Application Security Assurance Associate Director
DTCC
Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.
Pay and Benefits:
- Competitive compensation, including base pay and annual incentive
- Comprehensive health and life insurance and well-being benefits, based on location
- Pension / Retirement benefits
- Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
- DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).
As a member of the CISO organization, this role provides strategic leadership for application security governance across DTCC’s API and agent/MCP platforms. The leader owns the design, delivery, and continuous improvement of platform native AppSec controls—spanning build, deployment, and runtime—ensuring security is embedded through automation, policyascode, and standardized guardrails. By partnering closely with Cloud, Platform, and Application teams, this role enables secure scaling of AI workloads while reducing material risk, improving vulnerability signal quality, and ensuring controls are audit ready, measurable, and aligned to DTCC’s regulatory and risk management expectations.
- Establish and operate API security capabilities. Design, implement, and run API discovery, inventory, assessment, and monitoring capabilities across DTCC applications, aligned to DTCC Control Standards.
- Build MCP‑style security enablement. Develop and maintain model‑driven, context‑aware capabilities (e.g., correlation, orchestration, prioritization) that integrate API, application, and runtime security signals.
- Conduct targeted security assessments. Perform API and application security assessments, risk analysis, and security reviews, identifying design and implementation weaknesses in authentication, authorization, data exposure, and integration patterns.
- Monitor, mitigate, and escalate risk. Track API‑related vulnerabilities and control gaps, validate remediation, and escalate material risk in accordance with DTCC risk and escalation procedures.
- Operate and optimize tooling and platforms. Manage tools, services, and infrastructure supporting API discovery, testing, and analysis; partner with infrastructure, platform, and application teams to ensure effective and reliable use.
- Enable secure integration patterns. Contribute to and maintain API security standards, secure design guidance, and best practices for development teams.
- Continuously evolve detection capabilities. Research emerging API and AI‑driven security techniques and apply them pragmatically to improve detection, signal quality, and reporting.
- Demonstrate strong risk and ethics discipline. Follow established procedures, monitor controls, identify weaknesses, and consistently demonstrate sound judgment and ethical behavior.
Qualifications:
- Minimum of 8 years of related experience
- Bachelor's degree preferred or equivalent experience
Talents Needed for Success:
- Relevant certification, for example CISM, CISSP, Burp Suite Certified Practitioner
- API security expertise. Strong hands‑on experience securing APIs, services, and integrations, including authN/authZ, OAuth/OIDC, schema validation, rate limiting, and data protection.
- Model‑driven and automation mindset. Experience designing or operating model‑driven, context‑aware, or orchestrated security capabilities that improve prioritization and decision‑making.
- Security tooling and platform ownership. Proven experience managing security tools and supporting infrastructure, and integrating them with CI/CD, runtime, and observability platforms.
- Risk assessment and escalation judgment. Ability to evaluate API and integration risk, track remediation, and escalate appropriately within defined governance models.
- Cross‑team coordination. Strong ability to work across application, platform, cloud, and infrastructure teams to drive outcomes without direct authority.
- Secure design influence. Ability to translate API security risks into practical design guidance and standards for engineering teams.
- Continuous learning orientation. Actively tracks API, application, and AI‑enabled security trends and applies them responsibly.
- Integrity and accountability. Demonstrates attention to detail, consistency in following controls, and strong ethical behavior.
DTCC proudly supports Flexible Work Arrangements favoring openness and gives people freedom to do their jobs well, by encouraging diverse opinions and emphasizing teamwork. When you join our team, you’ll have an opportunity to make meaningful contributions at a company that is recognized as a thought leader in both the financial services and technology industries. A DTCC career is more than a good way to earn a living. It’s the chance to make a difference at a company that’s truly one of a kind.
Learn more about Clearance and Settlement by clicking here.
Serves as a dedicated technology resource for advancing DTCC’s business opportunities and providing industry thought leadership for leveraging new technology. The goal of this new department is to partner internally with IT, our business and regulatory divisions and externally with clients, regulators, and fintech vendors, to help build new platforms and business models to advance DTCC’s mission to support the financial markets.
The Information Technology group delivers secure, reliable technology solutions that enable DTCC to be the trusted infrastructure of the global capital markets. The team delivers high-quality information through activities that include development of essential, building infrastructure capabilities to meet client needs and implementing data standards and governance.