Own the Application Security product strategy and multi-quarter roadmap-from visibility and tooling inventory, through architecture and risk-surface mapping, tool procurement and upgrades, CI/CD enforcement, proactive threat reduction, and scaled institutionalization (Security Champions, architecture review, executive reporting). Deep working knowledge of modern AppSec practices and tooling (SAST, DAST, SCA, container/IaC/secrets scanning, vulnerability management, threat modeling, API security, and secure SDLC).