> Markdown version of [/jobs/ext/2037628-lead-application-security-engineer-appsec-sme](https://www.wearedevelopers.com/jobs/ext/2037628-lead-application-security-engineer-appsec-sme). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Application Security Engineer (AppSec SME) - **Company:** THE JUDGE GROUP, INC. - **Location:** Charlotte, NC, United States - **Experience:** Expert - **Salary:** $185,120.0 - $197,600.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cloud Computing Security, Cloud Engineering, CompTIA Security+, Cyber Security, Information Systems, Continuous Integration, Data Centers, Information Leak Prevention, Information Systems Security Architecture Professional, Software Engineering, Software Vulnerability Management, Google Cloud, Enterprise Software Applications, Large Language Models, Software Security, Generative AI, Infrastructure as Code (IaC), Information Technology, Devsecops, Security Orchestration, Automation & Response, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 12, 2026 - **Apply:** https://www.dice.com/job-detail/80160561-3a4f-417e-9e9f-ebb2f873d099 ## About the Role * Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or related field, or equivalent practical experience. * 7+ years of experience in Application Security, Cybersecurity Engineering, or Information Security Engineering within large-scale enterprise environments. * Strong expertise in Secure Software Development Lifecycle (SSDLC) methodologies and controls. * Hands-on experience with: + Threat Modeling + Secure Architecture and Secure Design Reviews + Static Application Security Testing (SAST) + Software Composition Analysis (SCA) + Dynamic Application Security Testing (DAST) + Penetration Testing + Vulnerability Management * Proven experience developing and implementing enterprise security strategies. * Strong stakeholder management and leadership skills with the ability to drive outcomes through influence. * Experience working in Agile and DevSecOps environments., * Experience securing Generative AI (GenAI) and Large Language Model (LLM) applications. * Expertise in adversarial AI testing, prompt injection mitigation, and AI security frameworks. * Experience building AI-enabled security automation and intelligent security workflows. * Strong understanding of CI/CD pipeline security and cloud-native application security. * Experience within highly regulated industries, including financial services, banking, insurance, or healthcare. * Knowledge of cloud security architectures across AWS, Azure, and Google Cloud Platform (Google Cloud Platform). * Relevant industry certifications, including: + CISSP + CSSLP + CISM + GIAC Certifications + Equivalent cybersecurity certifications Technical Skills Application Security * SSDLC * Threat Modeling * Secure Design Reviews * SAST * SCA * DAST * Penetration Testing * Vulnerability Management DevSecOps & Automation * CI/CD Security * Security Automation * Infrastructure as Code (IaC) * Secure Pipelines * Developer Security Tooling AI Security * Generative AI Security * LLM Security * Prompt Injection Defense * Adversarial Testing * AI Model Validation * Model Risk Management * AI Governance Leadership * Security Strategy Development * Stakeholder Management * Cross-Functional Leadership * Program Management * Risk Assessment & Governance ## Description We are seeking a Senior Lead Application Security Engineer (AppSec SME) to lead the Application Security strategy supporting the Data Center Modernization and Simplification (DCMS) program. This role combines deep technical expertise with strategic leadership to strengthen enterprise application security, drive modernization initiatives, and implement innovative AI-powered security solutions. The ideal candidate will have extensive experience in Application Security, Secure Software Development Lifecycle (SSDLC) practices, DevSecOps, and emerging AI/GenAI security technologies. This individual will partner with engineering, architecture, development, and security teams to reduce risk, improve security posture, and enable secure software delivery at enterprise scale., Application Security Strategy & Governance * Define and execute the Application Security strategy for DCMS applications using risk-based and tiered control frameworks. * Assess existing Application Security controls and establish baseline security requirements across application portfolios. * Identify security gaps and develop remediation roadmaps in partnership with application owners and technical stakeholders. * Collaborate with Application Security Champions, development teams, and engineering leaders to drive adoption of security controls. * Ensure compliance with enterprise Secure Software Development Lifecycle (SSDLC) standards and vulnerability remediation requirements. * Establish metrics, reporting, and governance processes to measure security effectiveness and program maturity. AI & Generative AI Security Innovation * Identify, design, and implement AI-driven security solutions that improve coverage, efficiency, and risk reduction. * Develop automated threat modeling capabilities leveraging source code, infrastructure-as-code (IaC), architecture data, and application metadata. * Lead security assessments and adversarial testing of GenAI and Large Language Model (LLM) applications. * Design defenses against prompt injection, model abuse, unauthorized tool usage, data leakage, and secrets exposure. * Evaluate and implement AI model scanning, integrity validation, and secure model onboarding processes. * Research emerging AI security threats and apply best practices to enterprise environments. Application Security Modernization & Automation * Drive modernization initiatives through security automation, tool integration, and process optimization. * Build proof-of-concepts (POCs) and pilot programs to evaluate emerging security technologies. * Scale successful security solutions across enterprise environments. * Improve developer experience by simplifying security processes while maintaining strong risk management controls. * Advance DevSecOps capabilities through seamless integration with CI/CD pipelines and developer workflows. Leadership & Strategic Influence * Serve as a trusted security advisor to senior technology and business leaders. * Provide recommendations on Application Security priorities, investments, and risk management strategies. * Lead cross-functional initiatives and influence stakeholders without direct reporting authority. * Mentor engineering teams on secure design principles and security best practices. * Translate emerging technologies, threat intelligence, and industry trends into actionable security strategies. ## Related Videos - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [The Sustainability Race: AI's Promises, Pitfalls and Potential](https://www.wearedevelopers.com/videos/100155-the-sustainability-race-ai-s-promises-pitfalls-and-potential) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Dev Digest 196: AI Killed DevOps, LLM Political Bias & AI Security](https://www.wearedevelopers.com/magazine/659-dev-digest-196-ai-killed-devops-llm-political-bias-ai-security)