Cybersecurity Application Security Engineer (AI/LLM Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Hybrid in Centennial, Colorado; candidates must live within 30 miles of an office and work in the office three days per week. The position requires United States citizenship and existing authorization to work in the United States. Visa sponsorship is not available.
Salary: $90,000–$125,000 annually, depending on experience.
Company
is a diversified company providing student loan servicing, professional services, consumer lending, payment processing, renewable energy solutions, and K-12 and higher education services.
What you will do
- Perform manual source code reviews and web, mobile, and application security testing.
- Use SAST, SCA, DAST, container scanning, secrets detection, and related security tooling.
- Develop automated source code review processes and integrate security checks into CI/CD pipelines.
- Expand the Security Champions program and help product teams implement secure SDLC practices.
- Assess and communicate vulnerabilities, risks, and urgency to engineering teams and management.
- Secure AI/LLM-integrated features through threat modeling and assessment of emerging attack surfaces.
Requirements
- 2–4 years of hands-on application security experience.
- Strong manual code review experience in at least one major language such as Java, JavaScript/TypeScript, C#, or PHP.
- Experience with OWASP Top 10, web testing methodologies, threat modeling, and web/API security.
- Experience integrating security tooling and automated checks into CI/CD pipelines.
- Scripting and automation skills with Python, Bash, or Node.
- United States citizenship, existing US work authorization, and ability to work hybrid within 30 miles of an office are required.
Nice to have
- Experience with AI or LLM-integrated applications, model security, or prompt safety.
- Mobile security, reverse engineering, or platform-specific secure coding experience.
- Certifications such as OSWE, OSCP, GWAPT, GCSA, GCPN, or ML security certifications.
- Experience mentoring junior developers or engineers in secure design and coding practices.
Culture & Benefits
- Hybrid work environment with remote work available for part of the week.
- Medical, dental, vision, HSA, and FSA benefits.
- Earned time off, 401(k), student loan repayment, life insurance, and disability coverage.
- Tuition reimbursement, employee stock purchase program, wellness program, and performance-based incentive pay.
- Respectful and inclusive workplace with reasonable accommodation support.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →