Senior Application Security Engineer (AI Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Application Security Engineer (AI Security): Leading enterprise threat modeling initiatives and building AI-driven security automation solutions with an accent on identifying application security risks and secure-by-design practices. Focus on designing AI/LLM-powered automation, integrating security controls into CI/CD pipelines, and remediating application vulnerabilities.
Location: Hybrid (3 Days Onsite / 2 Days Remote). Must be based in Charlotte, NC, Irving/Las Colinas, TX, or Chandler, AZ
Company
is a professional staffing firm providing specialized talent for enterprise security and engineering roles.
What you will do
- Lead enterprise threat modeling efforts using OWASP methodologies and best practices.
- Analyze and decompose application architectures to identify security risks and mitigation strategies.
- Design and implement AI/LLM-powered security automation solutions.
- Partner with development and architecture teams to improve overall application security posture.
- Integrate security controls into CI/CD pipelines and engineering workflows.
- Develop reusable security standards, reference architectures, and threat modeling frameworks.
Requirements
- 7+ years of Application Security Engineering experience.
- 2+ years of hands-on Threat Modeling experience.
- Experience building AI/LLM-based security solutions for enterprise environments.
- Strong understanding of secure application architecture, API security, authentication, and authorization.
- Experience with cloud security (AWS, Azure, or GCP).
- Must be based in Charlotte, NC, Irving/Las Colinas, TX, or Chandler, AZ
Nice to have
- Experience with DevSecOps, SAST, DAST, SCA, container security, and software supply chain security.
- Background in software engineering or application architecture.
- Experience securing AI-enabled applications and GenAI solutions.
- Python development experience.
- Certifications such as CISSP, CSSLP, CCSP, GIAC GWEB, or GIAC GWAPT.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →