstrated ability to recruit, develop, motivate, and retain technical talent and translate technical risk for engineers, architects, executives, auditors, and nontechnical stakeholders. 

Desired Qualifications

  • Experience securing healthcare, financial services, government, or other regulated-industry products; SaaS, on-premises, hybrid, virtualized, or customer-managed deployments. 
  • Experience with identity security, zero trust, SBOMs, SLSA, Sigstore, artifact signing, provenance, policy-as-code, APIs, microservices, serverless, mobile, endpoint software, or agentic AI security. 
  • Experience integrating security tools with Jira, ServiceNow, GitHub, GitLab, SIEM, CNAPP, vulnerability management, or GRC platforms. 
  • Familiarity with STRIDE, PASTA, attack trees, or other threat-modeling methods; relevant certifications such as CISSP, CCSP, CSSLP, AWS Security Specialty, or equivalent. 

This position offers a total compensation range of $184,000.00 to $227,700.00 (inclusive of base salary and variable compensation, such as bonuses and incentives). In addition, more information about Imprivata’s benefit offerings can be found here. This range represents the high and low end of Imprivata’s compensation range for this position. Actual compensation will vary and may be above or below the range based on various factors, such as a candidate’s location, skills, experience, and qualifications.

At Imprivata, we have a top-notch work environment, developmental opportunities, a competitive total rewards package, and the desire to have fun. If you have the skills and qualifications as we have described above, we want to hear from you!

Imprivata provides equal employment opportunities, regardless of race, religion, age, sex, national origin, disability status, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

#LI-Hybrid #LI-ML1

Similar Jobs at Imprivata

52 Minutes Ago
Remote or Hybrid
United States
210K-320K Annually
Expert/Leader
210K-320K Annually
Expert/Leader
Healthtech • Information Technology • Security • Software • Cybersecurity
Manages commercial sales across the Western United States, targeting medium and large accounts in non-healthcare industries. Responsibilities include exceeding quota, developing account strategies, engaging executive decision-makers, managing demonstrations and evaluations, partnering with resellers and internal sales teams, maintaining Salesforce and Clari forecasts, and expanding existing customer relationships. Requires extensive enterprise sales experience, Identity and Access Management expertise, executive-level selling, negotiation, presentation, and autonomous territory management.
Top Skills: ClariIdentity And Access ManagementSalesforce
4 Hours Ago
Remote or Hybrid
United States
141K-153K Annually
Senior level
141K-153K Annually
Senior level
Healthtech • Information Technology • Security • Software • Cybersecurity
Leads complex enterprise IT solution deployments for healthcare clients, managing project plans, budgets, schedules, staffing, risks, vendors, and client relationships. Coordinates internal and external teams, tracks project progress and deliverables, communicates with leadership, supports SOW and budget estimation, resolves issues, and contributes to professional services project management methodologies.
Top Skills: FinancialforceExcelMicrosoft ProjectOpenairSalesforce
3 Days Ago
Remote or Hybrid
United States
113K-142K Annually
Senior level
113K-142K Annually
Senior level
Healthtech • Information Technology • Security • Software • Cybersecurity
Designs and maintains privacy controls and privacy-enhancing technologies across products and enterprise systems. Embeds privacy by design into the software development lifecycle, builds automation for consent and data subject rights, supports privacy impact assessments, and develops data protection solutions. Partners with Engineering, Product, Security, Legal, and Compliance to translate regulations into technical requirements. Also supports AI governance, privacy tooling, reusable standards, documentation, and engineering training.
Top Skills: Access ControlsAi/Ml SystemsAudit LoggingAWSAzureConsent ManagementData De-IdentificationEncryptionGCPGoJavaJavaScriptPrivacy AutomationPythonTypescript

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account