Lead Application Security Engineer (AppSec SME)

THE JUDGE GROUP, INC.
Charlotte, NC, United States
2 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$185,120.0 - $197,600.0
Working hours
Regular working hours
Job source

Tech stack

Agile Methodology Artificial Intelligence Amazon Web Services Software System Penetration Testing Microsoft Azure Cloud Computing Security Cloud Engineering CompTIA Security+ Cyber Security Information Systems Continuous Integration Data Centers
+15 more
Information Leak Prevention Information Systems Security Architecture Professional Software Engineering Software Vulnerability Management Google Cloud Enterprise Software Applications Large Language Models Software Security Generative AI Infrastructure as Code (IaC) Information Technology Devsecops Security Orchestration, Automation & Response Static Application Security Testing Dynamic Application Security Testing

Job description

We are seeking a Senior Lead Application Security Engineer (AppSec SME) to lead the Application Security strategy supporting the Data Center Modernization and Simplification (DCMS) program. This role combines deep technical expertise with strategic leadership to strengthen enterprise application security, drive modernization initiatives, and implement innovative AI-powered security solutions.

The ideal candidate will have extensive experience in Application Security, Secure Software Development Lifecycle (SSDLC) practices, DevSecOps, and emerging AI/GenAI security technologies. This individual will partner with engineering, architecture, development, and security teams to reduce risk, improve security posture, and enable secure software delivery at enterprise scale., Application Security Strategy & Governance

  • Define and execute the Application Security strategy for DCMS applications using risk-based and tiered control frameworks.
  • Assess existing Application Security controls and establish baseline security requirements across application portfolios.
  • Identify security gaps and develop remediation roadmaps in partnership with application owners and technical stakeholders.
  • Collaborate with Application Security Champions, development teams, and engineering leaders to drive adoption of security controls.
  • Ensure compliance with enterprise Secure Software Development Lifecycle (SSDLC) standards and vulnerability remediation requirements.
  • Establish metrics, reporting, and governance processes to measure security effectiveness and program maturity.

AI & Generative AI Security Innovation

  • Identify, design, and implement AI-driven security solutions that improve coverage, efficiency, and risk reduction.
  • Develop automated threat modeling capabilities leveraging source code, infrastructure-as-code (IaC), architecture data, and application metadata.
  • Lead security assessments and adversarial testing of GenAI and Large Language Model (LLM) applications.
  • Design defenses against prompt injection, model abuse, unauthorized tool usage, data leakage, and secrets exposure.
  • Evaluate and implement AI model scanning, integrity validation, and secure model onboarding processes.
  • Research emerging AI security threats and apply best practices to enterprise environments.

Application Security Modernization & Automation

  • Drive modernization initiatives through security automation, tool integration, and process optimization.
  • Build proof-of-concepts (POCs) and pilot programs to evaluate emerging security technologies.
  • Scale successful security solutions across enterprise environments.
  • Improve developer experience by simplifying security processes while maintaining strong risk management controls.
  • Advance DevSecOps capabilities through seamless integration with CI/CD pipelines and developer workflows.

Leadership & Strategic Influence

  • Serve as a trusted security advisor to senior technology and business leaders.
  • Provide recommendations on Application Security priorities, investments, and risk management strategies.
  • Lead cross-functional initiatives and influence stakeholders without direct reporting authority.
  • Mentor engineering teams on secure design principles and security best practices.
  • Translate emerging technologies, threat intelligence, and industry trends into actionable security strategies.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or related field, or equivalent practical experience.
  • 7+ years of experience in Application Security, Cybersecurity Engineering, or Information Security Engineering within large-scale enterprise environments.
  • Strong expertise in Secure Software Development Lifecycle (SSDLC) methodologies and controls.
  • Hands-on experience with:
  • Threat Modeling
  • Secure Architecture and Secure Design Reviews
  • Static Application Security Testing (SAST)
  • Software Composition Analysis (SCA)
  • Dynamic Application Security Testing (DAST)
  • Penetration Testing
  • Vulnerability Management
  • Proven experience developing and implementing enterprise security strategies.
  • Strong stakeholder management and leadership skills with the ability to drive outcomes through influence.
  • Experience working in Agile and DevSecOps environments., * Experience securing Generative AI (GenAI) and Large Language Model (LLM) applications.
  • Expertise in adversarial AI testing, prompt injection mitigation, and AI security frameworks.
  • Experience building AI-enabled security automation and intelligent security workflows.
  • Strong understanding of CI/CD pipeline security and cloud-native application security.
  • Experience within highly regulated industries, including financial services, banking, insurance, or healthcare.
  • Knowledge of cloud security architectures across AWS, Azure, and Google Cloud Platform (Google Cloud Platform).
  • Relevant industry certifications, including:
  • CISSP
  • CSSLP
  • CISM
  • GIAC Certifications
  • Equivalent cybersecurity certifications

Technical Skills Application Security

  • SSDLC
  • Threat Modeling
  • Secure Design Reviews
  • SAST
  • SCA
  • DAST
  • Penetration Testing
  • Vulnerability Management

DevSecOps & Automation

  • CI/CD Security
  • Security Automation
  • Infrastructure as Code (IaC)
  • Secure Pipelines
  • Developer Security Tooling

AI Security

  • Generative AI Security
  • LLM Security
  • Prompt Injection Defense
  • Adversarial Testing
  • AI Model Validation
  • Model Risk Management
  • AI Governance

Leadership

  • Security Strategy Development
  • Stakeholder Management
  • Cross-Functional Leadership
  • Program Management
  • Risk Assessment & Governance

About the company

Vendor Opportunities: TEKsystems, Judge Group, Experis, Dexian, Motion Recruitment, Innova Solutions

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · World Congress 2024

51 sec

Repurposing hardware and operating underwater data centers

Chris Heilmann +1 · LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

4:42 min

Container hosting options available on Google Cloud Platform

Federico Fregosi · World Congress 2022

4:03 min

Managing massive power consumption scaling in AI data centers

Stephan Gillich Stephan Gillich +3 · World Congress 2024

Videos

See all

Related articles

See all