Faria is a leader in international education systems & services, offering an integrated suite across learning, admissions, school-to-home, and online courses. They are looking for a Lead Security/DevSecOps Engineer to drive application security practices and capabilities, manage security programs, and enhance the security posture across their products.
Responsibilities:
- Do an initial deep-dive assessment and evaluation to drive risk-based prioritisation of the following responsibilities
- Stand up and own the application security program across all five products — this is effectively greenfield
- Define and embed a secure SDLC (shift-left): security requirements, design reviews, guardrails, and coding standards for an AI engineering reality
- Select, deploy, and operationalise AppSec tooling (SAST, DAST, SCA/dependency and secrets scanning) integrated into CI/CD
- Implement and operationalise secrets management: detection, rotation, and vault integration across CI/CD pipelines
- Build risk-based vulnerability management: triage, prioritise, and drive remediation across teams and stacks. Lead remediation of some vulnerabilities as necessary in support of the software engineering team
- Run threat modeling and security reviews for new architecture and significant features
- Improve cloud security posture across AWS (primary) and Azure, partnering with platform/infra
- Lead technical incident response for application-layer incidents; coordinate with SOC and vCISO on cross-domain incidents
- Build security awareness and a security-champions network to upskill engineers
- Uphold student-data privacy and regulatory obligations
- Contribute technical evidence and metrics to support the security roadmap and future hiring decisions
Requirements:
- 7+ years in application/product security, ideally including standing up or substantially maturing an AppSec program (ideally near-zero to functioning)
- Strong AI knowledge and curiosity in the space, with the aim of proactive protection, as well as approaching problem-solving AI-first
- Comfortable as a founding, hands-on, solo function — self-directed and pragmatic under ambiguity
- Breadth across stacks: able to work across Ruby on Rails, PHP/Laravel, .NET/C#, and Python (deep in one or two, competent across the rest)
- Strong cloud security across AWS (primary) and Azure
- Deep grasp of common vulnerability classes and secure coding practices
- Hands-on with AppSec tooling and DevSecOps / CI/CD integration
- Threat-modeling experience
- Excellent communication and influencing skills — able to drive change in an engineering org, new to formal security
- GitHub Advanced Security experience is a strong nice-to-have
- The candidate has worked with student data or PII-heavy regulated environments (FERPA, COPPA, GDPR for UK/EU students)
- Proven experience managing large vulnerability backlogs: ability to classify, deduplicate, and drive burn-down across hundreds of repositories