builder-minded Application Security Engineer

Cvent
United States
9 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$120,000.0 - $160,000.0
Working hours
Regular working hours
Job source

Tech stack

JavaScript (Programming Language) Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Software System Penetration Testing JIRA Microsoft Azure Bash Shell Burp Suite Cloud Computing Cloud Computing Security Cloud Engineering
+25 more
Code Review Computer Programming Continuous Integration Software Design Documents Python (Programming Language) Open Web Application Security Systems Development Life Cycle Fortify (Software) Secure Coding Software Engineering TypeScript Software Vulnerability Management AWS Cdk Google Cloud Large Language Models Software Security Mitre Att&ck Veracode Build Management Machine Learning Operations Checkmarx Devsecops Security Orchestration, Automation & Response Static Application Security Testing Dynamic Application Security Testing

Job description

We’re seeking a senior, builder-minded Application Security Engineer who can go deep on hard technical problems while setting the direction for how AI reshapes a security program. This isn’t someone who just uses AI tooling - it’s someone who architects it: agentic systems that automate threat modeling end to end, AI-assisted vulnerability management, and self-serve security capabilities that change how an engineering org works. The ideal candidate is equally credible doing a rigorous design review, writing the automation that scales it, and communicating the resulting risk decisions to leadership. This role owns product security for the teams it partners with - they look to this person as the accountable security voice for their roadmap.

In This Role, You Will:

  • Architect and own AI-first security automation - design agentic systems and skills that take security work from intake (e.g., a Jira epic or design doc) through analysis to logged risk and published findings, with minimal manual handoff.
  • Lead the development of security agents and AI tooling - define the architecture for LLM-integrated workflows (via APIs and MCP connectors), set patterns for tool/function design, and decide build-vs-buy across the toolchain.
  • Drive AI-assisted threat modeling at scale - benchmark custom solutions against off-the-shelf agents, embed methodologies (STRIDE, PASTA, LINDDUN, MITRE ATT&CK) into automation, and make pentest scoping decisions defensible and repeatable.
  • Set the standard for AI feature security - define coverage models and assessment criteria for GenAI and AI/ML features, applying the OWASP LLM Top 10, OWASP AI Testing Guide, and MITRE ATLAS to real product risk.
  • Own integration and scaling of SAST, DAST, and SCA across CI/CD, including AI-assisted triage layers that cut noise and accelerate remediation.
  • Perform and lead deep secure design reviews, code reviews, threat modeling, and penetration testing for complex and high-risk systems, including cloud-native and AI-driven architectures.
  • Own product security for an assigned product area or portfolio - serve as the accountable security partner for those teams, drive their threat modeling, design reviews, and risk decisions end to end, and own the security posture and remediation outcomes for that scope.
  • Mentor Engineer II and mid-level teammates, review their automation and findings, and grow the team’s AI and AppSec capability.
  • Communicate risk clearly to both engineering and leadership audiences, and support compliance efforts across ISO 27001, SOC 2, and PCI., * You’ll define how AI transforms Application Security at scale - architecting automation and agents that change how an entire engineering org ships secure software.
  • You’ll join the ASRE team to innovate at the forefront of AI-assisted AppSec, with the autonomy to set technical direction.
  • You’ll work with teams who take security seriously and back you to drive meaningful, lasting change.
  • You’ll have both technical depth and leadership impact, with a path to grow into staff-level or lead roles.

Requirements

  • 5+ years of hands-on experience in application security or secure software development, with demonstrated technical ownership.
  • Strong scripting/programming skills - the ability to design and build non-trivial internal tools and automation in Python, JavaScript/TypeScript, or Bash.
  • Proven experience integrating security tooling into CI/CD and the SDLC, and improving it over time.
  • Strong familiarity with cloud platforms (AWS preferred; Google Cloud Platform or Azure acceptable) and cloud-native security, including securing applications built with AWS CDK / IaC.
  • Proficiency with security testing and cloud security tools (e.g., Burp Suite, Checkmarx, Mend, Veracode, Fortify, ZAP, Wiz) and the judgment to know when manual testing beats automation.
  • Deep understanding of the OWASP Top 10, CWE, SANS Top 25, secure coding practices, and web/API vulnerability classes.
  • Demonstrated end-to-end ownership of at least one security tool, automation, or agentic/LLM-integrated workflow that is used in production or relied on by a team - designed, shipped, and depended on by others. This is the primary, screenable differentiator from the Engineer II role.

Bonus If You Have:

  • Experience securing AI/ML pipelines and a working understanding of adversarial ML, prompt injection, and agent-misuse risk.
  • DevSecOps, IaC security, or supply-chain depth, and senior-relevant certifications (e.g., OSWE, OSCP, AWS Security - Specialty, CISSP).

Benefits & conditions

The estimated base salary range for new hires into this role is $120,000 - $160,000 annually + bonus depending on factors such as job-related knowledge, relevant experience, and location. We also offer a competitive benefits package, details of which can be found here.

About the company

Cvent is a leading meetings, events, and hospitality technology provider with more than 5,500+ employees and ~30,000 customers worldwide, including 60% of the Fortune 500. Founded in 1999, Cvent delivers a comprehensive event marketing and management platform for marketers and event professionals and offers software solutions to hotels, special event venues and destinations to help them grow their group/MICE and corporate travel business. Our technology brings millions of people together at events around the world. In short, we’re transforming the meetings and events industry through innovative technology that powers the human connection.

Cvent’s strength lies in its people, fostering a culture where everyone is encouraged to think like entrepreneurs, taking risks and making decisions confidently. We value diverse perspectives and celebrate differences, working together with colleagues and clients to build strong connections.

AI at Cvent: Leading the Future

Are you ready to shape the future of work at the intersection of human expertise and AI innovation? At Cvent, we’re committed to continuous learning and adaptation-AI isn’t just a tool for us, it’s part of our DNA. We’re looking for candidates who are eager to evolve alongside technology. If you love to experiment boldly, share your discoveries, and help define best practices for AI-augmented work, you’ll thrive here. Our team values professionals who thoughtfully integrate AI into their daily work, delivering exceptional results while relying on the human judgment and creativity that drive real innovation.

Throughout our interview process, you’ll have the chance to demonstrate how you use AI to learn, iterate, and amplify your impact. If you’re excited to be part of a team that’s leading the way in AI-powered collaboration, we’d love to meet you.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:15 min

Correlating OpenSSF scorecard metrics with real vulnerability data

Niels Tanis Niels Tanis · WWC 2024

3:35 min

Defining a serverless architecture using AWS CDK

Raphael Manke Raphael Manke · WWC 2023

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

2:41 min

Dynamic application security testing during the test phase

Milecia Mcgregor · LIVE

1:36 min

Managing infrastructure as code with AWS CDK

Markus Ziller Markus Ziller · WWC 2024

Videos

See all

Related articles

See all