Application Security Manager at Qoria

Qoria logo
Qoria

Application Security Manager

au flag
Australia

On-site

Full Time

#Product

#Application Security

#Penetration Testing

#Vulnerability Management

#SDLC

#SAST

#SCA

#WAF

#CI CD

#Threat Modeling

#Security

Qoria is looking for a Application Security Manager

Sign up to unlock quick summaries and profile fit assessments

Want to deliver tech with purpose, with people who care?

Join us in our mission to create solutions that help keep children safe online.


Who are we?

At Qoria, we're on a mission to make the digital world safer for children. Headquartered in Perth and listed on the ASX, our technology protects over 22 million kids across 180 countries. Through our Linewize, Smoothwall, and Qoria brands, we help schools and families identify online risks, block harmful content, and create safer digital learning environments.


What’s the opportunity?

The Application Security Manager is responsible for safeguarding the security of Qoria’s software applications. This role leads the application security engineering team and manages key programs including secure code scanning tools, penetration testing, bug bounty operations, WAF oversight, and vulnerability management compliance. The Application Security Manager ensures that our products are resilient to threats, compliant with security standards, and continuously improving in response to an evolving risk landscape.

Duties: What are my day to day duties?

The Application Security Manager is responsible for overseeing a broad range of activities to strengthen Qoria’s application security posture. This includes leadership across people, programs, and platforms, continuous improvement of tooling and process, and technical leadership. 

Vulnerability Management

You will be responsible for overseeing Qoria’s Vulnerability Management Program, ensuring that all identified vulnerabilities are handled in accordance with our internal policy. This program is a cross-functional initiative sponsored by the CTO, CPO, and CISO, and involves active participation from all areas of Engineering.

Penetration Testing & Security Assessments

This role oversees all penetration testing activities, including scheduling, scoping, and vendor management for third-party assessments. You’ll collaborate with engineering and product teams to drive timely remediation of findings, and you’ll play a key role in performing early-stage threat modelling and security reviews for new product features before they are released.

Code Security & Repository Governance

You will manage secure development tooling (including SAST, SCA, and related GitHub workflows) and ensure their integration into the SDLC. You’ll drive code repository hygiene, while managing and reducing technical debt tied to security issues.

Bug Bounty & Vulnerability Disclosure Programs

You will oversee Qoria’s Bug Bounty and Vulnerability Disclosure Program (VDP), working closely with our triage partners to ensure that submissions from security researchers are assessed efficiently and accurately. While triage is handled externally, you will be responsible for managing internal coordination, validating findings where needed, driving timely remediation with engineering teams, facilitating rewards, and continuously improving the program based on submission trends, feedback, and emerging threat intelligence.

Web Application Firewall (WAF) Oversight

You’ll manage WAF configurations and tuning to mitigate real-time application threats, working closely with engineering teams to ensure that all externally-facing applications are adequately protected. Your insight will be critical in aligning WAF rules with current attack patterns and Qoria’s broader threat model.

Security Communication & Developer Enablement

A core part of your success will lie in how well you foster a culture of security. You will lead Qoria’s Engineering Security Communication Program, delivering updates, training, and awareness campaigns that help developers build securely from the ground up. You’ll also oversee the approval and tracking of security tasks and support engineering teams with hands-on guidance and governance.

Team Leadership & Strategic Growth

As a team leader, you will manage, mentor, and expand the Application Security Engineering team. You will define clear goals, foster professional development, and build a collaborative, high-performing security culture. In partnership with the Director of Product Security, CISO and other senior leaders, you will also contribute directly to the evolution of Qoria’s global security strategy, ensuring application security scales effectively with the organisation’s growth.

Performance: How is my performance measured?

  • Deliver on Program Ownership: Timely and effective execution of penetration testing cycles, bug bounty management, engineering communications, WAF coverage, and vulnerability remediation workflows.

  • Meet Security SLAs: Ensure vulnerabilities - whether from scans, pen tests, or bug bounty disclosures - are triaged and remediated within defined SLAs.

  • Drive Secure Development Practices: Measurable improvements in the security maturity of engineering practices (e.g. shift-left adoption, SAST/SCA coverage, developer training completion).

  • Produce Actionable Reporting: Regular and high-quality reporting of application security posture, including clear KPIs, trends, and evidence for audit and board-level visibility.

  • Lead and Empower the Team: Foster a high-performing AppSec engineering team with clear goals, mentorship, and measurable team engagement.

  • Stakeholder Collaboration: Demonstrated trust and responsiveness in working with product, engineering, DevOps, compliance, and third-party vendors.
    Incident and Threat Readiness: Proactive participation in incident handling and real-time intelligence response to emergent threats.

Requirements: What skills & experience is required?

What skills & experience are required?

  • 5+ years of experience in Application Security, including secure SDLC integration, with 2+ years in a technical leadership or management role.

  • Deep expertise in secure development practices, penetration testing methodologies, and OWASP Top 10/CWE.

  • Background & experience in software development 

  • Hands-on experience with SAST, SCA, and WAF tools, CI/CD pipeline integration, and code repository security governance.

  • Proficiency with vulnerability management platforms 

  • Strong communication skills and experience managing cross-functional stakeholders, external vendors, and security researchers.

  • Bachelor’s degree in Computer Science, Information Security, or related field.

  • Certifications such as OSWE, CISSP, GWAPT, CSSLP, or GIAC AppSec tracks.

  • Experience with regulatory frameworks (e.g. SOC2, ISO 27001).

  • Familiarity with threat modeling methodologies (STRIDE, PASTA, etc.).

To be successful in this role, you must:

  • Be strategic yet hands-on, capable of setting security direction while diving into technical problem solving when needed.

  • Possess strong communication skills, especially in translating technical risk into business impact and driving action across teams.

  • Be a bridge between security and engineering - respected by developers, trusted by leadership, and responsive to operational realities.

  • Show bias for action: take ownership of issues and drive them to resolution, especially in fast-paced or ambiguous environments.

  • Demonstrate technical fluency with modern DevSecOps tooling, secure code review, GitOps, and vulnerability prioritization.

  • Have a continuous improvement mindset, always looking to refine processes, reduce false positives, and automate where possible.

  • Embody calm leadership under pressure, particularly in incident response or when communicating about newly discovered vulnerabilities.


Why choose us?

  • Deliver tech with purpose...

As a member of our Engineering team, your work truly matters. Your skills, knowledge and ideas will all help children stay safe online. It feels good to do good.

  • With people who care...

Our Engineers are amazing! They’re also amazingly supportive. We all take ownership of our work, end to end. And at the same time, we really care about growing and winning together.

  • Through work that you love...

You’ll get to work on solving problems for a global engineering team that has a user base in the tens of millions. And you'll be exposed to modern technologies and processes, in a fast-paced and supportive learning environment.

  • And a career that you own...

This role offers so many opportunities to expand your skills and grow your career. You’ll get to attend local software conferences, paid for by us. And as you step up and take ownership to make things happen, you’ll carve out an incredible career.


Shortlisting will commence immediately.

null
Qoria logo

Qoria

3 views

0 applied

Social Media

Visit Qoria
Share this job
Copy Permalink
Discover similar jobs
C
Chili Piper

Sales Development Representative

Remote

Full Time

#Sales

#Outbound Sales

#B2B SaaS

#Outbound Prospecting

#Lead Generation

#Sales Strategy

#Analytical Skills

#Communication Skills

#Outreach

#Cold Calling

#Product

Tebra logo
Tebra

Security Architect

179k - 204k USD

Remote

Full Time

#Security

#Cloud Security

#Healthcare

#Cloudflare

#GCP

#Kubernetes

#Terraform

#Python

#DevSecOps

#Vertex AI

#BigQuery

#Helm

#Workato

F
Form3

Junior Product Owner

Remote

Full Time

#Payments

#Product Management

#Business Analysis

#user

#API

#Data Analysis

#Stakeholder Management

#Product

L
Lightdash

Head of Engineering

Remote

Full Time

#Engineering Leadership

#AI

#Developer Experience

#TypeScript

#React

#Node.Js

#SQL

#Docker

#Kubernetes

#GCP

#Architecture

#Security

Hummingbird logo
Hummingbird

Senior Software Engineer, Infrastructure

Remote

Full Time

#Infrastructure Engineering

#Fintech

#Security

#AWS

#Terraform

#PostgreSQL

#Redis

#Ruby on Rails

#Python

#Docker

#CircleCi

#GraphQL

#TypeScript

S
Sparrow

Account Executive

Remote

Full Time

#Sales

#SaaS

#HR Tech

#B2B Sales

#Salesforce

#Outreach

#Gong

#LinkedIn Sales Navigator

#Product

#ROI

Vericast logo
Vericast

Sales Enablement Content Manager

Remote

Full Time

#Sales Enablement

#Content Management

#Sales

#Content

#Messaging Strategy

#Product

A
Arcade

Talent Network

Remote

Other

#Network

#Engineering

#Product

The Browser Company logo
The Browser Company

Staff Security Engineer

225k - 300k USD

Remote

Full Time

#Security

#Browser Development

#Security Engineering

#Golang

#Swift

#TypeScript

#Python

#Threat Modeling

#Security Architecture

E
Exodus Movement Inc.

Security Engineer

130k - 160k USD

Remote

Full Time

#Security Engineering

#Security

#AI

#Detection Engineering

#Incident Response

#SIEM

#AWS Security

#Scripting Languages

#MITRE

#Threat Modeling

W
Winona

Product Development Project Manager

Remote

Full Time

#Product Development

#Project Management

#Software Engineering

#Agile

#Scrum

#Kanban

#ClickUp

#SDLC

#Sprint Planning

#Coordination

#Management

#Resource Allocation

Unqork logo
Unqork

Senior Application Security Engineer

117k - 160k USD

Remote

Full Time

#Application Security

#Penetration Testing

#Security Engineering

#OWASP Top 10

#Node.Js

#Python

#Burp suite

#OWASP

#SAST

#DAST

#SCA

#Vulnerability Management

Xebia logo
Xebia

Senior DevOps Platform Engineer

Remote

Full Time

#DevOps

#Platform Engineering

#Harness

#Kubernetes

#Terraform

#AWS

#Azure

#GCP

#GitOps

#Observability

#Security

#Ansible

dLocal logo
dLocal

AI Product Manager

Remote

Full Time

#Product

#Developer Tools

#Software Engineering

#Product Management

#Git

#Testing

#Metrics Analysis

#Communication

#Orchestration

Chainguard logo
Chainguard

Enterprise Business Development Representative

100k - 100k USD

Remote

Full Time

#Business Development

#Enterprise Sales

#Security

#Outbound Sales

#Salesforce

#Outreach

#SalesLoft

#Pipeline Generation

#Stakeholder Engagement

Proof logo
Proof

Director of Product, Crypto

Remote

Full Time

#Crypto

#Product Management

#Web3

#Product Strategy

#Payments

#Product

#Customer Discovery

#Collaboration

#GTM

#Compliance

#Blockchain

C
Cross River

AVP, Product Manager - Online Banking

us flag
United States

150k - 180k USD

Hybrid

Full Time

#Product

#Banking

#Fintech

#Product Management

#Software Development

#Strategic Thinking

#Project Management

#API Products

#Jira

#Customer Insights

#Technical Proficiency

TomTom logo
TomTom

Senior Developer Advocate

nl flag
Netherlands

Hybrid

Full Time

#Product

#Developer Relations

#APIs

#SDKs

#JavaScript

#Python

#Java

#RESTful API

#Technical Content

#Community Engagement

Cloudinary logo
Cloudinary

Lead Product Manager

il flag
Israel

Hybrid

Full Time

#Product

#Product Management

#SaaS

#AI

#UX

#Agile

P
Platomics GmbH

Product Manager

at flag
AT, DE

44k - 55k USD

Hybrid

Full Time

#Product

#Healthcare

#Regulatory

#Product Management

#Market Research

#Jira

#Figma

#Analytics

#Data Analysis

Your dream job awaits.

Explore exciting opportunities, connect with top employers, and ignite your career.