01Responsibilities
Guide, mentor, and align Portfolio Security Leads (PSLs) and Security Champions in the ATHIP division, ensuring AppSec policies and standards are upheld.Serve as the primary AppSec SME for ATHIP, providing expert guidance, incident support, and escalation for security issues.Ensure continuous threat modeling, scanning, regular security reviews, and timely vulnerability remediation across ATHIP portfolios.Oversee training activities as part of mentoring PSLs and Security Champions, and ensure PSLs and Champions are enabled and empowered.Provide quarterly AppSec briefings to the ATHIP CTO and prepare monthly AppSec reports. Collaborate with Global Information Security (GIS) to support NIST attestation, incident management and exception filing.Collaborate with the DevSecOps CoE in driving integration of security controls in CI/CD pipelines (SAST, SCA, DAST, container scanning, IaC checks) to track provenance and protect the integrity of software.Validate and enforce ASVS-based security requirements across ATHIP services and applications.Nominate, assess, and guide PSLs and Security Champions; provide fallback if PSLs/Champions are unavailable.Collaborate with product managers, architects, Privacy Champions, and other CoEs to balance security and privacy requirements.Participate in and drive certain AppSec CoE strategic programs, including AppSec Metrics & Resources, AppSec Tools Deployment, ASVS Gap Assessment & Remediation, and SBOM/Supply Chain Management.Contribute to the AppSec CoEs mission and align with its goals to equip teams with standards, tools, and training to identify and fix security issues early and efficiently.
Job Qualifications:
Bachelors degree.GIAC GSEC, CISSP, or an equivalent baseline certification and one vendor-neutral Secure SDLC/AppSec certification (e.g., CSSLP) (preferred).12+ years of experience in application/product security, software engineering, or related roles.Demonstrated success leading cross-functional security initiatives and improving operational workflows.In case of an internal candidate, familiarity with Wolters Kluwer security policies and standards is required, and familiarity with ATHIP products is preferred.Experience managing or indirectly influencing others in a matrixed or project-based environment.Proficiency in one or more modern programming languages (Java, Python, C#, JavaScript).Hands-on experience with security testing tools (SAST, SCA, DAST, IaC scanning, container/runtime scanning).Experience embedding security checks in CI/CD (GitHub Actions, GitLab CI, Jenkins, Azure DevOps, Bitbucket etc.).Understanding of security facilities and capabilities in at least one major cloud provider (AWS, Azure, GCP).Strong business acumen with understanding of secure product strategy.Ability to translate strategic direction into actionable operational execution.Highly organized with strong attention to detail and process discipline.Effective communicator, able to influence across functions and seniority levels.Demonstrated ability to manage competing priorities in a fast-paced, matrixed .