Associate Director managing IT Product Development at Marsh McLennan. Leading security initiatives and collaborating with engineering teams in a hybrid working environment.
Responsibilities
Conduct comprehensive security-focused pull request reviews across multiple applications and technology stacks
Design, develop, and maintain reusable security libraries, frameworks, and boilerplate code for development teams
Establish and enforce secure coding standards through technical guidance and code review processes
Create and maintain security-focused development tools, linters, and automated checks
Review and provide technical input on application architectures from a security perspective
Participate in design reviews and technical discussions to ensure security best practices are embedded from the ground up
Perform threat modeling and security architecture assessments for new and existing applications
Collaborate with engineering teams to design secure, scalable solutions that meet business requirements
Serve as the senior technical member within the Security Champion community across MMC
Mentor and guide other security champions, providing technical expertise and best practice guidance
Lead technical discussions regarding proposed changes to Application Security Standards and guidelines
Act as resident security expert and technical consultant across multiple application portfolios
Actively contribute to secure application development through hands-on coding and technical implementation
Integrate security controls and features into applications (RBAC, authentication, authorization, encryption, etc.)
Develop and maintain security testing frameworks and automated security validation tools
Contribute to the design and implementation of security infrastructure and deployment pipelines
Establish and maintain technical security standards, guidelines, and best practices for development teams
Provide technical guidance on vulnerability assessment, triaging, and remediation approaches
Review and validate security incident remediation, including secrets management and disposal
Ensure alignment with industry standards (OWASP Top 10, SANS Top 25, CWE) and internal security policies
Work closely with development teams, product owners, and architects to integrate security seamlessly into the development process
Serve as technical liaison between development teams and global information security
Provide technical training and knowledge sharing sessions on secure development practices
Communicate complex security concepts clearly to both technical and non-technical stakeholders
Requirements
Bachelor's degree in Computer Science, Engineering, or equivalent technical experience
Overall experience of 14+ years, 7+ years of software development experience with strong engineering fundamentals
Expert-level proficiency in multiple programming languages (JavaScript/TypeScript, Python, Java, C#, etc.)
Deep understanding of modern application architectures, microservices, and cloud platforms (Azure, AWS)
Extensive experience with CI/CD pipelines, DevOps practices, and infrastructure as code
Advanced knowledge of secure coding practices, common vulnerabilities, and security testing methodologies
Advanced expertise in application security principles, practices, and industry standards
Experience with security testing tools (SAST, DAST, IAST, dependency scanning)
Deep understanding of authentication, authorization, cryptography, and secure communication protocols
Knowledge of threat modeling methodologies and security architecture patterns
Experience with security frameworks and compliance requirements (SOC 2, ISO 27001, NYDFS, etc.)
Proven track record of leading technical initiatives and mentoring development teams
Excellent communication skills with ability to influence and educate technical and non-technical audiences
Experience working in distributed, cross-functional teams across multiple time zones
Strong problem-solving skills with ability to balance security requirements with business needs
Benefits
Professional development opportunities
Interesting work
Supportive leaders
Vibrant and inclusive culture
Career opportunities
A range of benefits and rewards to enhance well-being
Senior Director managing US Access Strategy for Sanofi's diabetes medications. Leading a high - impact team to define market access strategies and optimize pricing and reimbursement.
Editorial Director defining and leading storytelling for Hinge, the dating app designed to be deleted. Focus on creating engaging narratives that resonate with users and advance company mission.
Director of Veterinary Quality ensuring veterinary excellence at Banfield Pet Hospital in Colorado markets. Championing quality and overseeing veterinary operations to meet standards.
Executive Underwriter for Zurich E&S, focusing on underwriting excess casualty lines and developing relationships with brokers. Manage new and renewal business to drive profitability and market growth.
Loss Sensitive/Complex Casualty Underwriter role with Zurich focuses on profitable growth and agent relationships. Hybrid work environment with office presence required.
Associate Director leading HR technology operations and supervising scrum teams for effective delivery and innovation at AT&T. Focused on team leadership and strategic collaboration in a fast - evolving environment.
Associate Director managing Patient Assistance Programs at AstraZeneca. Overseeing operations, vendor management, and stakeholder collaboration to enhance access to medications.
Executive Director providing leadership for integrated delivery of social programs in Alberta. Ensuring compliance, operational excellence, and continuous improvement across Alberta's social safety net.
Director leading initiatives to improve client delivery excellence and transformation within our healthcare technology implementation practice. Focusing on operational consistency and strategic methodologies.
Director of Materials leading materials management and supply chain systems in a global climate technologies company. Driving operational excellence and maintaining high service levels for customers across multiple locations.