This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in United States.
This is a senior-level application security role focused on strengthening the security of modern software and AI-enabled applications.
You will establish secure development practices and embed security throughout the software development lifecycle.
The role combines application security engineering, vulnerability management, threat modeling, and secure CI/CD practices.
You will also serve as a technical authority for securing AI and LLM-enabled applications, including RAG and agentic workflows.
Working closely with engineering, product, DevOps, compliance, and incident response teams, you will help turn security requirements into practical solutions.
The position offers significant ownership, influence, and the opportunity to drive long-term security initiatives across the organization.
Success will require strong technical judgment, communication skills, and the ability to operate independently in a complex, fast-paced environment.
Accountabilities
- Define and implement secure software development practices, including secure coding standards, code reviews, and security integration within CI/CD pipelines.
- Lead Shift Left security initiatives and work with software engineering teams to incorporate security requirements early in the development lifecycle.
- Identify, assess, prioritize, and remediate application vulnerabilities using automated security tools and manual testing techniques.
- Serve as the application security subject matter expert, helping developers reproduce vulnerabilities, understand risks, and implement effective mitigation strategies.
- Manage and optimize tools supporting the application security program, including open-source security solutions.
- Develop and lead threat modeling exercises, risk assessments, security audits, vulnerability assessments, and application security reviews.
- Partner with product, engineering, DevOps, compliance, and incident response teams to integrate security controls with business and operational objectives.
- Train and support Security Champions across development teams while promoting a strong culture of security awareness and continuous improvement.
- Establish secure design standards for AI-enabled applications, including LLM integrations, retrieval-augmented generation pipelines, agentic workflows, and model tool-use interfaces.
- Design and validate AI security guardrails covering prompt injection defenses, input and output validation, least-privilege access, rate and cost controls, and data loss prevention.
- Lead AI red-team exercises addressing prompt injection, jailbreaks, sensitive data exposure, insecure outputs, excessive agency, and AI/model supply-chain risks, using frameworks such as OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework.
- Review AI use cases and third-party AI capabilities, assessing providers, data flows, retention practices, application inventories, and requirements for handling nonpublic personal information.
- Establish secure usage standards for AI coding assistants, including human review requirements, scanning of AI-generated code, and controls for secrets and intellectual property.
- Drive application security initiatives through completion and maintain relevant security controls, standards, documentation, and governance processes.
- Support application-related security incidents by collaborating with incident response teams to investigate, contain, and remediate issues.
Requirements
- Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or a related discipline is preferred, or equivalent professional experience.
- At least 5 years of experience as a software developer or in a closely related technical role, with strong application security expertise.
- Strong knowledge of secure software development, application vulnerability management, threat modeling, risk assessment, and security testing.
- Experience integrating security controls into CI/CD pipelines and software development workflows.
- Familiarity with AI and LLM security concepts, including prompt injection, jailbreaks, RAG security, agentic workflows, tool-use risks, and sensitive data protection.
- Experience applying or working with security frameworks such as OWASP, MITRE ATLAS, and NIST AI Risk Management Framework.
- Ability to assess complex security problems, prioritize risks, and develop practical mitigation strategies.
- Strong organizational skills with the ability to manage multiple priorities, initiatives, and deadlines simultaneously.
- Excellent verbal and written communication skills, with the ability to collaborate effectively with technical and non-technical stakeholders.
- Ability to work independently while contributing effectively within cross-functional teams.
- Strong attention to detail and sound professional judgment when handling confidential information and security-sensitive matters.
- Proficiency with Microsoft Office, collaborative cloud platforms, documentation tools, and relevant third-party software applications.
- Ability to work in a fast-paced, metrics-driven environment and adapt to evolving technologies, threats, and business requirements.
- Demonstrated commitment to integrity, collaboration, continuous learning, customer service, and technical excellence.
- Ability to work Monday through Friday primarily from a home environment, with travel of approximately 5% or less.
Benefits
- Targeted salary range of $109,000–$156,000 annually, with compensation determined by factors including experience, education, skills, and geographic location.
- Medical, dental, and vision insurance.
- Life insurance and AD&D coverage.
- Long-term disability insurance.
- 401(k) retirement plan with employer match.
- Remote work environment with a primarily Monday–Friday schedule.
- Opportunity to influence enterprise application security and emerging AI security practices.
- Significant ownership and exposure to strategic and operational security initiatives.
- Collaborative environment focused on learning, innovation, and continuous improvement.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1