Sr. Technical Security Lead, North America
As a Senior Technical Security Lead on our North America Application Security team, you will help shape secure technology solutions from the earliest stages of design through production delivery. You will bring deep application security expertise, secure coding knowledge, and a business enabling mindset to help teams build security in from the start rather than address it after the fact. In this role, you will serve as a trusted advisor across the North America technology footprint, applying broader cybersecurity knowledge across penetration testing, vulnerability scanning, network security, identity and access management, and related domains to identify risk, strengthen controls, and influence sound design decisions. You will also help advance awareness of how AI is emerging in software development and security engineering, and apply that perspective to application security analysis, review, and SDLC decision making. Working closely with application development teams, technology leaders, and line of business CIOs, you will help ensure security is part of the conversation early and often throughout the solutioning and development lifecycle. This partnership will support secure change control, enable stable delivery, and help protect and strengthen the security of Chubb’s application ecosystem as it evolves alongside the business.
In this role, you will
- Lead application security reviews and SDLC engagement with a consultative, business enabling approach
- Apply deep knowledge of secure coding and application security best practices to influence secure design
- Evaluate AI related risks and opportunities as part of application security analysis and review
- Use broader cybersecurity knowledge across penetration testing, vulnerability scanning, network security, identity and access management, and related areas
- Partner with technology teams and line of business CIOs to support secure change control and delivery
- Identify security risks and recommend practical remediation options that balance protection and business needs
- Build trusted relationships with application development teams, business leaders, and executives
- Help ensure security is embedded in decisions affecting design, delivery, and production readiness
- A minimum of 8–10 years of experience in information security roles spanning Application Security, Vulnerability Management, Identity and Access Management, Network Security, Data Security, and/or related disciplines
- Bachelor’s degree required in Information Security, Computer Science, Information Technology, or a related field, or equivalent practical experience
- Apply deep security architecture expertise to review complex architectures, changes, and risk scenarios and make sound recommendations
- Demonstrate hands-on technical experience across network security, firewalls, DNS, Windows and Linux administration, cloud security, Active Directory, vulnerability management, secure ports and protocols, encryption, 3-tier architecture, database security, zero trust, third-party reviews, and data loss prevention
- Interpret and apply information security standards and frameworks such as ISO/IEC 27001/27002, PCI-DSS, and the NIST Cybersecurity Framework
- Communicate clearly with technical and non-technical stakeholders, including business leaders, project teams, and technical partners
- Manage project lifecycles across Agile, Waterfall, and CI/CD environments while staying self-directed, accountable, and able to escalate risks appropriately
- Collaborate effectively across priorities and leverage AI to improve security governance, automation, and review efficiency