openleverjobgether
Senior Application Security Engineer
Jobgether
LocationUS
EmploymentFull-time
Posted2026-08-24T09:30:10.514000+00:00
Last observed2026-08-26 21:51:40.410433
Job idjobgether-jobgether:lever:e133e2ed-ec95-47f7-8ba5-bb41f9fd09af
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in the United States. This remote role offers the opportunity to shape application security strategy across traditional software and emerging AI-enabled technologies. You will establish secure development standards, strengthen CI/CD security, and embed protection throughout the software development lifecycle. The role combines application security engineering, vulnerability management, threat modeling, and hands-on testing with strategic security leadership. A major focus will be securing AI and LLM applications, including RAG pipelines, agentic workflows, and model tool-use interfaces. You will lead AI red teaming and help establish practical guardrails against prompt injection, data exposure, excessive agency, and other emerging threats. Working closely with engineering, DevOps, product, compliance, and incident response teams, you will translate security risks into actionable solutions. This is a high-impact opportunity for an experienced security professional to influence secure-by-design practices across a technology-driven organization. Define and implement secure software development practices, including secure coding standards, code reviews, and security integration within CI/CD pipelines. Lead Shift Left security initiatives, embedding application security requirements and testing earlier in the development lifecycle. Identify, assess, prioritize, and help remediate application vulnerabilities through automated scanning, manual testing, and vulnerability management processes. Serve as the application security Subject Matter Expert, helping development teams reproduce vulnerabilities, understand risk, and implement effective mitigations. Train and collaborate with Security Champions across software engineering teams to strengthen application security awareness and capabilities. Operate, maintain, and continuously optimize tools supporting the Application Security program, including open-source security solutions. Lead threat modeling exercises and risk assessments for new and existing applications, translating findings into practical security controls. Partner with product and development teams during planning and requirements phases to define security requirements and secure application architectures. Conduct security audits and vulnerability assessments while maintaining appropriate security controls, documentation, and evidence. Collaborate with engineering, DevOps, compliance, and other stakeholders to align security practices with business and technology objectives. Partner with incident response teams to investigate, contain, and remediate application-related security incidents. Drive long-term application security initiatives from planning through successful completion. Define secure design patterns and secure-by-default requirements for AI-enabled applications, including LLM integrations, RAG pipelines, agentic workflows, and model tool-use interfaces. Design and validate AI security guardrails covering prompt injection defenses, input/output validation, least-privilege access, rate and cost controls, and data loss prevention. Lead adversarial testing and AI red team exercises covering prompt injection, jailbreaks, sensitive data disclosure, insecure outputs, excessive agency, and model or plugin supply-chain risks. Map AI security findings and controls to recognized frameworks such as OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework. Review new AI use cases and third-party AI capabilities, assessing providers, data flows, retention practices, and application security risks. Establish and enforce requirements for protecting nonpublic personal information (NPI) within AI systems. Develop secure usage standards for AI coding assistants, including human review requirements, security scanning, and control
This page is generated from the committed OpenOpps static snapshot. Use the source posting or apply link for the employer's current canonical posting state.