7 дней назад
Senior Application Security Engineer (AI)
164 300 - 222 300$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Application Security Engineer (AI): Securing Verisign applications across design, development, testing, and production with an accent on threat modeling, vulnerability management, and AI/LLM application risks. Focus on leading manual and automated assessments, integrating security testing into CI/CD pipelines, and developing guidance for AI-assisted software development.
Location: Reston, Virginia, United States; hybrid work schedule with office presence required
Annual base salary: $164,300–$222,300, plus potential discretionary bonus and eligible stock awards.
Company
provides internet infrastructure services focused on the security, stability, and resiliency of the networked world, including DNS services.
What you will do
- Act as an application security subject matter expert during requirements, design, and architecture phases, including threat modeling.
- Lead manual and automated application vulnerability assessments and provide remediation guidance to engineering teams.
- Manage the application security vulnerability lifecycle across software composition analysis, static and dynamic testing, interactive testing, and secrets scanning.
- Integrate security testing into CI/CD pipelines and review third-party applications against internal security requirements.
- Assess AI and LLM applications for prompt injection, sensitive data exposure, insecure outputs, and over-permissioned integrations.
- Mentor junior engineers, contribute to security standards, and present findings to technical and non-technical audiences.
Requirements
- 10+ years of information technology experience, including hands-on application development.
- 6+ years conducting application security assessments with commercial or open-source tools such as Burp Suite or Fortify.
- Experience with software composition analysis, dynamic application security testing, secrets scanning, and vulnerability management workflows.
- Strong knowledge of the OWASP Testing Framework, OWASP Top 10, software development lifecycles, and modern application architectures.
- Practical familiarity with AI and LLM application security risks and current industry guidance.
- Excellent communication, presentation, leadership, organizational, and independent-working skills.
Nice to have
- 6+ years of software development using Java, C++, Rust, Go, Python, or Perl.
- Experience implementing security assessments in continuous integration pipelines.
- Advanced Linux and command-line experience.
- Knowledge of Agile, DevOps security integration, API security testing, or bug bounty programs.
Culture & Benefits
- Mission-focused, values-driven environment centered on building a more secure internet.
- Dynamic and flexible work environment with opportunities for career growth.
- Competitive benefits and potential performance-based bonus and stock awards.
- Equal employment opportunity and workplace accommodation support.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
Decagon
9 дней назад
Lead Application Security Engineer (AI)
170 000 - 305 000$
BitGo Prime
9 дней назад
Senior Security Application Engineer (AI Security)
200 000 - 235 000$
11 дней назад
Application Security Engineer (AI)
100 000 - 130 000$
12 дней назад
Application Security Engineer (AI)
180 000 - 280 000$
8 часов назад
Senior Security Application Engineer (Web3)
200 000 - 235 000$
7 дней назад
Application Security Architect (AI)
158 050 - 193 325$