← Back to Jobs
Engineering
Engineer 5 - Penn Tester
Apex SystemsCharlotte, NC🇺🇸United StatesPosted 25 Jul 2026
Why This Role Stands Out
This hybrid role offers a fantastic opportunity to shape enterprise-wide application security strategy and lead cutting-edge AI-enabled security initiatives, fostering significant career growth. You'll thrive if you're a seasoned penetration tester with expertise in offensive security and a passion for driving innovation within a reputable organization. Apply now to make a substantial impact and advance your skills in this exciting leadership position.
Quick Overview
Work Type
Hybrid
Level
Mid Senior
Job Description
Job#: 3043810
Job Description:
Security Engineer 5 - (Penetration Testing, AI Security & Application Security Strategy)
Location
Job Summary
The organization is seeking a highly experienced Engineer 5 / Senior Lead Application Security Engineer to define and execute Application Security strategy supporting enterprise modernization initiatives, including the Data Center Modernization and Simplification (DCMS) program. This role serves as a senior technical leader responsible for driving enterprise-scale application security strategy, advancing security automation, leading penetration testing initiatives, and delivering innovative AI-enabled security capabilities.
The ideal candidate possesses deep expertise in Application Security, Secure Software Development Lifecycle (SSDLC) controls, offensive security, threat modeling, vulnerability management, and security engineering. This individual will partner with executive leadership, security teams, software engineering organizations, and business stakeholders to deliver scalable, automated, and risk-aligned security outcomes across the enterprise.
This role requires a strategic leader who can influence executive stakeholders, drive modernization initiatives, and shape the future of Application Security through the adoption of emerging technologies including Artificial Intelligence, Large Language Models (LLMs), and advanced security automation.
Key Responsibilities
Application Security Strategy & Leadership
Advanced Application Security & Offensive Security
Application Security
One or more of the following certifications are highly desired:
The ideal candidate is a senior Application Security leader who combines deep penetration testing expertise, offensive security capabilities, and modern AI security knowledge with proven enterprise leadership experience.
Successful candidates will possess expertise in SSDLC controls, application security architecture, offensive security methodologies, vulnerability management, security automation, and emerging AI security risks. They will have experience influencing executive stakeholders, partnering with developers and security champions, driving enterprise modernization efforts, and delivering scalable Application Security outcomes within highly regulated environments
Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.
Everforth Apex uses a virtual recruiter as part of the application process. Click for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at
Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Everforth Apex team member can provide.
Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.
If you require an accommodation under the Americans with Disabilities Act to participate in an interview with a virtual recruiter or to use our website for a search or application, please contact our Benefits Department at or . Please note that this contact information is strictly to be used for medical ADA accommodations and that no other inquiries will be answered.
UnitedHealthcare creates and publishes the Transparency in Coverage Machine-Readable Files on behalf of Everforth Apex Systems.
Job Description:
Security Engineer 5 - (Penetration Testing, AI Security & Application Security Strategy)
Location
- Charllotte, NC / Dallas, TX / Minneapolis, MN / Chandler, AZ / Des Moines. IA, Raleigh, NC
Job Summary
The organization is seeking a highly experienced Engineer 5 / Senior Lead Application Security Engineer to define and execute Application Security strategy supporting enterprise modernization initiatives, including the Data Center Modernization and Simplification (DCMS) program. This role serves as a senior technical leader responsible for driving enterprise-scale application security strategy, advancing security automation, leading penetration testing initiatives, and delivering innovative AI-enabled security capabilities.
The ideal candidate possesses deep expertise in Application Security, Secure Software Development Lifecycle (SSDLC) controls, offensive security, threat modeling, vulnerability management, and security engineering. This individual will partner with executive leadership, security teams, software engineering organizations, and business stakeholders to deliver scalable, automated, and risk-aligned security outcomes across the enterprise.
This role requires a strategic leader who can influence executive stakeholders, drive modernization initiatives, and shape the future of Application Security through the adoption of emerging technologies including Artificial Intelligence, Large Language Models (LLMs), and advanced security automation.
Key Responsibilities
Application Security Strategy & Leadership
- Define and lead enterprise Application Security strategy supporting Data Center Modernization and Simplification (DCMS) initiatives.
- Establish security control requirements and baseline security coverage models across application portfolios.
- Assess existing Application Security control coverage and identify gaps requiring remediation.
- Develop and execute AppSec onboarding and improvement plans across application portfolios.
- Partner with Application Security Champions, engineering teams, architects, and business stakeholders to drive security control adoption and remediation efforts.
- Ensure alignment with enterprise Secure Software Development Lifecycle (SSDLC) requirements and remediation expectations.
- Serve as a trusted advisor to senior leadership on Application Security risks, investments, and strategic priorities.
- Influence enterprise-wide security initiatives through technical expertise and strategic leadership.
- Lead enterprise penetration testing strategies and application security assessment programs.
- Perform or oversee:
- Application Penetration Testing
- Security Architecture Reviews
- Red Team Assessments
- Threat Modeling Exercises
- Vulnerability Research
- Security Assessments
- Adversarial Security Testing
- Evaluate vulnerabilities, identify security weaknesses, and develop remediation strategies.
- Research emerging attack techniques, threat actor behaviors, and evolving risk trends.
- Provide technical leadership on remediation planning and security risk reduction activities.
- Guide development teams on secure design principles and vulnerability mitigation strategies.
- Support offensive security initiatives including exploitation analysis, security testing, and application security validation activities.
- Lead secure-by-design and application security modernization initiatives across the enterprise.
- Drive adoption of security automation, security tooling, and developer enablement capabilities.
- Partner with software engineering teams to improve security outcomes while enhancing developer experience.
- Simplify and optimize Application Security processes while maintaining strong risk controls.
- Build proofs-of-concept and pilot emerging security capabilities, scaling successful solutions to production environments.
- Develop long-term strategy for AppSec platform maturity, automation, and operational effectiveness.
- Identify, evaluate, and implement AI and Generative AI (GenAI) security use cases that improve security effectiveness and reduce manual effort.
- Develop adversarial testing methodologies for:
- Large Language Models (LLMs)
- Generative AI Applications
- AI-Powered Services
- Design defenses against:
- Prompt Injection Attacks
- Model Abuse
- Tool Misuse
- Sensitive Data Exposure
- Secrets Leakage
- Support AI model scanning, integrity validation, secure onboarding, and governance programs.
- Define security controls addressing emerging AI-specific risks.
- Lead initiatives involving AI Testing, AI Security Analytics, AI Operationalization, and AI Security Assessment Automation.
- Evaluate emerging AI technologies and develop enterprise security strategies for AI adoption.
- Lead and mature enterprise SSDLC programs.
- Define and implement security requirements throughout the software development lifecycle.
- Provide expertise in:
- Threat Modeling
- Secure Design Reviews
- Secure Coding Practices
- Static Application Security Testing (SAST)
- Software Composition Analysis (SCA)
- Dynamic Application Security Testing (DAST)
- Penetration Testing
- Partner with engineering organizations to improve developer security capabilities and secure coding maturity.
- Drive consistent application of security controls across development teams.
- Drive modernization of Application Security controls through automation and platform integration.
- Design AI-driven security automation capabilities and intelligent security decisioning solutions.
- Develop and implement security tooling integrations and automation frameworks.
- Collaborate with DevSecOps teams to integrate security controls into CI/CD pipelines.
- Leverage Infrastructure as Code (IaC), platform automation, and security orchestration capabilities where appropriate.
- Improve security efficiency through automation, continuous validation, and workflow optimization.
- Act as a senior advisor to technology leadership on Application Security strategy and enterprise security roadmaps.
- Influence cross-functional teams without direct authority to achieve enterprise security outcomes.
- Collaborate with Application Security Champions, engineering organizations, and business stakeholders to drive risk reduction and secure development practices.
- Translate emerging threats, technologies, and industry trends into actionable security programs.
- Mentor and develop Application Security engineers and security practitioners.
- Contribute to enterprise security standards, policies, and best practices.
- Represent Application Security initiatives with executive leadership and key stakeholders.
- 7+ years of Application Security, Information Security Engineering, or related engineering experience.
- Deep expertise in enterprise-scale Application Security programs.
- Strong experience with:
- Threat Modeling
- Secure Design
- Secure Coding Practices
- SAST
- SCA
- DAST
- Penetration Testing
- Demonstrated experience defining and executing enterprise Application Security strategy.
- Proven ability to influence technical and business leaders across large organizations.
- Strong understanding of vulnerability management, remediation processes, and security governance.
- Exceptional communication, leadership, and executive stakeholder management skills.
Advanced Application Security & Offensive Security
- Experience leading enterprise Application Security transformation and modernization initiatives.
- Experience supporting Application Security governance, security consulting, remediation planning, and security champion programs.
- Strong expertise in:
- Application Security Testing
- Offensive Security
- Vulnerability Research
- Exploitation Techniques
- Red Team Methodologies
- Security Assessments
- Experience driving secure-by-design and SSDLC initiatives across large application portfolios.
- Experience working directly with developers and application owners to implement security controls and remediation plans.
- Experience securing:
- Generative AI Applications
- Large Language Models (LLMs)
- AI/ML Platforms
- Experience conducting adversarial AI testing and prompt injection assessments.
- Experience with:
- Prompt Engineering
- LLM Security
- AI Testing
- AI Operationalization
- AI Security Analytics
- AI Security Assessment Automation
- Experience building AI-driven security automation capabilities.
- Strong understanding of:
- DevSecOps
- CI/CD Security Integration
- Security Automation
- Infrastructure as Code (IaC)
- Platform Automation
- Experience integrating security scanning technologies into software delivery pipelines.
- Experience developing security tooling integrations and automation frameworks.
- Experience supporting enterprise modernization initiatives, cloud-native architectures, and security transformation programs.
- Experience with:
- Cloud Security
- Cloud Architecture
- Platform Engineering
- Infrastructure Automation
- Google Cloud Platform (Google Cloud Platform)
- Azure Environments
- Experience working within highly regulated environments such as financial services.
Application Security
- Application Security
- Secure Coding
- Threat Modeling
- Secure Design Reviews
- Penetration Testing
- Vulnerability Assessment
- Vulnerability Management
- Security Architecture
- Risk Analysis
- Application Security Governance
- SSDLC
- SAST
- DAST
- SCA
- Security Control Validation
- Developer Enablement
- Secure Development Practices
- GenAI Security
- LLM Security
- Prompt Engineering
- Prompt Injection Testing
- Adversarial AI Testing
- AI Security Analytics
- AI Operationalization
- AI Governance
- Secure AI Deployment
- DevSecOps
- CI/CD Security
- Security Automation
- Security Tool Integration
- Platform Automation
- Infrastructure as Code (IaC)
- API Security Integration
One or more of the following certifications are highly desired:
- CISSP
- CSSLP / CSSP
- CISM
- GIAC Certifications
- OSCP
- OSCE
- Other advanced Application Security or Offensive Security certifications
The ideal candidate is a senior Application Security leader who combines deep penetration testing expertise, offensive security capabilities, and modern AI security knowledge with proven enterprise leadership experience.
Successful candidates will possess expertise in SSDLC controls, application security architecture, offensive security methodologies, vulnerability management, security automation, and emerging AI security risks. They will have experience influencing executive stakeholders, partnering with developers and security champions, driving enterprise modernization efforts, and delivering scalable Application Security outcomes within highly regulated environments
Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.
Everforth Apex uses a virtual recruiter as part of the application process. Click for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at
Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Everforth Apex team member can provide.
Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.
If you require an accommodation under the Americans with Disabilities Act to participate in an interview with a virtual recruiter or to use our website for a search or application, please contact our Benefits Department at or . Please note that this contact information is strictly to be used for medical ADA accommodations and that no other inquiries will be answered.
UnitedHealthcare creates and publishes the Transparency in Coverage Machine-Readable Files on behalf of Everforth Apex Systems.
Skills
Stakeholder Management
Similar jobs
Senior Vice President, Forward Deployed Engineer - BNY
BNY · Pittsburgh, United States
17 minutes ago$104k - $210k/yrM365 Automation /Engineer
TEKsystems c/o Allegis Group · New York, United States
2 hours ago$75 - $85/hrMonitoring Engineer
TEKsystems c/o Allegis Group · Sioux Falls, United States
2 hours ago$95k - $110k/yrTelecommunications Engineer (AL)
Apex Systems · Fort Rucker, United States
4 hours ago$43 - $48/hrCOTS Implementation Engineer
Apex Systems · Falls Church, United States
4 hours ago$70 - $73/hrMLOps Engineer
Apex Systems · McLean, United States
5 hours ago