> Markdown version of [/jobs/ext/2271341-manager-application-ai-security](https://www.wearedevelopers.com/jobs/ext/2271341-manager-application-ai-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager- Application & AI Security - **Company:** Everforth Apex - **Location:** Scottsdale, AZ, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Microsoft Azure, Software as a Service, Encodings, Cyber Security, Continuous Integration, Github, OAuth, Open Source Technology, Open Web Application Security, Platform as a Service (PAAS), Software Engineering, Large Language Models, Sonatype, Software Security, Veracode, Gitlab, Kubernetes, Information Technology, Checkmarx, Devsecops, Jenkins, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 27, 2026 - **Apply:** https://www.dice.com/job-detail/f9144b4f-2c92-4c44-a3b9-f7d39fef8ed5 ## About the Role * Bachelor's degree in Computer Science, Cybersecurity, or a related field, or a minimum of 7 years in security. * 5+ years in application security and/or DevSecOps, including team leadership. * Hands-on experience building security into CI/CD pipelines (e.g., Azure DevOps, GitHub Actions, GitLab, Jenkins) as guardrails-as-code. * Strong experience with application security testing across SAST, DAST, SCA/open-source, secrets scanning, and API security (e.g., Checkmarx, Veracode, Snyk). * Comprehensive knowledge of API security architecture and standards such as OAuth2, OWASP, and CIS. * Experience securing containers/Kubernetes and Infrastructure-as-Code, threat modeling, and generating SBOMs. * Working knowledge of AI/LLM security: usage governance, prompt-injection and jailbreak testing, LLM red-teaming, and MCP/AI-agent runtime controls. * Familiarity with AI governance frameworks such as NIST AI RMF and ISO 42001. * Ability to translate complex technology issues into language a wide range of audiences can understand. * CISSP or CCNP-Security required. Preferred Qualifications * CSSLP, CCSP, or CISM preferred. Work Environment This role allows for work in a general indoor office environment or working from home. The position involves using a personal computer/laptop and associated equipment. Physical requirements include sedentary work, with occasional walking and standing. Mental requirements include managing stress, making decisions under pressure, and handling multiple priorities. ## Description You will keep the organization's applications, cloud, and AI usage governed and secure-by-default, ensuring that delivery speed never outruns risk review. You will hold the central AI-governance mandate and own the DevSecOps golden pipelines, application security testing, and MCP/AI-agent runtime security, embedding guardrails as code and making safe AI adoption the default. Key Responsibilities * Own the secure software development lifecycle per NIST SSDF (SP 800-218) and ISO/IEC 27001:2022 A.8.25-A.8.31, including application security reviews for major releases and PaaS/SaaS application posture. * Own Contact Center tooling Security guardrails including the agent flows, member workflows and overall platform and call center security guardrails for member experience. * Own CI/CD golden-pipeline guardrails and pipeline/artifact integrity (SLSA), run pipeline monitoring, and manage application/pipeline PIM role assignments through the platform operated by Identity. * Run application security testing - API security, aligned to OWASP ASVS and the OWASP Top 10 / API Security Top 10 (ISO/IEC 27001:2022 A.8.29). * Own container/Kubernetes and IaC security scanning, threat modeling (OWASP SAMM), secure-code training, and SBOM generation for internally built applications (NIST SSDF; NTIA minimum elements). * Own cloud tenant security guardrails at the application/PaaS layer. * Hold the central AI-governance mandate - LLM/Copilot usage policy, local/public model governance, and data-leakage & shadow-AI controls - implementing NIST AI RMF and ISO/IEC 42001 technical controls with GRC. * Own the AI/model inventory and AI-BOM and the model registry and approval workflow. * Conduct prompt-injection / jailbreak testing and LLM red-teaming (OWASP Top 10 for LLM Applications; MITRE ATLAS). * Secure MCP and AI-agent runtimes: per-tool-call authorization, guardrails, and containment. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j)