> Markdown version of [/jobs/ext/1428636-application-security-engineer-ai](https://www.wearedevelopers.com/jobs/ext/1428636-application-security-engineer-ai). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - AI - **Company:** American CyberSystems - **Location:** Charlotte, NC, United States (Remote available) - **Salary:** $176,800.0 - $187,200.0 - **Contract:** Temporary contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Logic Synthesis of Circuits, Systems Development Life Cycle, Application Specific Integrated Circuits, Large Language Models, Software Security, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 24, 2026 - **Apply:** https://www.jofdav.com/jobs/58971574-application-security-engineer-ai ## About the Role * Experience in Application Security or Information Security Engineering experience at enterprise scale. * Experience in SSDLC controls including threat modeling, secure design, SAST, SCA, DAST, and penetration testing. * Ability to define security strategy and deliver outcomes through influence and technical leadership. ## Description * Define and lead the Application Security strategy for DCMS in-scope applications using tier-based control models. * Evaluate existing AppSec control coverage and establish baseline mappings by application tier. * Identify control gaps and drive remediation and onboarding plans with application teams and stakeholders. * Partner with Application Security Champions and engineering teams to ensure consistent adoption of required AppSec controls. * Ensure alignment with enterprise SDLC requirements and defect remediation expectations. * AI Innovation for Application Security * Identify and deliver AI and GenAI use cases that reduce manual AppSec effort and improve security coverage. * Design and implement automated threat modeling using code, infrastructure-as-code, and application metadata. * Develop adversarial testing capabilities for GenAI and LLM-based applications, including prompt injection and abuse scenarios. * Lead initiatives for AI model scanning, integrity validation, and secure onboarding of models. * Define protections for AI-specific risks including insecure prompt construction, tool misuse, and secrets exposure. * AppSec Modernization and Automation * Drive modernization of AppSec controls through automation, rationalization, and platform integration. * Build proofs-of-concept and pilot new security capabilities, scaling successful solutions into production. * Influence simplification of AppSec processes to improve developer experience while maintaining strong risk controls. * Senior Lead Influence and Leadership. * Provide strategic guidance to senior leadership on Application Security priorities, risks, and investment decisions. * Influence cross-functional teams without direct authority to achieve enterprise security outcomes. * Research emerging threats and technologies and translate insights into actionable AppSec strategy. ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Creating Industry ready solutions with LLM Models](https://www.wearedevelopers.com/videos/899-creating-industry-ready-solutions-with-llm-models) - [Edit Your Future: Queerverse Radical AI](https://www.wearedevelopers.com/videos/909-edit-your-future-queerverse-radical-ai) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [From Monolith Tinkering to Modern Software Development](https://www.wearedevelopers.com/videos/822-from-monolith-tinkering-to-modern-software-development) - [Lies, Damned Lies and Large Language Models](https://www.wearedevelopers.com/videos/1231-lies-damned-lies-and-large-language-models) ## Related Articles - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)