Application Security Engineer - Threat & Vulnerability Management (AI Focus) for
Quick Overview
Job Description
Job Title: Application Security Engineer - Threat & Vulnerability Management (AI Focus)
Location: Remote
Duration: 6+ Months
Position Overview:
The Application Security Engineer - Threat & Vulnerability Management (AI Focus) is responsible for driving secure-by-design practices across AI and agentic application development lifecycles. This role partners closely with engineering, platform, security, and AI teams to ensure that AI-powered applications, agents, and supporting pipelines are developed, tested, deployed, and maintained securely.
The ideal candidate will lead vulnerability management initiatives for AI workloads, establish security controls throughout AI development pipelines, and proactively assess emerging threats associated with Large Language Models (LLMs), AI agents, and AI supply chains.
Job Description:
Key Responsibilities
Secure Development & DevSecOps
• Integrate and optimize SAST, DAST, SCA, and other application security tooling within AI and agentic CI/CD pipelines.
• Develop and maintain secure SDLC controls for AI application development.
• Establish security guardrails and best practices for developers, makers, and AI engineering teams.
• Collaborate with platform and engineering teams to embed security requirements into AI development workflows.
Threat Modeling & Risk Management
• Lead threat modeling exercises for AI applications, agents, and LLM-powered systems.
• Assess risks associated with OWASP LLM Top 10, OWASP Agentic AI Top 10, and other emerging AI security frameworks.
• Identify and mitigate AI-specific attack vectors including:
Vulnerability Management
• Define and enforce vulnerability management standards and SLAs across AI workloads.
• Conduct vulnerability assessments and coordinate remediation efforts with development teams.
• Track, prioritize, and report application security risks using risk-based methodologies.
• Monitor security posture and provide recommendations for continuous improvement.
AI Supply Chain Security
• Build and manage Software Bill of Materials (SBOM) capabilities for AI, LLM, and traditional software assets.
• Evaluate risks associated with open-source models, libraries, plugins, and third-party AI services.
• Ensure governance and compliance of AI dependencies throughout the software lifecycle.
Governance & Security Enablement
• Develop security standards, policies, and guidance for AI application development.
• Provide training and consultation to development teams on secure AI coding practices.
• Participate in architecture reviews and security assessments for AI initiatives.
• Support audits, compliance assessments, and security reviews related to AI systems.
Experience
• 5+ years of experience in Application Security, DevSecOps, Product Security, or Vulnerability Management.
• Experience implementing and managing:
o SAST
o DAST
o Software Composition Analysis (SCA)
o CI/CD security controls
• Hands-on experience integrating security solutions into modern software delivery pipelines.
• Experience conducting threat modeling and security architecture reviews.
Technical Skills
• Deep understanding of secure application development methodologies.
• Knowledge of AI/LLM attack surfaces and emerging AI security risks.
• Familiarity with OWASP Top 10, OWASP API Security Top 10, OWASP LLM Top 10, and OWASP Agentic AI guidance.
• Experience with container, cloud, and API security.
• Knowledge of Software Bill of Materials (SBOM) frameworks and supply chain security practices.
• Strong understanding of DevOps, CI/CD, and cloud-native architectures.
Similar jobs
- IT
IT Security Engineer (Remote)
NewIrvine Technology Corporation (ITC)
Kirkland, WA🇺🇸$140k - $160k/yrRemote23 hours agoAWSAzureGenerative AI+2Technology - DT
IT - ADMIN - Security Architect - Consultant - Data Modeling Engineer
NewDatasoft Technologies, Inc.
Columbia, SC🇺🇸$125/hrRemote23 hours agoTechnology - MT
Cyber Security Engineer
Maxpath Technologies LLC
United States🇺🇸Remote5 weeks agoDockerBashPowerShell+2Technology - ZT
Cyber Security Analyst II
NewZolon Tech Solutions Inc
United States🇺🇸Remote23 hours agoTechnology - AI
Security Architect – Data Modeling Engineer
NewARK Infotech Spectrum
United States🇺🇸Hybrid23 hours agoTechnology - KE
Senior Data Security Engineer (USSOCOM-Zero Trust, Azure Security & DLP)
NewKentro
Tampa, FL🇺🇸On-site23 hours agoSQLEncryptionSplunk+3Technology