
Application Security Manager
On-site
Full Time
#Product
#Application Security
#Penetration Testing
#Vulnerability Management
#SDLC
#SAST
#SCA
#WAF
#CI CD
#Threat Modeling
#Security
We are looking for someone who wants to deliver technology with purpose alongside a team that truly cares. At Qoria, we are on a mission to make the digital world safer for children. Headquartered in Perth and listed on the ASX, our technology protects over 22 million kids across 180 countries. Through our Linewize, Smoothwall, and Qoria brands, we help schools and families identify online risks, block harmful content, and create safer digital learning environments.
About the Role
The Application Security Manager is a full-time position responsible for safeguarding the security of our software applications. You will lead our application security engineering team and manage critical programs, including secure code scanning, penetration testing, bug bounty operations, WAF oversight, and vulnerability management compliance. This role ensures our products remain resilient to threats and compliant with security standards as we continue to grow.
Key Responsibilities
- Oversee our comprehensive vulnerability management program, ensuring all identified issues are handled according to internal policy through cross-functional collaboration with engineering leadership.
- Manage penetration testing cycles and security assessments, including vendor coordination, scoping, and driving the remediation of findings alongside product teams.
- Lead the integration of secure development tooling like SAST and SCA into our SDLC, while fostering a culture of security through developer enablement and training programs.
Requirements
- At least 5 years of experience in application security, including secure SDLC integration, with a minimum of 2 years in a technical leadership or management capacity.
- A strong background in software development and deep expertise in penetration testing methodologies and the OWASP Top 10.
- Hands-on proficiency with SAST, SCA, and WAF tools, as well as experience with CI/CD pipeline integration and vulnerability management platforms.
- A Bachelor’s degree in Computer Science, Information Security, or a related field.
- Relevant industry certifications such as OSWE, CISSP, GWAPT, CSSLP, or GIAC AppSec tracks.
- Familiarity with regulatory frameworks like SOC2 or ISO 27001 and threat modeling methodologies like STRIDE or PASTA.
Location
This role is based in Australia and requires an on-site presence.
Compensation and Benefits
We believe in supporting your professional growth and well-being. As part of our team, you can expect the following:
- Opportunities to attend local software conferences, fully paid for by the company.
- A supportive, high-performing environment where you can work on global-scale problems.
- The chance to own your career path while contributing to a mission-driven organization that protects millions of children online.






