Capital One

SeniorProductManager,AppSec

$209–239k McLean, Virginia, United States FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Senior candidates.

The Brief

“Senior Product Manager, AppSec at Capital One. Skills: Application Security, Product Management, DevSecOps. Drive strategy for Appsec scanning tools. Define vision for Appsec”

What You'll Achieve.

Improve developer experience; Maximize ROI; Maintain best-in-class toolset

Industry & Context.

Problems you'll solve

Systemic patterns; Architectural gaps; Root cause analysis

What They're Looking For.

Must Have

High School Diploma, GED or equivalent certification, At least 6 years of experience in cybersecurity or information technology, At least 3 years of experience translating cybersecurity strategy and analysis into product requirements, At least 3 years of application security experience

Nice to Have

Bachelor's degree in Computer Science, 4+ years in Application or Product Security or Software Engineering with an emphasis on AppSec and vulnerability management strategy, 4+ years of experience managing AppSec products in a large-scale enterprise, 2+ years of experience defining standards for AI-augmented development and ethical AI usage, 2+ years of experience working in cloud-native environments, Knowledge of OWASP Top 10, Knowledge of software supply chain security, Experience with automated DAST, Experience with manual Penetration Testing

What You'll Do.

Drive strategy for Appsec scanning tools

Define vision for Appsec

Define roadmap for Appsec

Define partnership model for Appsec

Serve as bridge between security strategy and technical

Ensure security testing service area provides comprehensive coverage

Meet demands and scale of customers

Own multi-year product roadmap for Application Security

Ensure alignment with enterprise risk appetites

Ensure alignment with evolving threat landscape

Liaise to Security Engineering Enablement and Architecture

Translate security requirements into developer workflows

Lead strategic evaluation of Appsec security tools

Ensure maximization of ROI

Maintain best-in-class toolset

Define product strategy for AI-application security

Define secure integration of AI agents into SDLC

Define prompt engineering guardrails

Define automated remediation pipelines

Evangelize AppSec mission through Office Hours

Evangelize AppSec mission through community

Simplify complex technical risks for executive leadership

Establish governance model for vulnerability disposition

Ensure clear SLAs for vulnerability disposition

Ensure audit trails for vulnerability disposition

Ensure exception workflows for vulnerability disposition

Evaluate customer pain points

Assess customer pain points

Incorporate customer pain points in strategy

Incorporate customer pain points in planning

Incorporate customer pain points in prioritization

How You'll Work.

Team & Collaboration

Liaison to Security Engineering; Liaison to Architecture; Partner with senior engineers; Partner with architects

Communication Scope

Simplify complex technical risks; Executive presentations

Process & Methodology

Roadmap planning, Requirement gathering, Prioritization

Full Job Description

Senior Product Manager, AppSec ## ****The Mission**** As an Application Security Product Manager, you will drive strategy for Appsec scanning tools with a shift left mindset to improve developer experience. You won't just manage tools; you will define the vision, roadmap, and partnership model that allows our engineering teams to innovate at speed without compromising security. You will serve as the bridge between high-level security strategy and technical execution, ensuring that our security testing service area provides comprehensive coverage while meeting the demands and scale of the customers, without compromising trust and accountability. ## ## ## ****Roles and Responsibilities:**** * ****Strategy & Roadmap:** **Own the multi-year product roadmap for Application Security ensuring alignment with enterprise risk appetites and the evolving threat landscape. * ****Engineering Partnership:** **Act as the primary liaison to Security Engineering Enablement and Architecture to translate security requirements into scalable, fix-first developer workflows. * ****Vendor & Capability Evaluation:** **Lead the strategic evaluation of Appsec security tools (e.g., SAST/DAST/SCA), ensuring we maximize ROI and maintain a best-in-class toolset. * ****AI Transformation:** **Define the product strategy for AI-application security, including the secure integration of AI agents into the SDLC, prompt engineering guardrails, and automated remediation pipelines. * ****Stakeholder Management:** **Evangelize the AppSec mission through Office Hours and community forums; simplifying complex technical risks for executive leadership to drive informed decision-making. * ****Operational Governance:** **Establish the governance model for vulnerability disposition (SAST/DAST/OffSec, ensuring clear SLAs, audit trails, and exception workflows that don't hinder velocity. ## ## ## ****What You Will Bring:**** * ****A Strategic Mindset:** **The ability to look past individual vulnerabilities to see sy

Free ATS check

Applying for this Senior Product Manager, AppSec role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Workday

  • Workday has a multi-step form — save your progress after every section.
  • "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
  • Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
  • Job requisition numbers are useful when following up with HR by email.

ANONYMOUS · UNFILTERED

What do employees actually say about Capital One?

Real rants from real employees. Read before you apply.

Read Company Rants →