Application Security Manager at Qoria

Qoria logo
Qoria

Application Security Manager

au flag
Australia

On-site

Full Time

#Product

#Application Security

#Penetration Testing

#Vulnerability Management

#SDLC

#SAST

#SCA

#WAF

#CI CD

#Threat Modeling

#Security

Qoria is looking for a Application Security Manager

Sign up to unlock quick summaries and profile fit assessments

Want to deliver tech with purpose, with people who care?

Join us in our mission to create solutions that help keep children safe online.


Who are we?

At Qoria, we're on a mission to make the digital world safer for children. Headquartered in Perth and listed on the ASX, our technology protects over 22 million kids across 180 countries. Through our Linewize, Smoothwall, and Qoria brands, we help schools and families identify online risks, block harmful content, and create safer digital learning environments.


What’s the opportunity?

The Application Security Manager is responsible for safeguarding the security of Qoria’s software applications. This role leads the application security engineering team and manages key programs including secure code scanning tools, penetration testing, bug bounty operations, WAF oversight, and vulnerability management compliance. The Application Security Manager ensures that our products are resilient to threats, compliant with security standards, and continuously improving in response to an evolving risk landscape.

Duties: What are my day to day duties?

The Application Security Manager is responsible for overseeing a broad range of activities to strengthen Qoria’s application security posture. This includes leadership across people, programs, and platforms, continuous improvement of tooling and process, and technical leadership. 

Vulnerability Management

You will be responsible for overseeing Qoria’s Vulnerability Management Program, ensuring that all identified vulnerabilities are handled in accordance with our internal policy. This program is a cross-functional initiative sponsored by the CTO, CPO, and CISO, and involves active participation from all areas of Engineering.

Penetration Testing & Security Assessments

This role oversees all penetration testing activities, including scheduling, scoping, and vendor management for third-party assessments. You’ll collaborate with engineering and product teams to drive timely remediation of findings, and you’ll play a key role in performing early-stage threat modelling and security reviews for new product features before they are released.

Code Security & Repository Governance

You will manage secure development tooling (including SAST, SCA, and related GitHub workflows) and ensure their integration into the SDLC. You’ll drive code repository hygiene, while managing and reducing technical debt tied to security issues.

Bug Bounty & Vulnerability Disclosure Programs

You will oversee Qoria’s Bug Bounty and Vulnerability Disclosure Program (VDP), working closely with our triage partners to ensure that submissions from security researchers are assessed efficiently and accurately. While triage is handled externally, you will be responsible for managing internal coordination, validating findings where needed, driving timely remediation with engineering teams, facilitating rewards, and continuously improving the program based on submission trends, feedback, and emerging threat intelligence.

Web Application Firewall (WAF) Oversight

You’ll manage WAF configurations and tuning to mitigate real-time application threats, working closely with engineering teams to ensure that all externally-facing applications are adequately protected. Your insight will be critical in aligning WAF rules with current attack patterns and Qoria’s broader threat model.

Security Communication & Developer Enablement

A core part of your success will lie in how well you foster a culture of security. You will lead Qoria’s Engineering Security Communication Program, delivering updates, training, and awareness campaigns that help developers build securely from the ground up. You’ll also oversee the approval and tracking of security tasks and support engineering teams with hands-on guidance and governance.

Team Leadership & Strategic Growth

As a team leader, you will manage, mentor, and expand the Application Security Engineering team. You will define clear goals, foster professional development, and build a collaborative, high-performing security culture. In partnership with the Director of Product Security, CISO and other senior leaders, you will also contribute directly to the evolution of Qoria’s global security strategy, ensuring application security scales effectively with the organisation’s growth.

Performance: How is my performance measured?

  • Deliver on Program Ownership: Timely and effective execution of penetration testing cycles, bug bounty management, engineering communications, WAF coverage, and vulnerability remediation workflows.

  • Meet Security SLAs: Ensure vulnerabilities - whether from scans, pen tests, or bug bounty disclosures - are triaged and remediated within defined SLAs.

  • Drive Secure Development Practices: Measurable improvements in the security maturity of engineering practices (e.g. shift-left adoption, SAST/SCA coverage, developer training completion).

  • Produce Actionable Reporting: Regular and high-quality reporting of application security posture, including clear KPIs, trends, and evidence for audit and board-level visibility.

  • Lead and Empower the Team: Foster a high-performing AppSec engineering team with clear goals, mentorship, and measurable team engagement.

  • Stakeholder Collaboration: Demonstrated trust and responsiveness in working with product, engineering, DevOps, compliance, and third-party vendors.
    Incident and Threat Readiness: Proactive participation in incident handling and real-time intelligence response to emergent threats.

Requirements: What skills & experience is required?

What skills & experience are required?

  • 5+ years of experience in Application Security, including secure SDLC integration, with 2+ years in a technical leadership or management role.

  • Deep expertise in secure development practices, penetration testing methodologies, and OWASP Top 10/CWE.

  • Background & experience in software development 

  • Hands-on experience with SAST, SCA, and WAF tools, CI/CD pipeline integration, and code repository security governance.

  • Proficiency with vulnerability management platforms 

  • Strong communication skills and experience managing cross-functional stakeholders, external vendors, and security researchers.

  • Bachelor’s degree in Computer Science, Information Security, or related field.

  • Certifications such as OSWE, CISSP, GWAPT, CSSLP, or GIAC AppSec tracks.

  • Experience with regulatory frameworks (e.g. SOC2, ISO 27001).

  • Familiarity with threat modeling methodologies (STRIDE, PASTA, etc.).

To be successful in this role, you must:

  • Be strategic yet hands-on, capable of setting security direction while diving into technical problem solving when needed.

  • Possess strong communication skills, especially in translating technical risk into business impact and driving action across teams.

  • Be a bridge between security and engineering - respected by developers, trusted by leadership, and responsive to operational realities.

  • Show bias for action: take ownership of issues and drive them to resolution, especially in fast-paced or ambiguous environments.

  • Demonstrate technical fluency with modern DevSecOps tooling, secure code review, GitOps, and vulnerability prioritization.

  • Have a continuous improvement mindset, always looking to refine processes, reduce false positives, and automate where possible.

  • Embody calm leadership under pressure, particularly in incident response or when communicating about newly discovered vulnerabilities.


Why choose us?

  • Deliver tech with purpose...

As a member of our Engineering team, your work truly matters. Your skills, knowledge and ideas will all help children stay safe online. It feels good to do good.

  • With people who care...

Our Engineers are amazing! They’re also amazingly supportive. We all take ownership of our work, end to end. And at the same time, we really care about growing and winning together.

  • Through work that you love...

You’ll get to work on solving problems for a global engineering team that has a user base in the tens of millions. And you'll be exposed to modern technologies and processes, in a fast-paced and supportive learning environment.

  • And a career that you own...

This role offers so many opportunities to expand your skills and grow your career. You’ll get to attend local software conferences, paid for by us. And as you step up and take ownership to make things happen, you’ll carve out an incredible career.


Shortlisting will commence immediately.

null
Qoria logo

Qoria

3 views

0 applied

Social Media

Visit Qoria
Share this job
Copy Permalink
Discover similar jobs
P
Primer.io

Senior Product Manager

Remote

Full Time

#Product

#Payments

#Product Strategy

#Stakeholder Management

#Collaboration

#Data Analysis

#Roadmap Planning

#Competitive Analysis

A
Astra

Product Lead, Payments

us flag
United States

Remote

Full Time

#Product

#Payments

#Fintech

#Product Management

#API Design

#RTP

#Move

#NACHA

A
Airship

Alliance and Partnership Manager

Remote

Full Time

#Partnerships

#Business Development

#SaaS

#Partnership Management

#Sales

#Crossbeam

#Salesforce

#Marketing

#Product

#API

Upwave logo
Upwave

DevOps Security Contractor

us flag
United States

Remote

Contractor

#Product

#DevOps

#Security

#AWS

#Infrastructure Security

#IAM

#Incident Response

#SOC 2

#Cloud Security

Fullscript logo
Fullscript

Cloud Security Engineer

73k - 80k USD

Remote

Full Time

#Security

#Cloud

#AWS

#Google Cloud

#Terraform

#Python

#Go

#IAM

B
Banyan Software

AI Director

250k - 300k USD

Remote

Full Time

#Technology

#Software

#AI

#Cloud Native

#CI CD

#DevSecOps

#Microservices

#Infrastructure as Code

#AWS

#Azure

Distribusion logo
Distribusion

Technical Product Manager, Rail Integrations

Remote

Full Time

#Product

#Tech

#Product Management

#API

#Data Products

#Stakeholder Management

#Teams

#Process Improvement

#Jira

CareMessage logo
CareMessage

Senior Product Manager - Data & Interoperability

Remote

Full Time

#Product Development

#Product

#Data

#FHIR

#HL7

#Electronic Health Records

#Product Management

#B2B SaaS

#Technology

A
AppSamurai

Sales Account Executive

Remote

Full Time

#Business Development

#Sales

#SaaS Sales

#B2B Sales

#Account Management

#CRM

#Product

#Contract Negotiation

#Demand Generation

#Outbound Prospecting

Ethena Labs logo
Ethena Labs

Staff Security Engineer

Remote

Full Time

#Security

#DeFi

#Engineering

#Solidity

#EVM

#Foundry

#SAFe

M
Magicschool

Senior Security Engineer

Remote

Full Time

#Engineering

#Security

#Edtech

#SAST

#DAST

#SCA

#AWS

#Google Cloud

#Threat Modeling

#IAM

#SSO

#SAML

#OIDC

Diabolocom logo
Diabolocom

Python Backend Engineer

Remote

Full Time

#AI

#Engineering

#Python

#CI CD

#Microservices

#API Design

#Testing

#Domain Driven Design

V
VidMob

Staff DevOps Security Engineer

Remote

Full Time

#Engineering

#DevOps

#Security

#AWS

#GCP

#Kubernetes

#Terraform

#Gitlab

#Datadog

#Prometheus

#Grafana

#OpenTelemetry

#Vertex AI

C
Coalition, Inc.

Director, Integrated Security Campaigns

ca flag
Canada

180k - 240k USD

Remote

Full Time

#Marketing

#Security

#Demand Generation

#Campaigns

#Digital Marketing

#ABM

#Field Marketing

#SEM

#Paid Social

#Attribution

#Campaign Strategy

Agiloft logo
Agiloft

Senior Platform Engineer

Remote

Full Time

#Product

#Engineering

#Python

#AWS

#Serverless

#API Gateway

#Lambda

#DynamoDB

#Git

#Postgres

#CloudFormation

#SAM

#RESTful API

#GitHub Actions

#Docker

#ECS

Frontify logo
Frontify

Backend Engineer

ch flag
Switzerland

Remote

Full Time

#Product

#Engineering

#PHP

#RESTful API

#GraphQL

#React

#API Design

#Unit Testing

#Integration Testing

K
Kognity

Head of Product Design

se flag
Sweden

Remote

Full Time

#Product

#Design

#Edtech

#Product Design

#AI

#Leadership

#Strategy

#Prototyping

L
Linear

Senior / Staff Fullstack Engineer

, EU

Remote

Full Time

#Product

#Developer Tools

#React

#TypeScript

#GraphQL

#Node

#PostgreSQL

#JavaScript

#MobX

#Redis

#Kubernetes

Thefreeosk logo
Thefreeosk

Associate Product Manager

80k - 95k USD

Remote

Full Time

#Product

#Retail

#Jira

#Confluence

#Slack

#Google Workspace

#Microsoft Office

#Excel

#Google Sheets

#Agile

#Scrum

S
Seqera.io

Senior Design Engineer

Remote

Full Time

#Product

#Design

#React

#Angular

#JavaScript

#UI Design

#Prototyping

#Design Systems

Your dream job awaits.

Explore exciting opportunities, connect with top employers, and ignite your career.