台北市中山區8年以上專科以上
【About the role】
Hytech is seeking a forward-thinking Manager of Software Security Architecture to lead the strategy, development, and execution of a world-class application security program. This highly technical leadership role will define the vision for embedding security throughout the software development lifecycle (SDLC), including modern AI and machine learning platforms. The ideal candidate will have deep expertise in secure software development, application security engineering, CI/CD automation, and integrating security into traditional, cloud-native, and AI-enabled environments. You will lead a global team of security engineers, build scalable developer-focused security solutions, and shape security strategies across engineering, infrastructure, DevOps, and data science teams.
What this job involves:
[Program Ownership & Strategy]:
1. Own and advance the enterprise application security program, including vision, technical strategy, and execution.
2. Define and implement scalable, modern AppSec practices for cloud-native and AI-enabled development.
3. Represent application security in enterprise architecture, risk, and compliance initiatives.
4. Define KPIs to measure security posture and program effectiveness.
[Leadership & Collaboration]:
1. Lead, mentor, and grow a global team of application security engineers and specialists.
2. Promote a proactive “shift-left” culture by embedding security throughout the SDLC.
3. Partner with development, DevOps, AI/ML, and product teams to integrate secure practices into software and data science workflows.
4. Build strong cross-functional relationships to drive security-first thinking and align investments with business value.
[Security Tooling & Technical Implementation]:
1. Drive adoption and optimization of security tools (SAST, DAST, SCA, IAST, secrets scanning, etc.) in CI/CD workflows.
2. Design and deploy developer-friendly tools for threat modeling, code scanning, secrets detection, and dependency analysis.
3. Implement internal secure-by-default frameworks and reference architectures.
[AI/ML Security]:
1. Collaborate with AI/ML teams to implement secure design patterns for model development, training pipelines, and service deployment.
2. Develop and enforce security controls for AI applications, including data integrity, robustness, governance, and prompt injection prevention.
3. Evaluate and integrate emerging tools for securing ML pipelines, generative AI models, and AI APIs.
[Security Enablement, Education & Documentation]:
1. Build scalable security enablement programs, including secure coding workshops, bootcamps, and self-service resources/platforms.
2. Develop and maintain internal security documentation, policies, and standards.
[Research & Continuous Improvement]:
1. Stay current on application security threats, AI security research, and best practices in cloud and software engineering.