Gartner
Gartner
Gartner is a global research and advisory firm that helps enterprise leaders make informed decisions on mission-critical priorities. Its work combines expert analysis, consulting, executive guidance, research, and digital market services across areas such as technology, finance, human resources, legal, marketing, sales, and product strategy. Gartner also organizes more than 40 conferences and advises organizations on improving technology investments. Teams work within a hybrid model designed to support collaboration across a diverse, international workforce, with career opportunities spanning client services, consulting, research, advisory, technology, and corporate functions.

Lead Application Security Engineer - Gartner (Hybrid)

Lead application security engineering at Gartner across applications and cloud environments. Drive vulnerability management, threat modeling, automation, and security controls across business units.

Description

  • Support Gartner’s application security program
  • Conduct daily vulnerability assessments
  • Work with Information Security and technology stakeholders to identify risks and vulnerabilities
  • Coordinate remediation and prioritize security efforts across business units
  • Help deploy security tools, technologies, and controls
  • Deliver security education and training
  • Develop automation solutions and integrate security tools
  • Work with business stakeholders to design secure applications
  • Assess applications for security weaknesses and support remediation
  • Mentor engineers and security champions in threat modeling
  • Triage and prioritize security risks, vulnerabilities, and exceptions
  • Coordinate the orchestration, automation, and administration of security platforms
  • Manage the vulnerability lifecycle from identification and threat assessment through modeling and risk avoidance
  • Produce actionable reports on the organization’s security posture
  • Establish metrics, key risk indicators, and security scorecards
  • Act as the application security subject-matter expert and primary contact for critical issues, risk assessments, and CI/CD concerns
  • Assess requirements and implement improvements to security tools, processes, and technologies
  • Use data to set priorities, identify systemic issues, and guide roadmap decisions

Requirements

  • 6–8 years of experience in security engineering
  • Demonstrated expertise in DevSecOps, cloud security, and application security
  • Strong independent judgment, critical thinking, and problem-solving ability
  • Experience with vulnerability scanners, application security testing platforms, and cloud security tools
  • Professional experience conducting threat modeling
  • Experience leading projects, initiatives, and resources through direct and indirect leadership
  • Advanced understanding of risk assessment and prioritization
  • Cloud security experience with AWS, Azure, or GCP
  • Understanding of Infrastructure as Code and Policy as Code principles
  • Familiarity with security controls, guidance, and frameworks including SOC 2, ISO 27001/27013, and NIST 800-53
  • Ability to automate workflows and develop code-based solutions
  • Scripting or programming experience in Java, .NET, HTML, Ruby, PHP, Perl, C#, Python, JavaScript, PowerShell, or Bash
  • Experience with penetration testing and web application security assessments
  • Strong communication, collaboration, and analytical skills
  • Ability to establish effective relationships with colleagues, stakeholders, partners, and suppliers
  • Ability to explain risk in business-relevant terms to technical and non-technical audiences
  • Ability to apply expert knowledge to complex technical and business challenges
  • Commitment to continuous learning and professional development

Benefits

  • Competitive compensation package
  • Broad opportunities for growth and learning
  • Ongoing mentorship and apprenticeship support
  • Leadership, development, technical training, and certification opportunities
  • Collaborative and supportive workplace culture
  • Flexible work-from-home options alongside collaboration in dynamic offices
  • More than 20 paid time-off days, holidays, and floating holidays during the first year
  • Comprehensive medical, dental, and vision coverage
  • 401(k) plan with company matching and immediate vesting
  • Health and wellness allowance programs
  • Parental leave
  • Tuition reimbursement
  • Employee Stock Purchase Plan
  • Employee Assistance Program
  • Gartner Gives charity matching
  • 401(k) matching of up to $7,200 annually
  • Ability to purchase company stock at a discount

Related Jobs

Ramp

Senior Analyst, Employee Lifecycle Data (Workday) at Ramp – New York Hybrid

Ramp

Own Workday employee lifecycle data for Ramp, including HRIS transactions, bulk updates, reconciliations, audits, and data quality controls. Partner across HRIS, Payroll, Benefits, Global Mobility, and vendors to maintain accurate, scalable processes.

Open
Marigold

Senior Full-Stack Software Engineer – Australia Remote

Marigold

Join Marigold as a senior engineer working on Campaign Monitor marketing technology across microservices, web applications, event streaming, and AWS infrastructure. Influence architecture and code quality within autonomous product teams.

Open
Rosendahl Nextrom GmbH

Physical AI Research Engineer – Hybrid in Austria

Rosendahl Nextrom GmbH
501 – 1,000 Employees
AutomotiveConsultingLogistics

Develop robot-learning systems for Rosendahl Nextrom’s industrial production technologies, spanning perception, reinforcement learning, and adaptive robotics. Apply foundation models and sim-to-real methods to help robots learn and operate flexibly in real-world environments.

Open
Cisco

AI Researcher, Large Language Models and Agentic AI

Cisco

Advance Cisco’s AI research across scalable models, agentic systems, and production infrastructure. Publish research and improve enterprise and security-focused AI applications.

Open