
Lead Application Security Engineer
Posted Jul 18

Posted Jul 18
This is a fully remote position, open to applicants in United States.
• Utilize AI-enhanced threat modeling tools to detect security risks related to applications, platforms, APIs, cloud, data, and AI/ML at early stages of design and development.
• Employ automated security assessment tools to scrutinize architecture, design documents, code modifications, APIs, and data flows for security vulnerabilities and control deficiencies.
• Lead AI-driven code security assessments using SAST, DAST, SCA, secrets detection, IaC scanning, container scanning, and contextual risk evaluation.
• Implement automation and intelligent correlation to evaluate third-party libraries, APIs, vendor integrations, and open-source dependencies for security, compliance, and supply-chain risks.
• Assist AI-enabled red team, blue team, and incident response exercises to affirm detection, prevention, and response capabilities.
• Collaborate with developers and QA engineers to integrate AI-powered security testing and automated risk identification within CI/CD pipelines.
• Develop and enhance security automation that offers real-time feedback to developers throughout design, coding, testing, release, and deployment phases.
• Apply AI-assisted analysis to assess architecture and design documents, identify risks earlier, and suggest secure implementation patterns.
• Contribute to intelligent security checkpoints that minimize manual review demands while enhancing consistency, traceability, and developer efficiency.
• Aid in crafting scalable guardrails, reusable security controls, and policy-as-code functionalities across application and platform teams.
• Track emerging security risks associated with applications, cloud, APIs, AI/ML, and data through AI-assisted threat intelligence, vulnerability intelligence, and attack-pattern evaluations.
• Identify and assess AI-specific threats such as prompt injection, data poisoning, model misuse, model leakage, insecure tool utilization, and sensitive data exposure.
• Support the design and implementation of proactive defense mechanisms for applications, APIs, data platforms, and AI-driven systems.
• Utilize automated signals, telemetry, and risk scoring to aid investigations, post-incident reviews, and ongoing enhancements of prevention and detection capabilities.
• Transform recurring vulnerabilities and incidents into feedback loops that refine threat models, secure design patterns, and SDLC controls.
• Advocate for secure coding and design practices through AI-supported guidance, reusable playbooks, automated suggestions, and developer-friendly documentation.
• Contribute to internal security standards, secure engineering frameworks, and AI-native security playbooks.
• Assist teams in adopting security self-service functionalities that lessen reliance on manual AppSec reviews.
• Work collaboratively with Engineering, DevOps, QA, Product, and AI platform teams to cultivate a culture centered on security and automation.
• Leverage metrics and insights to evaluate control effectiveness, remediation trends, developer engagement, and overall security maturity.
• Bachelor’s degree in Computer Science, Cybersecurity, or a related discipline, or equivalent practical experience.
• Over 5 years of experience in Application Security, DevSecOps, Secure Software Development, or Security Engineering.
• Solid understanding of OWASP Top 10, SANS CWE Top 25, secure design principles, and application threat modeling.
• Familiarity with AI/ML security concepts such as prompt injection, data poisoning, adversarial testing, model integrity, model misuse, and AI supply-chain risks.
• Experience in creating or integrating AI-enhanced security workflows, security bots, automated triage systems, or risk scoring models.
• Proficient in using AI-assisted or automation-driven methods to enhance security testing, vulnerability evaluation, code review, or risk prioritization.
• Familiarity with contemporary application frameworks and architectures such as React, Node.js, Django, FastAPI, or similar technologies.
• Knowledge of securing APIs, microservices, and authentication and authorization mechanisms like OAuth2, OIDC, JWT, and service-to-service authentication.
• Experience with cloud platforms such as AWS, GCP, or Azure, and containerized environments like Docker and Kubernetes.
• Practical knowledge of security testing and automation tools including Semgrep, SonarQube, Burp Suite, OWASP ZAP, Trivy, Snyk, GitHub Advanced Security, or similar tools.
• Ability to analyze security findings, correlate risk contexts, and provide actionable remediation guidance for engineering teams.
• Strong collaboration and communication skills, capable of working across Engineering, Product, QA, DevOps, and Security teams.
• Unlimited PTO
• Excellent medical, dental, and vision coverage
• Employee Equity
• Employee Discounts, Virtual Wellness Classes, and Pet Insurance
• And more!!
Nokia
Lime
Twin Health
Anthropic
Get handpicked remote jobs straight to your inbox weekly.