Grant Thornton logo
Product & Application Security - Associate Director
full-timeDublin

Summary

Location

Dublin

Type

full-time

Explore Jobs

About this role

Associate Director — Product & Application Security (EMEA)

Role Purpose

Lead and scale the Product & Application Security program for our products portfolio across EMEA. Own secure-by-design practices from architecture and threat modeling through DevSecOps in CI/CD, vulnerability management, and coordinated disclosure—enabling developer velocity without compromising risk posture. Align to our System Development & Application Security standards and reference patterns.

Key Outcomes 

  • Establish EMEA-fit Secure SDLC guardrails (requirements → release gating) and publish reference architectures for authentication/authorization, secrets, cryptography, logging, and privacy.

  • Embed DevSecOps controls in pipelines (SAST, SCA, secret scanning, IaC/K8s policy-as-code, SBOM generation, artifact signing and provenance) with measurable pass/fail criteria.

  • Stand up product vulnerability management with SLA tiers, risk-based triage, and executive reporting.

  • Launch an EMEA secure coding enablement track and developer champions program.

  • Demonstrate compliance readiness for GDPR/NIS2 and AI-related controls applicable to product features.

Responsibilities

  • Own AppSec architecture and threat modeling for high-risk services; review designs and third-party components.

  • Define and enforce pipeline security controls; partner with Engineering to shift-left testing and automate gates.

  • Govern SBOM standards and software supply-chain risk (open-source hygiene, provenance, signing).

  • Lead vulnerability management and remediation orchestration across squads; partner with SRE for runtime hardening.

  • Chair the Product Security Review Board for go-live exceptions and risk acceptance.

  • Collaborate with Privacy/Legal on data protection by design; align with GRC on policy and control mapping.

  • Mentor an EMEA AppSec team; provide matrix leadership across GDC and product squads.

Required Qualifications

  • 10+ years in Application/Product Security; 3+ years leading programs at scale.

  • Expertise with OWASP ASVS, threat modeling (STRIDE/ATT&CK), API security, and cloud-native architectures (Azure/AWS).

  • Hands-on with SAST/SCA/DAST, IaC/K8s policy (e.g., OPA), container scanning, and SBOM tooling.

  • Proven stakeholder management with Engineering, Product, and Platform teams.

  • Relevant certifications such as CSSLP, CISSP, or CISM (preferred).

Preferred Qualifications

  • Experience with AI/ML product risks (prompt injection, model supply chain, dataset governance).

  • Familiarity with GDPR, NIS2, and secure disclosure practices.

Key Performance Indicators (KPIs)

  • Builds passing security gates (%).

  • MTTR for critical vulnerabilities.

  • Coverage of threat models and reference patterns.

  • SBOM completeness and policy adherence.

  • Exception trend and closure rate.

#LI-KS1


We are Grant Thornton
Grant Thornton Ireland is rapidly approaching 3,000 people, in 9 offices across Ireland, Isle of Man, Gibraltar and Bermuda. With a presence in over 149 countries around the world and a global network of 73,000 people, we bring our clients the local knowledge, national expertise and global presence to help them succeed – wherever they’re located.

At GT, we work as trusted advisors, bringing local knowledge and national expertise, with a global presence, to help businesses succeed – wherever they are located. We make business more personal by investing in building relationships and empowering our clients to make the right decisions for their organisation now and for the future. Whether that is working with the public sector to build thriving communities, with regulators and financial institutions to build trust, or with a diverse range of businesses to help them achieve their goals, Grant Thornton Ireland work hard to support clients to act on the issues that matter.

At GT Ireland we don’t just predict your future, we build it
A Career at GT
Looking for a more fulfilling role in professional services? One where fresh thinking, collaboration and diversity are valued? At Grant Thornton we do things differently.

What does this mean for you?
A career in a more inclusive working environment, a more collaborative work culture, a more supported, flexible working role, more possibilities to grow and more opportunities to help shape the future for your clients. We respect and value your experience. And we want you to bring your authentic self to work and be at your best. It is how it should be.

Grow with us 
 At Grant Thornton, we care about our people and work hard to make you feel valued. If you are looking to deepen and develop your skills, knowledge, and experience throughout your career, then that is what you will get, and more.

Our Benefits
Please follow this link for information on our generous benefits package.

Equity, diversity and inclusion
At Grant Thornton, we provide equitable opportunities for all our colleagues. We are a responsible, sustainable business where equity, diversity and inclusion (ED&I) is at the forefront of our workplace culture agenda, and today, we continue to build and develop on our existing ED&I structure and strategy to meet our workplace culture needs. People are at the heart of our business and teams built with varied individuals present diverse viewpoints, which need to be heard and valued.

We are all at our best when we are able to be ourselves and we view integrity and authenticity as integral values to bring to our day-to-day work-life at the firm. We are excited to see the personality and perspectives you will bring to our team because we know we will all benefit from them. Diversity of thought, background and experience enables better decision-making, improves the quality of our delivery, and helps us to meet the needs of our clients. Our firm is built on people and their ideas, so we want to hear all the new perspectives and fresh thinking you have to offer. You form the bedrock of our firm’s best-practice principles and we will champion you as leaders from day one.

Reward and benefits
Our reward and benefits are designed to create an environment where our people can flourish. We are committed to building a culture where our people have access to the necessary benefits to help promote a healthy lifestyle and thrive.

Recognition
We want to create a culture of recognition and celebrating success, by saying thank you to people who surpass our expectations and recognising the right values and behaviours. Our Shout Out recognition scheme is our way of highlighting and promoting achievements. Whether you simply want to say thank you, celebrate a special occasion or give an award for doing something exceptional, you can do all of this and more through the scheme.

Other facts

Tech stack
Application Security,Product Security,Threat Modeling,DevSecOps,Vulnerability Management,Secure Coding,GDPR Compliance,Cloud-native Architectures,SAST,SCA,DAST,API Security,Stakeholder Management,Mentoring,Risk Management,Data Protection

About Grant Thornton

In the US, Grant Thornton LLP and Grant Thornton Advisors LLC (and their respective subsidiary entities) practice as an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable law, regulations and professional standards. Grant Thornton LLP is a licensed independent CPA firm that provides attest services to its clients, and Grant Thornton Advisors LLC and its subsidiary entities provide tax and business consulting services to their clients. Grant Thornton Advisors LLC and its subsidiary entities are not licensed CPA firms.

With a unified, local presence across seven countries – including the U.S., Ireland, and others, our platform represents a community of 18,000+ problem solvers, relationship builders, and quality-driven industry specialists. Serving clients across 16 distinct industries, we believe how we serve matters as much as what we do. Learn how we go beyond the expectations of business at GT.com.

Team size: 5,001-10,000 employees
LinkedIn: Visit
Industry: Professional Services
Founding Year: 1924

What you'll do

  • Lead and scale the Product & Application Security program across EMEA, ensuring secure-by-design practices throughout the development lifecycle. Collaborate with various teams to implement security controls and manage vulnerabilities effectively.

Ready to join Grant Thornton?

Take the next step in your career journey

Frequently Asked Questions

What does a Product & Application Security - Associate Director do at Grant Thornton?

As a Product & Application Security - Associate Director at Grant Thornton, you will: lead and scale the Product & Application Security program across EMEA, ensuring secure-by-design practices throughout the development lifecycle. Collaborate with various teams to implement security controls and manage vulnerabilities effectively..

Why join Grant Thornton as a Product & Application Security - Associate Director?

Grant Thornton is a leading Professional Services company.

Is the Product & Application Security - Associate Director position at Grant Thornton remote?

The Product & Application Security - Associate Director position at Grant Thornton is based in Dublin, Leinster, Ireland. Contact the company through Clera for specific work arrangement details.

How do I apply for the Product & Application Security - Associate Director position at Grant Thornton?

You can apply for the Product & Application Security - Associate Director position at Grant Thornton directly through Clera. Click the "Apply Now" button above to start your application. Clera's AI-powered platform will help match your profile with this opportunity and guide you through the application process. You can also learn more about Grant Thornton on their website.