Lead Application Security Engineer (AppSec SME)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+15 more
Job description
We are seeking a Senior Lead Application Security Engineer (AppSec SME) to lead the Application Security strategy supporting the Data Center Modernization and Simplification (DCMS) program. This role combines deep technical expertise with strategic leadership to strengthen enterprise application security, drive modernization initiatives, and implement innovative AI-powered security solutions.
The ideal candidate will have extensive experience in Application Security, Secure Software Development Lifecycle (SSDLC) practices, DevSecOps, and emerging AI/GenAI security technologies. This individual will partner with engineering, architecture, development, and security teams to reduce risk, improve security posture, and enable secure software delivery at enterprise scale., Application Security Strategy & Governance
- Define and execute the Application Security strategy for DCMS applications using risk-based and tiered control frameworks.
- Assess existing Application Security controls and establish baseline security requirements across application portfolios.
- Identify security gaps and develop remediation roadmaps in partnership with application owners and technical stakeholders.
- Collaborate with Application Security Champions, development teams, and engineering leaders to drive adoption of security controls.
- Ensure compliance with enterprise Secure Software Development Lifecycle (SSDLC) standards and vulnerability remediation requirements.
- Establish metrics, reporting, and governance processes to measure security effectiveness and program maturity.
AI & Generative AI Security Innovation
- Identify, design, and implement AI-driven security solutions that improve coverage, efficiency, and risk reduction.
- Develop automated threat modeling capabilities leveraging source code, infrastructure-as-code (IaC), architecture data, and application metadata.
- Lead security assessments and adversarial testing of GenAI and Large Language Model (LLM) applications.
- Design defenses against prompt injection, model abuse, unauthorized tool usage, data leakage, and secrets exposure.
- Evaluate and implement AI model scanning, integrity validation, and secure model onboarding processes.
- Research emerging AI security threats and apply best practices to enterprise environments.
Application Security Modernization & Automation
- Drive modernization initiatives through security automation, tool integration, and process optimization.
- Build proof-of-concepts (POCs) and pilot programs to evaluate emerging security technologies.
- Scale successful security solutions across enterprise environments.
- Improve developer experience by simplifying security processes while maintaining strong risk management controls.
- Advance DevSecOps capabilities through seamless integration with CI/CD pipelines and developer workflows.
Leadership & Strategic Influence
- Serve as a trusted security advisor to senior technology and business leaders.
- Provide recommendations on Application Security priorities, investments, and risk management strategies.
- Lead cross-functional initiatives and influence stakeholders without direct reporting authority.
- Mentor engineering teams on secure design principles and security best practices.
- Translate emerging technologies, threat intelligence, and industry trends into actionable security strategies.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or related field, or equivalent practical experience.
- 7+ years of experience in Application Security, Cybersecurity Engineering, or Information Security Engineering within large-scale enterprise environments.
- Strong expertise in Secure Software Development Lifecycle (SSDLC) methodologies and controls.
- Hands-on experience with:
- Threat Modeling
- Secure Architecture and Secure Design Reviews
- Static Application Security Testing (SAST)
- Software Composition Analysis (SCA)
- Dynamic Application Security Testing (DAST)
- Penetration Testing
- Vulnerability Management
- Proven experience developing and implementing enterprise security strategies.
- Strong stakeholder management and leadership skills with the ability to drive outcomes through influence.
- Experience working in Agile and DevSecOps environments., * Experience securing Generative AI (GenAI) and Large Language Model (LLM) applications.
- Expertise in adversarial AI testing, prompt injection mitigation, and AI security frameworks.
- Experience building AI-enabled security automation and intelligent security workflows.
- Strong understanding of CI/CD pipeline security and cloud-native application security.
- Experience within highly regulated industries, including financial services, banking, insurance, or healthcare.
- Knowledge of cloud security architectures across AWS, Azure, and Google Cloud Platform (Google Cloud Platform).
- Relevant industry certifications, including:
- CISSP
- CSSLP
- CISM
- GIAC Certifications
- Equivalent cybersecurity certifications
Technical Skills Application Security
- SSDLC
- Threat Modeling
- Secure Design Reviews
- SAST
- SCA
- DAST
- Penetration Testing
- Vulnerability Management
DevSecOps & Automation
- CI/CD Security
- Security Automation
- Infrastructure as Code (IaC)
- Secure Pipelines
- Developer Security Tooling
AI Security
- Generative AI Security
- LLM Security
- Prompt Injection Defense
- Adversarial Testing
- AI Model Validation
- Model Risk Management
- AI Governance
Leadership
- Security Strategy Development
- Stakeholder Management
- Cross-Functional Leadership
- Program Management
- Risk Assessment & Governance
About the company
Vendor Opportunities: TEKsystems, Judge Group, Experis, Dexian, Motion Recruitment, Innova Solutions
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud
Dev Digest 121 - AI goes offline
Dev Digest 120 - Apple and peers
How to Become an AI Engineer