Senior Application Security Engineer
Summary
This role involves leading application security strategy with a focus on securing AI and LLM-enabled technologies. The engineer will establish secure development standards, perform threat modeling, and conduct AI red teaming to protect against emerging threats.
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in the United States.
This remote role offers the opportunity to shape application security strategy across traditional software and emerging AI-enabled technologies.
You will establish secure development standards, strengthen CI/CD security, and embed protection throughout the software development lifecycle.
The role combines application security engineering, vulnerability management, threat modeling, and hands-on testing with strategic security leadership.
A major focus will be securing AI and LLM applications, including RAG pipelines, agentic workflows, and model tool-use interfaces.
You will lead AI red teaming and help establish practical guardrails against prompt injection, data exposure, excessive agency, and other emerging threats.
Working closely with engineering, DevOps, product, compliance, and incident response teams, you will translate security risks into actionable solutions.
This is a high-impact opportunity for an experienced security professional to influence secure-by-design practices across a technology-driven organization.
Accountabilities:
- Define and implement secure software development practices, including secure coding standards, code reviews, and security integration within CI/CD pipelines.
- Lead Shift Left security initiatives, embedding application security requirements and testing earlier in the development lifecycle.
- Identify, assess, prioritize, and help remediate application vulnerabilities through automated scanning, manual testing, and vulnerability management processes.
- Serve as the application security Subject Matter Expert, helping development teams reproduce vulnerabilities, understand risk, and implement effective mitigations.
- Train and collaborate with Security Champions across software engineering teams to strengthen application security awareness and capabilities.
- Operate, maintain, and continuously optimize tools supporting the Application Security program, including open-source security solutions.
- Lead threat modeling exercises and risk assessments for new and existing applications, translating findings into practical security controls.
- Partner with product and development teams during planning and requirements phases to define security requirements and secure application architectures.
- Conduct security audits and vulnerability assessments while maintaining appropriate security controls, documentation, and evidence.
- Collaborate with engineering, DevOps, compliance, and other stakeholders to align security practices with business and technology objectives.
- Partner with incident response teams to investigate, contain, and remediate application-related security incidents.
- Drive long-term application security initiatives from planning through successful completion.
- Define secure design patterns and secure-by-default requirements for AI-enabled applications, including LLM integrations, RAG pipelines, agentic workflows, and model tool-use interfaces.
- Design and validate AI security guardrails covering prompt injection defenses, input/output validation, least-privilege access, rate and cost controls, and data loss prevention.
- Lead adversarial testing and AI red team exercises covering prompt injection, jailbreaks, sensitive data disclosure, insecure outputs, excessive agency, and model or plugin supply-chain risks.
- Map AI security findings and controls to recognized frameworks such as OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework.
- Review new AI use cases and third-party AI capabilities, assessing providers, data flows, retention practices, and application security risks.
- Establish and enforce requirements for protecting nonpublic personal information (NPI) within AI systems.
- Develop secure usage standards for AI coding assistants, including human review requirements, security scanning, and controls against exposure of secrets or intellectual property.
- Stay current on emerging application and AI security threats and promote a culture of continuous security improvement.
- Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or a related field is preferred; equivalent experience may be considered.
- At least 5 years of experience as a software developer or in a similar technical role.
- Strong understanding of application security principles, secure software development, vulnerability management, threat modeling, and risk assessment.
- Experience identifying and remediating application vulnerabilities through automated security tools and manual testing.
- Demonstrated ability to integrate security controls and testing into CI/CD pipelines and development workflows.
- Knowledge of AI and LLM security concepts, including prompt injection, jailbreaks, sensitive data exposure, insecure output handling, excessive agency, and AI supply-chain risks.
- Familiarity with AI security and risk frameworks such as OWASP Top 10 for LLM Applications, MITRE ATLAS, and NIST AI Risk Management Framework.
- Strong analytical and problem-solving abilities, with the judgment to evaluate complex security issues and determine appropriate solutions.
- Excellent written, verbal, and interpersonal communication skills, with the ability to explain technical security concepts to both technical and non-technical stakeholders.
- Ability to manage multiple priorities, projects, and deadlines in a fast-paced, metrics-driven environment.
- Ability to work effectively both independently and as part of cross-functional teams.
- Strong attention to detail and a high degree of organization.
- Ability to handle confidential information and sensitive matters with discretion.
- Proficiency with Microsoft Office, collaborative cloud-based platforms, wikis, and third-party software applications.
- Demonstrated commitment to integrity, respect, collaboration, continuous learning, customer service, and high-quality results.
- Comfortable working primarily remotely with limited travel of approximately 5% or less.
- Ability to maintain focus, learn new processes, make timely decisions, and complete work independently within established workflows.
- Availability to work primarily Monday through Friday during the business week.
- Targeted salary range: $109,000–$156,000 annually, with compensation influenced by experience, education, skills, and geographic location.
- Fully remote work environment.
- Medical insurance.
- Dental insurance.
- Vision insurance.
- Life insurance.
- Accidental Death & Dismemberment (AD&D) coverage.
- Long-term disability (LTD) coverage.
- 401(k) retirement plan with employer match.
- Competitive compensation and comprehensive benefits package.
- Opportunity to work on cutting-edge application and AI security initiatives.
- High-impact role with significant influence over security strategy, standards, and technology practices.
- Collaborative environment with opportunities to work across engineering, product, DevOps, compliance, and incident response teams.
- Professional growth through continuous learning and exposure to emerging cybersecurity technologies.
Requirements:
Benefits:
As published by lever
Resume/CV, Full name, Email, Phone, Current location, Current company