Job#: 3039198 Job Description: AppSec OSS Sr. Program Manager
Location: Lone Tree, CO, Phoenix, AZ, or Southlake, TX (Hybrid)
Role Overview
We are seeking a seasoned Sr. Program Manager to lead complex, cross-functional cybersecurity initiatives focused on Application Security (AppSec), Software Supply Chain Security, and DevSecOps. This role will drive execution across Product, Architecture, Engineering, Security, and Operations teams while delivering scalable governance, risk reduction, and compliance outcomes.
Core Responsibilities
- Lead multiple enterprise Open-Source Software (OSS) and software supply chain security initiatives.
- Drive end-to-end execution across dependency governance, SCA governance, production enforcement, and CI/CD security controls.
- Coordinate across Product, Engineering, Architecture, AppSec, and Infrastructure teams to ensure delivery alignment.
- Manage program governance including roadmap tracking, RAID management, executive reporting, and dependency coordination.
- Partner with engineering teams to operationalize policy-driven security controls and scalable enforcement mechanisms.
- Translate technical initiatives into business-focused outcomes tied to risk reduction and audit readiness.
- Drive Organizational Change Management (OCM) strategy to support adoption of OSS controls, including stakeholder engagement, communication planning, and rollout enablement across engineering teams.
- Lead change readiness, training, and adoption efforts to ensure successful implementation of new governance, enforcement, and developer workflow changes.
Executive Communication & Governance
- Present concise program updates to senior leadership and governance forums.
- Elevate risks, blockers, compliance concerns, and execution gaps proactively.
- Drive decision-making and cross-functional alignment across distributed teams.
- Develop clear, executive-level narratives around software supply chain risk and governance maturity.
- Establish and execute communication strategies to drive alignment, awareness, and sustained adoption of OSS security initiatives across leadership and engineering stakeholders.
Preferred Experience
- Experience leading AppSec, DevSecOps, OSS governance, or software supply chain programs at enterprise scale.
- Understanding of OSS ecosystems, SCA governance, dependency management, and software supply chain risk.
- Familiarity with tools such as Black Duck, Artifactory, Nexus, ProGet, SBOM platforms, or similar technologies.
- Experience with CI/CD-integrated security controls, policy enforcement, and audit/compliance programs.
- Stakeholder management and ability to influence without direct authority.
- Financial services or other regulated industry experience is preferred.
- Experience driving Organizational Change Management (OCM), including large-scale technology adoption, behavioral change, and cross-functional transformation initiatives, is highly preferred.
Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.
Everforth Apex uses a virtual recruiter as part of the application process. Click for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at
Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Everforth Apex team member can provide.
Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.
If you require an accommodation under the Americans with Disabilities Act to participate in an interview with a virtual recruiter or to use our website for a search or application, please contact our Benefits Department at or . Please note that this contact information is strictly to be used for medical ADA accommodations and that no other inquiries will be answered.
UnitedHealthcare creates and publishes the Transparency in Coverage Machine-Readable Files on behalf of Everforth Apex Systems.