AI Application Security Analyst - AppSec & ML Security

PURE Insurance
United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$45,000.0 - $100,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Application Lifecycle Management Automation of Tests Microsoft Azure Bash Shell Cloud Computing Python (Programming Language) OAuth Open Web Application Security Openid Connect
+13 more
Tensorflow Security Assertion Markup Language (SAML) Web Application Security Scripting Google Cloud Delivery Pipeline Software Security Integration Frameworks Machine Learning Operations Devsecops Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

We are seeking an AI Application Security Analyst to secure modern applications, including those leveraging machine learning and AI technologies. This role focuses on identifying, assessing, and mitigating vulnerabilities across the application lifecycle, with particular emphasis on AI-enabled applications and services.

You will work closely with engineering teams to embed security into development pipelines, implement testing and runtime protections, and ensure that AI/ML components are resilient against emerging threats.

What you’ll do:

  • Perform application security assessments using SAST, DAST, and interactive testing tools
  • Identify, triage, and prioritize vulnerabilities across web, API, and microservices architectures
  • Integrate security testing into CI/CD pipelines (DevSecOps)
  • Assess security risks in AI/ML-enabled applications, including model exposure and inference endpoints
  • Identify vulnerabilities such as adversarial inputs, model abuse, and data poisoning
  • Secure AI APIs, plugins, and third-party integrations
  • Implement and tune WAF, RASP, and API security controls
  • Conduct threat modeling and secure design reviews for applications and AI use cases
  • Assess and harden identity and access flows ensuring least privilege
  • Partner with developers to remediate vulnerabilities and improve secure coding practices
  • Monitor and respond to application-layer security incidents, * Faster remediation cycles
  • Strong runtime protection
  • Secure AI feature deployment
  • Improved developer security practices

Operational Expectations:

  • Participate in on-call rotation
  • Provide after-hours and weekend support
  • Respond to security alerts and incidents
  • Collaborate with teams during incident response

What We Do

We’re a member-owned property and casualty insurer designed exclusively for financially successful families and driven by a purpose of doing what is right for our members. Our reciprocal model focuses on service and doing what is right for the membership: we provide exceptional service, hospitality and care, we partner with our members to help prevent losses and we create smart insurance solutions at fair prices.

We aim for our members to love their insurance . It is our mission is to create a membership experience so compelling that our members never want to leave.

Requirements

Do you have experience in Web Application Security Testing?, * 3-6+ years of experience in Application Security or Product Security

  • Hands-on experience with SAST, DAST, IAST tools
  • Strong knowledge of OWASP Top 10 vulnerabilities
  • Experience securing APIs and microservices
  • Experience with modern authentication and authorization protocols (OAuth 2.0, OpenID Connect, SAML)
  • Familiarity with CI/CD pipelines
  • Basic understanding of AI/ML systems
  • Security certification or willingness to obtain within 6 months, * Experience with ML frameworks is a plus
  • Familiarity with AI threat models
  • Experience with WAF, RASP, or API security solutions
  • Experience with cloud platforms (AWS, Azure, GCP)
  • Scripting skills (Python, Bash)

Benefits & conditions

3.93.9 out of 5 stars Remote $45,000 - $100,000 a year - Full-time

About the company

We want to be transparent about what we expect from each other. From PURE, you can expect:

Opportunities to stretch and grow: your professional and personal development matters to us. We’re committed to providing experiences through on-the-job learning and professional development that increase your impact and rewards.

Clarity and kindness: you can rely on us to be open, honest and supportive, offering clarity on what success looks like.

Support in good times and bad: we believe in showing up for each other consistently, not only when it’s easy. You can expect a thoughtful partner, even when we disagree.

A community that cares: we are committed to sustaining a community in which each person feels cared for as an individual. We lift each other up, celebrate wins together and support one another through challenges in work and life.

Who You Are

All of the strongest relationships are a partnership- a two way street. So here’s what we ask of you:

  • Aim to bring your best every day: you’re here because you want to be part of a team that makes a real impact and aims high.
  • Be a student and a teacher: share your knowledge and talents and be willing to listen and learn from those around you.
  • Get comfortable being uncomfortable: we face tough moments and obstacles with a ā€œcourage over comfortā€ approach and a positive, solutions-oriented mindset.
  • Be a culture builder: building a positive culture is everyone’s responsibility, based on care, respect and openness to diverse perspectives.

The base salary for this role can range from $45,000 to $100,000 based on a full-time work schedule. An individual’s ultimate compensation will vary depending on job-related skills and experience, geographic location, alignment with market data, and equity among other team members with comparable experience

To ensure a successful onboarding experience, all new hires must work onsite at one of our offices during their first week of employment. Candidates should apply only if they are able to meet this requirement.

You must create an Indeed account before continuing to the company website to apply

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:00 min

Top security vulnerabilities for AI applications

Deepu Deepu Ā· WWC 2025

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz Ā· WWC Europe 2026

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil Ā· LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders Ā· LIVE

3:17 min

Implementing a practical security checklist for production environments

Jose Manuel Ortega Jose Manuel Ortega Ā· Europe 2026 Virtual

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz Ā· WWC Europe 2026

Videos

See all

Related articles

See all