openleverjobgether
Application Security Engineer
Jobgether
LocationUS
EmploymentFull-time
Posted2026-08-20T14:16:15.031000+00:00
Last observed2026-08-26 21:51:40.410433
Job idjobgether-jobgether:lever:ee725b39-d956-48c8-a98f-9694a000d62d
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Application Security Engineer based in the United States. This role helps strengthen application security across modern software environments, including AI-enabled applications and services. You will embed security throughout the development lifecycle through code reviews, automated testing, manual assessments, and secure design practices. The position offers exposure to emerging AI security challenges, including LLM applications, RAG pipelines, and agentic workflows. You’ll partner closely with engineering, product, DevOps, compliance, and incident response teams to identify and reduce risk. A key focus will be enabling developers to understand vulnerabilities and adopt practical, secure development practices. You’ll also contribute to threat modeling, AI red teaming, security tooling, and the organization’s broader security awareness efforts. This is a remote opportunity for a developing security professional seeking meaningful hands-on experience in application and AI security. Apply and maintain secure software development practices, including code reviews and security testing integrated into CI/CD pipelines. Identify, validate, prioritize, and triage application vulnerabilities using automated security tools and manual testing techniques. Support Shift Left security initiatives by helping development teams adopt secure coding practices and remediate identified vulnerabilities. Support Security Champions programs by answering development-team questions and helping deliver security training. Assist developers with vulnerability reproduction, risk assessment, and remediation guidance, escalating complex or high-risk issues when appropriate. Operate, tune, maintain, and improve application security tools, including open-source solutions. Collaborate with product, engineering, DevOps, and compliance stakeholders to incorporate security requirements into application architecture and design. Participate in threat modeling, security design reviews, recurring security assessments, and vulnerability testing. Maintain security control documentation, testing evidence, findings, and remediation guidance. Apply secure development standards to AI-enabled applications, including LLM integrations, RAG pipelines, and agentic workflows. Configure, test, and monitor AI security guardrails, including prompt-injection defenses, input/output validation, least-privilege controls, and data-loss prevention measures. Conduct AI red-team testing covering prompt injection, jailbreaks, sensitive-data exposure, insecure outputs, and excessive agency, using recognized security frameworks such as OWASP Top 10 for LLM Applications and MITRE ATLAS. Support security reviews of new AI use cases and third-party AI capabilities, including controls protecting nonpublic personal information. Help establish secure-use practices for AI coding assistants, including appropriate human review and security scanning of AI-generated code. Assist incident response teams with investigation and remediation of application-related security incidents. Monitor emerging application and AI security threats and contribute to security awareness and compliance initiatives. Requirements Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or a related discipline preferred; equivalent education and experience may be considered. At least 3 years of experience as a software developer or in a comparable technical role. Experience with application security, secure software development, vulnerability management, code review, or security testing is highly relevant. Familiarity with automated and manual application security testing methodologies. Experience with AI/LLM security concepts, including prompt injection, jailbreaks, RAG security, agentic workflows, and AI guardrails, is valuable. Familiarity with OWASP application security princi
This page is generated from the committed OpenOpps static snapshot. Use the source posting or apply link for the employer's current canonical posting state.