AppSec Jobs
← Back to all jobs

Gartner

Lead Security Engineer

Hybrid
Irving, TXPosted 3 days ago116000 USD - 170000 USDWebsite
Apply on LinkedIn →

At a Glance

8+ years experienceAWSAzureGCPPythonJava

About This Role

The Lead Security Engineer will be responsible for supporting Gartner's AppSec function. This individual will play an integral role in executing daily vulnerability assessments functions; working closely with Information Security partners and technology stakeholders to identify risks/vulnerabilities and collaborate with key stakeholders on remediation, developing and tracking risk/vulnerability remediation and prioritize effort across various business units, partnering to implement security tools, technologies and controls with an appropriate balance of security, business, and user experience, while providing education and training; and engineer automation solutions and/or security tool integrations to assist with day-to-day AppSec responsibilities.

Responsibilities

  • Collaborate with business stakeholders to design secure applications, test applications for security weakness, and partner on remediation of identified issues.
  • Mentor engineers and security champions on practical threat modeling techniques
  • Triage and prioritize security risks, vulnerabilities, and exceptions in alignment with business impact and risk tolerance.
  • Coordinate the orchestration, automation, and management of security technologies and platforms.
  • Own day-to-day life cycle management, including identification, threat assessment, threat modeling and risk avoidance.
  • Create reasonable and actionable reports showing direct impact to the security posture.
  • Define and implement meaningful metrics to measure the effectiveness of security controls through KRIs and security scorecards.
  • Serve as a subject-matter-expert for Application Security; act as a first point of contact for critical issues, security risk assessments and triaging CI/CD issues with Partners and stakeholders.
  • Evaluate business and technical requirements to identify and implement tools, processes, and technologies to improve security posture in environments.
  • Use data to drive prioritization, highlight systemic issues, and influence roadmap decisions

Requirements

DevSecOpsAWSAzureGCPNISTJavaPythonJavaScript
  • 6-8 years of experience in a Security Engineering role
  • Proven experience in DevSecOps, Cloud Security, and Application Security
  • Strong independent critical thinking and problem-solving skills
  • Experience using vulnerability scanning technologies, AST platforms, and cloud security tooling
  • Formal experience with threat modeling
  • Experience leading projects, initiatives, and resources through direct and indirect leadership
  • Deep knowledge of Assessing and prioritization of Risk with ability to think like a bad actor
  • Cloud experience (AWS, Azure, GCP)
  • Infrastructure as Code (IaC) and Policy as Code (PaC) Concepts
  • Proven communication, collaboration, and critical thinking skills
  • Ability to build trusting, meaningful relationships with peers, stakeholders, partners and suppliers
  • Ability to define and communicate risk in a business-relevant language to both non-technical and technical audiences
  • Ability to apply expert knowledge to solve complex business/technical issues strategically
  • Desire for life-long learning and continuous personal/professional development
  • Familiarity with technical security controls, guidelines, and frameworks outlined by standards such as SOC2, ISO 27001/27013, NIST 800-53
  • Ability to automate tasks and code solutions to repetitive problems
  • Scripting or programming experience (Java, .NET, HTML, Ruby, PHP, Perl, C#, Python, JavaScript, PowerShell, Bash)
  • Experience with penetration testing and web application assessment

Benefits & Perks

Competitive compensation
Limitless growth and learning opportunities
Ongoing mentorship and apprenticeship; Leadership courses, development programs, technical courses, certification opportunities
Collaborative and positive culture with diverse team of professionals
Direct impact on strategy
Flexibility of working from home and energy of collaborating in dynamic offices
20+ PTO days plus holidays and floating holidays in first year
Extensive medical, dental insurance and vision plan
401K with corporate match, immediate vesting
Health-and-wellness-related allowance programs
Parental leave
Tuition reimbursement
Employee Stock Purchase Plan
Employee Assistance Program
Gartner Gives Charity Match

About Gartner

Gartner, Inc. is a prominent global research and advisory firm founded in 1979, with a focus on providing insights and consulting services primarily in information technology (IT). Headquartered in Stamford, Connecticut, Gartner operates over 110 offices in more than 100 countries and employs around 16,000 people. The company reported revenue of $4.25 billion and has a market capitalization of approximately $31.48 billion as of April 2025. Gene Hall has been the CEO since 2004. Gartner's core offerings include research and advisory services, featuring impactful reports and market analysis tools like the Magic Quadrant and Hype Cycle. The firm provides consulting on IT strategy, digital business operations, and emerging technologies. Over the years, Gartner has expanded its focus beyond IT into areas such as digital transformation and cloud computing, positioning itself as a leading provider in market research. Its client base includes businesses in the IT sector and organizations seeking strategic guidance.

Industry

information services

Employees

22,000

1317 engineers

Revenue

$6.5B

Website

Visit →

Security at Gartner

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

  • Gartner's AppSec philosophy centers on collaboration and mentorship rather than strict gatekeeping.
  • Their stated mission is to "Collaborate with business stakeholders to design secure applications." They emphasize developer enablement by mentoring engineers and security champions on practical threat modeling.
  • Their risk philosophy is to "Triage and prioritize security risks, vulnerabilities, and exceptions in alignment with business impact and risk tolerance.".

Security Team

The AppSec team at Gartner includes roles such as Lead Security Engineer and Security Engineer (Purple Team). As of June 2026, there are at least two active job postings for these positions. The team seeks individuals with experience in vulnerability scanning, AST platforms, cloud security tooling, and SIEM/XDR for log analysis. Specific information regarding the total team size, reporting lines, and key public-facing leaders is not publicly available.

Key Initiatives

  • Gartner maintains a Security Champions program, where security leaders mentor engineers on threat modeling.
  • Their 'Shift Left' approach involves triaging CI/CD issues with stakeholders and collaborating during the design phase.
  • The vulnerability management process includes daily assessment functions and the development of tracking systems to prioritize remediation efforts across business units.
  • Formal threat modeling is a standard requirement for high-risk services.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.

Interested in this role?

Apply on LinkedIn