Director of Application and DevSecOps Security

<span class="jobdescription"><p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Be part of a team that unleashes the power of leading-edge technologies to help improve the health and well-being of those most vulnerable in our country and communities. Working at Gainwell carries its rewards. You’ll have an incredible opportunity to grow your career in a company that values work flexibility, learning, and career development. You’ll add to your technical credentials and certifications while enjoying a generous, flexible vacation policy and educational assistance. We also have comprehensive leadership and technical development academies to help build your skills and capabilities.</span></p> <p> </p><div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:18.0px;word-wrap:break-word"><h2 style="font-size:1.0em;margin:0.0px"><b>Summary</b></h2> </div><div><p>The Director of Application & DevSecOps Security is responsible for leading the organization’s strategy and execution of secure software development practices across application security, API security, and DevOps (shift-left) initiatives.</p> <p> </p> <p>This role establishes and enforces SDLC security policies, defines secure design requirements, and builds scalable training programs to embed security into the engineering culture, ensuring the organization can deliver secure, resilient, and compliant solutions at scale.</p> <p> </p> <p>This leader partners cross-functionally with Engineering, Product, DevOps, and Risk teams to ensure security is integrated early and continuously throughout the development lifecycle.</p></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:18.0px;word-wrap:break-word"><h2 style="font-size:1.0em;margin:0.0px"><b>Your role in our mission</b></h2> </div><div><ul> <li>Define and lead the enterprise Application Security and DevSecOps strategy aligned to business objectives.</li> <li>Build and mature a shift-left security program integrated into CI/CD pipelines.</li> <li>Establish and implement roadmap for API security, including governance, discovery, and runtime protection.</li> <li>Balance governance with enablement by establishing guardrails, reusable patterns, and self‑service security tooling that empower engineering teams.</li> <li>Lead, mentor, and grow a high-performing security engineering team.</li> <li>Oversee secure coding practices, SAST/DAST/SCA tooling, and vulnerability management processes.</li> <li>Define API security standards including authentication, authorization, rate limiting, and data protection.</li> <li>Drive threat modeling practices across critical applications and services.</li> <li>Partner with engineering and development teams to remediate risks and improve secure design patterns.</li> <li>Embed automated security controls into CI/CD pipelines.</li> <li>Champion developer-first security tooling and workflows</li> <li>Partner with DevOps teams to ensure secure infrastructure-as-code (IaC) practices.</li> <li>Measure and improve security posture through pipeline metrics and KPIs.</li> <li>Define and maintain secure SDLC policies, standards, and control frameworks.</li> <li>Establish secure design and architecture requirements for new systems.</li> <li>Ensure alignment with regulatory and compliance requirements (e.g., SOC 2, ISO 27001, NIST).</li> <li>Lead security reviews and design approvals for critical initiatives.</li> <li>Design and implement role-based and just-in-time developer security training programs.</li> <li>Build secure coding guidelines and internal knowledge resources.</li> <li>Drive security awareness and culture across engineering teams.</li> <li>Partner with leadership to ensure adoption and accountability.</li> <li>Define KPIs and KRIs for application and DevSecOps security maturity.</li> <li>Report on risk posture, vulnerabilities, and program effectiveness to executive leadership.</li> <li>Continuously assess and improve tooling, processes, and coverage.</li> </ul></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:18.0px;word-wrap:break-word"><h2 style="font-size:1.0em;margin:0.0px"><b>What we're looking for</b></h2> </div><div><ul> <li>10+ years of experience in cybersecurity with a strong focus on application security and DevSecOps.</li> <li>5+ years in a leadership or director-level role managing teams.</li> <li>Deep expertise in secure SDLC, application security testing (SAST, DAST, SCA), and API security.</li> <li>Experience integrating security into CI/CD pipelines and cloud-native environments (AWS, Azure, or GCP).</li> <li>Experience with container security, Kubernetes security, serverless security concepts and delivery.</li> <li>Strong knowledge of modern architectures (microservices, containers, Kubernetes).</li> <li>Proven experience building security programs and influencing engineering culture.</li> </ul></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:18.0px;word-wrap:break-word"><h2 style="font-size:1.0em;margin:0.0px"><b>What you should expect in this role</b></h2> </div><div><ul type="disc"> <li>Fully Remote Opportunity – Work from anywhere in the U.S. </li> <li>Minimal Travel Required – Occasional travel opportunities (0-20%). </li> <li>Video cameras must be used during all interviews, as well as during the initial week of orientation.</li> </ul> <p> </p> <p>The deadline to submit applications for this posting is June 5, 2026.</p></div></div></div><p> </p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">The pay range for this position is $150,200.00 - $214,500.00 per year, however, the base pay offered may vary depending on geographic region, internal equity, job-related knowledge, skills, and experience among other factors. Put your passion to work at Gainwell. You’ll have the opportunity to grow your career in a company that values work flexibility, learning, and career development. All salaried, full-time candidates are eligible for our generous, flexible vacation policy, a <span style="color:#cb1ac6"><u><a style="color:#cb1ac6" href="https://jobs.gainwelltechnologies.com/content/benefits/?locale=en_US">401(k) employer match, comprehensive health benefits</a></u></span>, and educational assistance. We also have a variety of leadership and technical development academies to help build your skills and capabilities.</span></p> <p> </p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">We believe nothing is impossible when you bring together people who care deeply about making healthcare work better for everyone. Build your career with Gainwell, an industry leader. You’ll be joining a company where collaboration, innovation, and inclusion fuel our growth. Learn more about Gainwell at our <span style="color:#cb1ac6"><a style="color:#cb1ac6" href="https://www.gainwelltechnologies.com/">company website</a></span> and visit our <span style="color:#cb1ac6"><a style="color:#cb1ac6" href="https://jobs.gainwelltechnologies.com/">Careers site</a></span> for all available job role openings.</span></p> <p> </p> <p><span style="font-size:8.0pt;font-family:arial, helvetica, sans-serif"><em style="font-style:italic">Gainwell Technologies <span style="color:#32363a">is an Equal Opportunity Employer, where all qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical condition), age, sexual orientation, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. <span style="font-size:8.0pt;font-family:arial, helvetica, sans-serif">Gainwell Technologies defines “wages” and “wage rates” to include “all forms of pay, including, but not limited to, salary, overtime pay, bonuses, stock, stock options, profit sharing and bonus plans, life insurance, vacation and holiday pay, cleaning or gasoline allowances, hotel accommodations, reimbursement for travel expenses, and benefits.</span></span></em></span></p> </span>

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...