
Team Lead, AppSec
Posted Jul 18

Posted Jul 18
This is a fully remote position, open to applicants in United States.
β’ Lead the security of applications and products across Forward-developed, third-party, and AI-generated software.
β’ Advance the penetration testing program: rigorously security-test and address vulnerabilities in existing software, and consistently evaluate newly developed agents and the software created by them.
β’ Actively develop and incorporate AI solutions within the application security function.
β’ Manage remediation processes and vulnerability oversight in collaboration with Engineering, including analysis of pre-production versus post-production gaps.
β’ Collaborate with various teams to establish controls that mitigate external exposure: network allowlists, egress proxies, and proxy-level data loss prevention.
β’ Assist in the test-to-production review process to ensure that AI-generated work undergoes a security review prior to promotion.
β’ Mentor and cultivate a team of senior engineers; establish standards for quality and coverage in offensive testing.
β’ Develop and sustain security services within the Forward application stack.
β’ Generally requires 7 or more years of experience in application security, offensive security, or product security, including leadership roles.
β’ Proficient in hands-on penetration testing and code reviews for web applications, APIs, and cloud infrastructure (AWS).
β’ Proven experience in establishing or expanding a security testing program β including scoping, tools, cadence, and remediation service level agreements.
β’ Knowledge of AI/LLM attack surfaces: prompt injection, insecure tool usage by agents, and vulnerabilities associated with AI-generated code.
β’ Familiarity with modern programming languages such as Ruby, Python, or Go, as well as secure software development lifecycle practices.
β’ Strong ability to convey risk and priorities clearly to both engineers and executives.
β’ Typically holds a Bachelor's Degree in Computer Science or a related technical field, or possesses equivalent professional experience.
β’ It would be advantageous to have:
β’ Experience in penetration testing or red-teaming LLM applications and agentic systems.
β’ OSCP/OSWE or similar offensive security certifications.
β’ Experience managing bug bounty or external testing programs.
β’ A background in fintech or other regulated sectors.
β’ Flexibility is a key priority: Our employees enjoy the autonomy to choose their work environment (be it from home, in the office, or a mix of both) along with adaptable hours.
Knowtion Health
Jet Support Services, Inc. (JSSI)
Ascend Healthcare
Get handpicked remote jobs straight to your inbox weekly.