Haystack
← Back to Jobs
Technology
JC

Application Security Engineer / Senior Application Security Engineer / AI Application Security Engineer

JC CORPORATIONSUnited States🇺🇸United StatesPosted 4 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
United States
Posted
16 hours ago
OWASPGenerative AILLMPython

Job Description

Job Overview

We are seeking a Senior Application Security Engineer with strong hands-on software engineering experience and deep expertise in Application Security, Python automation, AI/ML, LLMs, and Agentic AI.

The ideal candidate is a hands-on engineer who has shipped production code and can build security automation, tooling, and reusable workflows. Experience with Claude Code, AI agents, MCP integrations, prompt injection, OWASP LLM Top 10, and agent security is highly desirable.

Key Responsibilities

  • Design, develop, and maintain application security automation and tooling using Python.
  • Build reusable security workflows leveraging Claude Code, including skills, subagents, hooks, slash commands, and MCP integrations.
  • Assess and secure AI/ML, LLM, and agentic AI applications.
  • Identify and address emerging AI security risks including prompt injection, excessive agent/tool permissions, model and tooling supply-chain risks, and data exposure.
  • Perform threat modeling, vulnerability assessments, and secure architecture reviews.
  • Integrate security practices throughout the Secure SDLC and CI/CD pipelines.
  • Address common application security vulnerabilities including OWASP Top 10, API security, authentication, and authorization.
  • Develop automation to improve vulnerability detection, remediation, and security engineering workflows.
  • Evaluate when security issues should be automated, escalated, or manually remediated.
  • Collaborate with software engineers, architects, DevOps, and AI/ML teams to implement secure solutions.

Required Skills

  • 10 15+ years of software engineering and application security experience.
  • Strong hands-on Python development and automation experience.
  • Strong software development background with demonstrated production coding experience.
  • Hands-on experience with Claude Code and its extensibility capabilities.
  • Knowledge of AI/ML, LLMs, Generative AI, and AI Agents.
  • Understanding of Agentic AI security and emerging AI application risks.
  • Knowledge of OWASP Top 10 / OWASP LLM Top 10.
  • Strong experience with Secure SDLC and Threat Modeling.
  • Strong understanding of API Security, Authentication, and Authorization.
  • Ability to develop security tooling, automation, and reusable workflows.
  • Strong problem-solving and security engineering judgment.

Nice to Have

  • Experience securing production LLM or Agentic AI systems.
  • Experience building internal AI security tooling.
  • Experience with MCP (Model Context Protocol) integrations.
  • Contributions to open-source security projects/tools.
  • Certifications such as OSCP, GWAPT, or CSSLP.

Similar jobs