← Все вакансии/Senior/jobgether
SeniorRemoteUS

Application Security Engineer

J
jobgether
Зарплата
$9,100–$13,000
Уровень
Senior
Формат
Remote
О роли

Описание вакансии

About the company

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in United States.

Responsibilities
  • Define and implement secure software development practices, including secure coding standards, code reviews, and security integration within CI/CD pipelines.
  • Lead Shift Left security initiatives and work with software engineering teams to incorporate security requirements early in the development lifecycle.
  • Identify, assess, prioritize, and remediate application vulnerabilities using automated security tools and manual testing techniques.
  • Serve as the application security subject matter expert, helping developers reproduce vulnerabilities, understand risks, and implement effective mitigation strategies.
  • Manage and optimize tools supporting the application security program, including open-source security solutions.
  • Develop and lead threat modeling exercises, risk assessments, security audits, vulnerability assessments, and application security reviews.
  • Partner with product, engineering, DevOps, compliance, and incident response teams to integrate security controls with business and operational objectives.
  • Train and support Security Champions across development teams while promoting a strong culture of security awareness and continuous improvement.
  • Establish secure design standards for AI-enabled applications, including LLM integrations, retrieval-augmented generation pipelines, agentic workflows, and model tool-use interfaces.
  • Design and validate AI security guardrails covering prompt injection defenses, input and output validation, least-privilege access, rate and cost controls, and data loss prevention.
  • Lead AI red-team exercises addressing prompt injection, jailbreaks, sensitive data exposure, insecure outputs, excessive agency, and AI/model supply-chain risks, using frameworks such as OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework.
  • Review AI use cases and third-party AI capabilities, assessing providers, data flows, retention practices, application inventories, and requirements for handling nonpublic personal information.
  • Establish secure usage standards for AI coding assistants, including human review requirements, scanning of AI-generated code, and controls for secrets and intellectual property.
  • Drive application security initiatives through completion and maintain relevant security controls, standards, documentation, and governance processes.
  • Support application-related security incidents by collaborating with incident response teams to investigate, contain, and remediate issues.
Requirements
  • Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or a related discipline is preferred, or equivalent professional experience.
  • At least 5 years of experience as a software developer or in a closely related technical role, with strong application security expertise.
  • Strong knowledge of secure software development, application vulnerability management, threat modeling, risk assessment, and security testing.
  • Experience integrating security controls into CI/CD pipelines and software development workflows.
  • Familiarity with AI and LLM security concepts, including prompt injection, jailbreaks, RAG security, agentic workflows, tool-use risks, and sensitive data protection.
  • Experience applying or working with security frameworks such as OWASP, MITRE ATLAS, and NIST AI Risk Management Framework.
  • Ability to assess complex security problems, prioritize risks, and develop practical mitigation strategies.
  • Strong organizational skills with the ability to manage multiple priorities, initiatives, and deadlines simultaneously.
  • Excellent verbal and written communication skills, with the ability to collaborate effectively with technical and non-technical stakeholders.
  • Ability to work independently while contributing effectively within cross-functional teams.
  • Strong attention to detail and sound professional judgment when handling confidential information and security-sensitive matters.
  • Proficiency with Microsoft Office, collaborative cloud platforms, documentation tools, and relevant third-party software applications.
  • Ability to work in a fast-paced, metrics-driven environment and adapt to evolving technologies, threats, and business requirements.
  • Demonstrated commitment to integrity, collaboration, continuous learning, customer service, and technical excellence.
  • Ability to work Monday through Friday primarily from a home environment, with travel of approximately 5% or less.
Conditions
  • Targeted salary range of $109,000–$156,000 annually, with compensation determined by factors including experience, education, skills, and geographic location.
  • Medical, dental, and vision insurance.
  • Life insurance and AD&D coverage.
  • Long-term disability insurance.
  • 401(k) retirement plan with employer match.
Стек и навыки

С чем работаем