openleverjobgether
Senior Application Security Engineer
Jobgether
LocationUS
EmploymentFull-time
Posted2026-08-24T07:31:29.692000+00:00
Last observed2026-08-26 21:51:40.410433
Job idjobgether-jobgether:lever:1acc8752-2939-4af9-af4a-d4e67a97ad5e
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in United States. This is a senior-level application security role focused on strengthening the security of modern software and AI-enabled applications. You will establish secure development practices and embed security throughout the software development lifecycle. The role combines application security engineering, vulnerability management, threat modeling, and secure CI/CD practices. You will also serve as a technical authority for securing AI and LLM-enabled applications, including RAG and agentic workflows. Working closely with engineering, product, DevOps, compliance, and incident response teams, you will help turn security requirements into practical solutions. The position offers significant ownership, influence, and the opportunity to drive long-term security initiatives across the organization. Success will require strong technical judgment, communication skills, and the ability to operate independently in a complex, fast-paced environment. Define and implement secure software development practices, including secure coding standards, code reviews, and security integration within CI/CD pipelines. Lead Shift Left security initiatives and work with software engineering teams to incorporate security requirements early in the development lifecycle. Identify, assess, prioritize, and remediate application vulnerabilities using automated security tools and manual testing techniques. Serve as the application security subject matter expert, helping developers reproduce vulnerabilities, understand risks, and implement effective mitigation strategies. Manage and optimize tools supporting the application security program, including open-source security solutions. Develop and lead threat modeling exercises, risk assessments, security audits, vulnerability assessments, and application security reviews. Partner with product, engineering, DevOps, compliance, and incident response teams to integrate security controls with business and operational objectives. Train and support Security Champions across development teams while promoting a strong culture of security awareness and continuous improvement. Establish secure design standards for AI-enabled applications, including LLM integrations, retrieval-augmented generation pipelines, agentic workflows, and model tool-use interfaces. Design and validate AI security guardrails covering prompt injection defenses, input and output validation, least-privilege access, rate and cost controls, and data loss prevention. Lead AI red-team exercises addressing prompt injection, jailbreaks, sensitive data exposure, insecure outputs, excessive agency, and AI/model supply-chain risks, using frameworks such as OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework. Review AI use cases and third-party AI capabilities, assessing providers, data flows, retention practices, application inventories, and requirements for handling nonpublic personal information. Establish secure usage standards for AI coding assistants, including human review requirements, scanning of AI-generated code, and controls for secrets and intellectual property. Drive application security initiatives through completion and maintain relevant security controls, standards, documentation, and governance processes. Support application-related security incidents by collaborating with incident response teams to investigate, contain, and remediate issues. Requirements Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or a related discipline is preferred, or equivalent professional experience. At least 5 years of experience as a software developer or in a closely related technical role, with strong application security expertise. Strong knowledge of secure software development, application vulnerability management
This page is generated from the committed OpenOpps static snapshot. Use the source posting or apply link for the employer's current canonical posting state.