Director, Application Security Engineering (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Director, Application Security Engineering (AI): Strengthening application and agent security across web, mobile, data, and AI-enabled workflows with an accent on secure SDLC practices, developer-friendly guardrails, and risk-based remediation. Focus on operating security tooling, conducting threat modeling, securing CI/CD pipelines, and addressing AI-specific trust, data exposure, prompt, and tool-invocation risks.
Location: Hybrid role with three days per week in the office. Preference is given to candidates near a TKO office in New York City, Stamford, Orlando, Austin, or Las Vegas.
Salary: $142,500–$190,000 annually.
Company
is a sports and entertainment company operating UFC, WWE, PBR, IMG, and On Location.
What you will do
- Own and evolve application security practices across the secure software development lifecycle.
- Configure, tune, and operate SAST, SCA, secret scanning, code scanning, repository protections, and CI/CD security controls.
- Conduct threat modeling and security design reviews for systems, integrations, APIs, and high-risk workflows.
- Review vulnerabilities, validate findings, prioritize risk-based remediation, and improve reporting.
- Develop standards, playbooks, reference architectures, documentation, and developer enablement programs.
- Assess and improve security for AI-assisted development, AI applications, and agentic systems.
Requirements
- 5+ years of hands-on experience in application security, product security, DevSecOps, or related software security roles.
- Experience working directly with engineering teams in fast-moving delivery environments.
- Hands-on experience with SAST, SCA, GitHub, GitHub Advanced Security, SonarQube, Dependabot, or comparable tooling.
- Strong understanding of application and API security, authentication and authorization, secrets, dependencies, injection, deserialization, and data protection.
- Experience with SSDLC, shift-left security, threat modeling, vulnerability management, CI/CD, containers, IaC, and Git-based workflows.
- Ability to provide clear remediation guidance and technical documentation for technical and non-technical audiences.
Nice to have
- Experience securing AI agents, LLM applications, copilots, or agentic workflows.
- Experience with DAST, API security testing, penetration testing, red-team support, or adversarial testing.
- Knowledge of policy-as-code, IaC scanning, container security, SBOMs, provenance, attestation, and secrets management.
- Familiarity with AWS or GCP application-layer security and cloud-native architectures.
- Experience with security metrics, dashboards, regulated environments, or mentoring engineers.
Culture & Benefits
- Hands-on partnership with software engineering, platform, DevOps, architecture, QA, infrastructure, compliance, and security teams.
- Focus on practical, scalable security controls that improve delivery without unnecessary disruption.
- Health care, retirement benefits, vacation, paid time off, and additional company offerings.
- Growth and professional development opportunities, with base compensation and potential short- and long-term incentives.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →