Haystack
← Back to Jobs
Technology
CS

Application Security Engineer

Compest Solutions IncSunnyvale, CA🇺🇸United StatesPosted Oct 5, 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Sunnyvale, CA, United States
Posted
Yesterday
MicroservicesBashLLMPenetration TestingPython

Job Description

Job title: AI Security Engineer / Application Security Engineer
Location: Onsite in Seattle, Washington and Sunnyvale, California. Local candidates are required.
Position Type- Contract
Rate USD $/hr on W2
Job Description/ Responsibilities

Role Overview

We are seeking an experienced AI Security / Application Security Engineer to strengthen our security engineering capabilities across application security, cloud services, APIs, and AI/LLM integrations. The ideal candidate will have hands-on experience in security architecture reviews, threat modeling, vulnerability assessment, penetration testing, and adversarial testing of AI agents.

Key Responsibilities

  • Conduct security and privacy design reviews for applications, APIs, cloud services, engineering proposals, and AI integrations.
  • Review system architecture, data flows, access controls, trust boundaries, authentication, authorization, and security safeguards.
  • Perform threat modeling for critical services and AI agents, identifying attack surfaces, attack scenarios, attack paths, mitigations, and residual risks.
  • Conduct hands-on security and adversarial testing of AI/LLM agents, including:
  • Prompt injection
  • Tool misuse
  • Excessive agency
  • Unauthorized data access
  • Permission and access-control issues
  • External integrations
  • Sensitive-data exposure
  • Identify, validate, and document security vulnerabilities and provide practical remediation recommendations.
  • Work closely with engineering, security, privacy, and third-party teams to drive remediation and validate security controls.
  • Develop reusable security assessment methodologies, checklists, threat models, test cases, and reporting templates.
  • Support security automation and AI-assisted security workflows where appropriate.

Required Qualifications

  • 3+ years of professional experience in security engineering, application security, product security, offensive security, systems architecture, or a related technical security field.
  • Experience reviewing complex technical designs and identifying security risks in:
  • Applications
  • APIs
  • Cloud services
  • Microservices
  • Distributed systems
  • Strong understanding of:
  • Threat modeling
  • Vulnerability assessment
  • Risk modeling
  • Authentication and authorization
  • Least-privilege principles
  • Data protection
  • Security architecture
  • Hands-on experience with security testing, vulnerability investigation, penetration testing, adversarial testing, or security-control validation.
  • Strong technical communication skills with the ability to explain security findings to engineering and business stakeholders.

Preferred Qualifications

  • Experience assessing AI/LLM applications and autonomous AI agents.
  • Knowledge of prompt injection, jailbreaks, unsafe tool use, excessive agency, and AI data-security risks.
  • Experience with privacy and security design reviews.
  • Experience securing cloud environments.
  • Security automation experience using Python, Go, Bash, or similar languages.
  • Familiarity with application-security frameworks and industry security practices.

Key Skills

Application Security | AI/LLM Security | Threat Modeling | Penetration Testing | Adversarial Testing | Cloud Security | API Security | Security Architecture | Vulnerability Assessment | Privacy & Data Protection | Python/Go/Bash | Security Automation

Similar jobs