Capital One
SeniorProductManager,AppSec
Neural analysis suggests this role is
optimal for Senior candidates.
“Senior Product Manager, AppSec at Capital One. Skills: Application Security, Product Management, DevSecOps. Drive strategy for Appsec scanning tools. Define vision for Appsec”
What You'll Achieve.
Improve developer experience; Maximize ROI; Maintain best-in-class toolset
Industry & Context.
Systemic patterns; Architectural gaps; Root cause analysis
What They're Looking For.
Must Have
High School Diploma, GED or equivalent certification, At least 6 years of experience in cybersecurity or information technology, At least 3 years of experience translating cybersecurity strategy and analysis into product requirements, At least 3 years of application security experience
Nice to Have
Bachelor's degree in Computer Science, 4+ years in Application or Product Security or Software Engineering with an emphasis on AppSec and vulnerability management strategy, 4+ years of experience managing AppSec products in a large-scale enterprise, 2+ years of experience defining standards for AI-augmented development and ethical AI usage, 2+ years of experience working in cloud-native environments, Knowledge of OWASP Top 10, Knowledge of software supply chain security, Experience with automated DAST, Experience with manual Penetration Testing
What You'll Do.
Drive strategy for Appsec scanning tools
Define vision for Appsec
Define roadmap for Appsec
Define partnership model for Appsec
Serve as bridge between security strategy and technical
Ensure security testing service area provides comprehensive coverage
Meet demands and scale of customers
Own multi-year product roadmap for Application Security
Ensure alignment with enterprise risk appetites
Ensure alignment with evolving threat landscape
Liaise to Security Engineering Enablement and Architecture
Translate security requirements into developer workflows
Lead strategic evaluation of Appsec security tools
Ensure maximization of ROI
Maintain best-in-class toolset
Define product strategy for AI-application security
Define secure integration of AI agents into SDLC
Define prompt engineering guardrails
Define automated remediation pipelines
Evangelize AppSec mission through Office Hours
Evangelize AppSec mission through community
Simplify complex technical risks for executive leadership
Establish governance model for vulnerability disposition
Ensure clear SLAs for vulnerability disposition
Ensure audit trails for vulnerability disposition
Ensure exception workflows for vulnerability disposition
Evaluate customer pain points
Assess customer pain points
Incorporate customer pain points in strategy
Incorporate customer pain points in planning
Incorporate customer pain points in prioritization
How You'll Work.
Team & Collaboration
Liaison to Security Engineering; Liaison to Architecture; Partner with senior engineers; Partner with architects
Communication Scope
Simplify complex technical risks; Executive presentations
Process & Methodology
Roadmap planning, Requirement gathering, Prioritization
Full Job Description
Senior Product Manager, AppSec ## ****The Mission**** As an Application Security Product Manager, you will drive strategy for Appsec scanning tools with a shift left mindset to improve developer experience. You won't just manage tools; you will define the vision, roadmap, and partnership model that allows our engineering teams to innovate at speed without compromising security. You will serve as the bridge between high-level security strategy and technical execution, ensuring that our security testing service area provides comprehensive coverage while meeting the demands and scale of the customers, without compromising trust and accountability. ## ## ## ****Roles and Responsibilities:**** * ****Strategy & Roadmap:** **Own the multi-year product roadmap for Application Security ensuring alignment with enterprise risk appetites and the evolving threat landscape. * ****Engineering Partnership:** **Act as the primary liaison to Security Engineering Enablement and Architecture to translate security requirements into scalable, fix-first developer workflows. * ****Vendor & Capability Evaluation:** **Lead the strategic evaluation of Appsec security tools (e.g., SAST/DAST/SCA), ensuring we maximize ROI and maintain a best-in-class toolset. * ****AI Transformation:** **Define the product strategy for AI-application security, including the secure integration of AI agents into the SDLC, prompt engineering guardrails, and automated remediation pipelines. * ****Stakeholder Management:** **Evangelize the AppSec mission through Office Hours and community forums; simplifying complex technical risks for executive leadership to drive informed decision-making. * ****Operational Governance:** **Establish the governance model for vulnerability disposition (SAST/DAST/OffSec, ensuring clear SLAs, audit trails, and exception workflows that don't hinder velocity. ## ## ## ****What You Will Bring:**** * ****A Strategic Mindset:** **The ability to look past individual vulnerabilities to see sy
Applying for this Senior Product Manager, AppSec role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Workday
- Workday has a multi-step form — save your progress after every section.
- "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
- Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
- Job requisition numbers are useful when following up with HR by email.
ANONYMOUS · UNFILTERED
What do employees actually say about Capital One?
Real rants from real employees. Read before you apply.