5 дней назад
Senior Security Engineer - Secure SDLC (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Security Engineer - Secure SDLC (AI) (Application Security/AI): Building enterprise security guardrails, vulnerability management workflows, and secure AI development controls across the software development lifecycle with an accent on CI/CD governance, application security scanning, and AI risk management. Focus on designing security gates, reducing critical vulnerabilities before production, integrating security tooling, and assessing risks in LLMs, AI agents, and software supply chains.
Location: Remote or office-based in Pennsylvania, United States; US citizenship required due to contractual and access requirements.
Company
is a healthcare and insurance organization building enterprise-scale information security capabilities.
What you will do
- Design and enforce shift-left security guardrails across IDEs, commit workflows, CI/CD pipelines, AI-assisted development, and production delivery.
- Deploy and manage SAST, DAST, dependency, container, secret detection, API security, and AI application security tools.
- Lead risk-based vulnerability triage, remediation SLAs, root cause analysis, and security debt reduction.
- Architect and automate the application security toolchain, including GitLab and JFrog integrations, dashboards, reporting, and policy enforcement.
- Advise engineering and architecture teams on secure coding, threat modeling, AI assistants, LLM integrations, agentic workflows, and software supply chain security.
- Define AppSec and AI security metrics, support audits and compliance activities, and report posture and risk trends to leadership.
Requirements
- US citizenship is required.
- Bachelor's degree in Computer Science, Information Systems, or a closely related field.
- Senior-level information security and systems analysis experience, including security engineering, operating systems, software administration, and risk management.
- Deep proficiency with application security scanning, GitLab security features, JFrog Xray or equivalent, CI/CD security controls, and software supply chain protection.
- Experience with AI security risks and controls, including prompt injection, insecure output handling, excessive agency, model supply chain threats, and sensitive data leakage.
- Proficiency in Python, Go, Bash, or an equivalent scripting or programming language, plus familiarity with Docker, Kubernetes, cloud security, SBOMs, and secure code reviews.
Nice to have
- Experience with STRIDE, PASTA, OWASP SAMM, BSIMM, NIST SSDF, and NIST AI RMF.
- Healthcare or financial services compliance experience, including HIPAA, PCI-DSS, SOC 2, or NIST CSF.
- Prior software development experience and experience with penetration testing, red team exercises, or AI security assessments.
- Master's degree or certifications such as CISSP, Security+, CSSLP, GWEB, GWAPT, OSCP, or AI security certifications.
Culture & Benefits
- Work is listed as remote from Pennsylvania, with the position also designated office-based and requiring a physical work site.
- Travel requirement is 0%–25%.
- Regularly teach and train others and mentor less senior staff.
- Work alongside engineering, architecture, software delivery enablement, ISRM, and risk management teams.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
7 дней назад
Staff Application Security Engineer (Cybersecurity)
8 дней назад
Senior Product Security Engineer
7 дней назад
Application Security Architect (AI)
158 050 - 193 325$
12 дней назад
Application Security Engineer (Cybersecurity)
86 900 - 198 000$
8 дней назад
Application Security / DevSecOps Engineer (AI)
120 000 - 150 000$
Writer
6 дней назад
Staff Security Engineer, Applications (AI)
204 000 - 240 000$