> Markdown version of [/jobs/ext/157157-ai-application-security-analyst-appsec-ml-security](https://www.wearedevelopers.com/jobs/ext/157157-ai-application-security-analyst-appsec-ml-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # AI Application Security Analyst - AppSec & ML Security - **Company:** PURE Insurance - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $45,000.0 - $100,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Application Lifecycle Management, Automation of Tests, Microsoft Azure, Bash Shell, Cloud Computing, Python (Programming Language), OAuth, Open Web Application Security, Openid Connect, Tensorflow, Security Assertion Markup Language (SAML), Web Application Security, Scripting, Google Cloud, Delivery Pipeline, Software Security, Integration Frameworks, Machine Learning Operations, Devsecops, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** May 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c63a234b6982aa0d ## About the Role Do you have experience in Web Application Security Testing?, * 3-6+ years of experience in Application Security or Product Security * Hands-on experience with SAST, DAST, IAST tools * Strong knowledge of OWASP Top 10 vulnerabilities * Experience securing APIs and microservices * Experience with modern authentication and authorization protocols (OAuth 2.0, OpenID Connect, SAML) * Familiarity with CI/CD pipelines * Basic understanding of AI/ML systems * Security certification or willingness to obtain within 6 months, * Experience with ML frameworks is a plus * Familiarity with AI threat models * Experience with WAF, RASP, or API security solutions * Experience with cloud platforms (AWS, Azure, GCP) * Scripting skills (Python, Bash) ## Description We are seeking an AI Application Security Analyst to secure modern applications, including those leveraging machine learning and AI technologies. This role focuses on identifying, assessing, and mitigating vulnerabilities across the application lifecycle, with particular emphasis on AI-enabled applications and services. You will work closely with engineering teams to embed security into development pipelines, implement testing and runtime protections, and ensure that AI/ML components are resilient against emerging threats. What you'll do: * Perform application security assessments using SAST, DAST, and interactive testing tools * Identify, triage, and prioritize vulnerabilities across web, API, and microservices architectures * Integrate security testing into CI/CD pipelines (DevSecOps) * Assess security risks in AI/ML-enabled applications, including model exposure and inference endpoints * Identify vulnerabilities such as adversarial inputs, model abuse, and data poisoning * Secure AI APIs, plugins, and third-party integrations * Implement and tune WAF, RASP, and API security controls * Conduct threat modeling and secure design reviews for applications and AI use cases * Assess and harden identity and access flows ensuring least privilege * Partner with developers to remediate vulnerabilities and improve secure coding practices * Monitor and respond to application-layer security incidents, * Faster remediation cycles * Strong runtime protection * Secure AI feature deployment * Improved developer security practices Operational Expectations: * Participate in on-call rotation * Provide after-hours and weekend support * Respond to security alerts and incidents * Collaborate with teams during incident response What We Do We're a member-owned property and casualty insurer designed exclusively for financially successful families and driven by a purpose of doing what is right for our members. Our reciprocal model focuses on service and doing what is right for the membership: we provide exceptional service, hospitality and care, we partner with our members to help prevent losses and we create smart insurance solutions at fair prices. We aim for our members to love their insurance . It is our mission is to create a membership experience so compelling that our members never want to leave. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Get security done: streamlining application security with Aikido](https://www.wearedevelopers.com/videos/1638-get-security-done-streamlining-application-security-with-aikido) - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems)