SECTION I · THE BRIEF
Brief #69034Updated 22 SEP 2026REMOTE-USAWorkdaySOFTWARE COMPANIES
Employbl Company Profile

Director, Application Security

Dotloop is the leading online transaction and productivity optimization platform in real estate. Dotloop reduces complexity by replacing separate form creation, e-sign, and transaction management systems with a single…

Location
Remote-USA
Company size
50–200
Posted
Yesterday
Via
Workday
Section II · Full ProfileFree with an account
  • 01Comp band & equity packageLocked
  • 02Seniority & experience requirementsLocked
  • 03Interview process & rubricLocked
  • 04Hiring manager & team contextLocked
  • 05Growth trajectory in this roleLocked
  • 06Offer & decision timelineLocked

Free account · no card · 2 minutes

Director, Application Security

Dotloop· Remote-USAView company profile


Job title
Director, Application Security
Job location
Remote-USA
Job description

About the team

Zillow’s Information Security team is the engineering-first security organization at the heart of one of the most-visited real estate platforms in the United States. We protect a product ecosystem that drives real estate transactions, safeguards the personal and financial data of millions of customers, and powers a marketplace that is reimagining what it means to come home.

We operate like a product engineering team- we build, automate, and ship. Our security engineers are embedded partners to the product and platform organizations, not gatekeepers. We move fast, we prefer paved roads over guard rails, and we treat security as a feature of the product rather than a tax on it. Our work spans cloud-native infrastructure at scale, a high-velocity application development lifecycle, real-time threat detection and response, and a threat intelligence program that informs both defensive and product risk decisions across the company.

This is a team where technical credibility matters. Our leaders write strategy documents and review detection logic and SDLC security controls. If you’ve spent your career building things - secure software, detection pipelines, AppSec programs, zero trust architectures -this is the kind of organization you’ve been building toward.

About the role

As Director of Information Security, drive the strategy, execution, and maturity Application Security, and Security Architecture and our India Security Team. This is an M5 leadership role that reports directly to the VP, Information Security , and carries significant accountability for the security posture, talent, and engineering culture of a large, multi-function organization.


We are looking for a builder, someone who has led application security organizations inside high-growth technology companies where engineering velocity is a first-class value. You have a background that started in software engineering or security engineering, and you’ve never fully left it behind. You are the leader who can earn trust with a senior engineers and peers, recruit principal-level security engineers, and then go present business risk.


You will manage a team of managers and senior individual contributors across your four domains, partnering deeply with Platform Engineering, Product, Legal, Privacy, and Compliance. You will set multi-year technical roadmaps, own the operational budget and tooling strategy for your org, and serve as a key voice in defining the company’s overall security risk posture and investment priorities.


Responsibilities

Leadership & Organizational Strategy

  • Lead and develop a multi-manager organization across Application Security, and Security Architecture, setting clear direction, healthy team culture, and high-performance expectations at every level.
  • Establish and execute a 2–3-year strategic roadmap for your domains that is tightly coupled to Zillow’s product and platform engineering priorities, not just industry compliance frameworks.
  • Own workforce planning, org design, talent acquisition, and the development of a bench of future security leaders—with a specific focus on recruiting and retaining engineers who want to build, not just advise.
  • Manage budget, tooling portfolio, and vendor relationships across your scope, with a bias toward consolidation, automation ROI, and eliminating tool sprawl.
  • Represent Application Security at the executive and leadership level; translate complex technical risk into business impact for the VP

Application Security

  • Lead an AppSec organization that partners with product engineering rather than policing it—building “paved road” security capabilities embedded in CI/CD pipelines, frameworks, and developer tooling.
  • Drive a developer-first security culture: create security enablement programs, secure coding training, and internal tooling that make the secure path the easy path for Zillow’s engineers.
  • Ensure comprehensive coverage of Zillow’s application portfolio including secure design review, DAST/SAST integration, dependency management, and API security.
  • Own product security strategy, ensuring that security is a design-time consideration in new product features, not an audit checkpoint at the end of the SDLC.
  • Build and maintain a vulnerability management program with clear SLAs, risk-based prioritization, and executive-facing reporting.

Security Architecture

  • Partner with the  Security Architecture function to establish and maintain enterprise security patterns, reference architectures, and guardrails for Zillow’s cloud-native, AWS-centric infrastructure.
  • Drive Zero Trust principles and identity-driven access across the environment, working with Platform Engineering to embed security patterns into infrastructure-as-code and platform primitives.
  • Ensure security architecture is a proactive partner in platform and product design reviews, providing clear, opinionated guidance that accelerates rather than slows engineering delivery.
  • Maintain a forward-looking architecture posture: evaluate emerging threats and technology shifts (e.g., AI/ML-driven attack surfaces, cloud configuration risk) and evolve controls accordingly.

This role has been categorized as a Remote position. “Remote” employees do not have a permanent corporate office workplace and, instead, work from a physical location of their choice, which must be identified to the Company. U.S. employees may live in any of the 50 United States, with limited exceptions.

In California, Connecticut, Maryland, Massachusetts, New Jersey, New York, Washington state, and Washington DC the standard base pay range for this role is $220,200.00 - $351,800.00 annually. This base pay range is specific to these locations and may not be applicable to other locations. In Colorado, Hawaii, Illinois, Maine, Minnesota, Nevada, Ohio, Rhode Island, Vermont, and Virginia the standard base pay range for this role is $209,200.00 - $334,200.00 annually. The base pay range is specific to these locations and may not be applicable to other locations.

In addition to a competitive base salary this position is also eligible for equity awards based on factors such as experience, performance and location. Actual amounts will vary depending on experience, performance and location. Employees in this role will not be paid below the salary threshold for exempt employees in the state where they reside.

Who you are

  • 12+ years of progressive security experience, with at least 5 years in leadership roles managing managers and multi-functional security teams; prior experience in a high-growth consumer technology or fintech company is strongly preferred.
  • Roots in security engineering, software development, or platform engineering—you have built things, not just governed them, and your technical instincts remain sharp enough to engage credibly with principal engineers and architects.
  • Demonstrated experience owning multiple security domains simultaneously (e.g., SOC/detection, AppSec, architecture) with the organizational maturity to drive excellence across each without personally bottlenecking any of them.
  • Proven track record in Application Security leadership at scale—specifically, building AppSec programs that integrate natively into SDLC, CI/CD, and developer workflows inside technology-forward organizations.
  • Deep expertise in multi  cloud security (AWS preferred), including IaC security (Terraform/CloudFormation), Kubernetes/container security, and Zero Trust architecture patterns.
  • Strong detection engineering mindset: experience moving a SOC from alert triage to custom detection pipelines, SOAR automation, and threat-model-driven coverage.
  • Ability to quantify and communicate security risk in business and financial terms; experience presenting to executive leadership and, ideally, board-level audiences.
  • Talent magnet: a reputation for hiring and developing elite security engineers, with the technical credibility to attract senior ICs who could work anywhere.
  • Familiarity with the modern security tooling ecosystem: SIEM, SOAR, DLP,EDR, EPM,   CSPM/CWPP ,SaST /DaST. IAC, and container security - with the judgment to rationalize and consolidate rather than accumulate.
  • Proficiency in at least one scripting or programming language (Python, Go, or similar); sufficient to review automation, detection logic, and security tooling code written by your team.

Get to know us

At Zillow, we’re reimagining how people move—through the real estate market and through their careers. As the most-visited real estate platform in the U.S., we help people navigate buying, selling, financing and renting with greater ease and confidence. Whether you're working in tech, sales, operations, or design, you’ll be part of a company reshaping an industry and helping more people make home a reality.


How we work is a key part of that transformation. Through Cloud HQ, our strategic approach to distributed work, most employees have the flexibility to work from wherever they’re most productive—enabling us to move fast, stay connected and deliver on our people promise. 


Zillow is honored to be recognized among the best workplaces in the U.S. Zillow was named one of FORTUNE 100 Best Companies to Work For® in 2026, and included on TIME’s America’s Best Companies 2026 list, reflecting our commitment to creating an innovative, inclusive, and engaging culture where employees are empowered to grow.


No matter where you sit in the organization, your work will help drive innovation, support our customers, and move the industry—and your career—forward, together.


Zillow Group is an equal opportunity employer committed to fostering an inclusive, innovative environment with the best employees. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. If you have a disability or special need that requires accommodation, please contact your recruiter directly.


Qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable state and local law.


Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

View job listing ↗
The Saturday Briefing

Get the Saturday tech briefing

New company profiles, funding moves, and who’s hiring across the market — every Saturday morning.

Dotloop headquarters

Cincinnati, OH

Company size

50200 employees

Founded

2008

Total raised

$9,100,000

View company profile ↗

Funding rounds