> Markdown version of [/jobs/ext/2632856-application-security-architect-ai-harness](https://www.wearedevelopers.com/jobs/ext/2632856-application-security-architect-ai-harness). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Architect - AI Harness - **Company:** Edward D. Jones & Co., L.P. - **Location:** Tempe, AZ, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Software System Penetration Testing, Audit Trail, Cloud Computing Security, Static Program Analysis, Code Review, Cyber Security, Continuous Integration, Github, Open Source Technology, Open Web Application Security, Systems Development Life Cycle, Regression Testing, Secure Coding, Software Engineering, Toolchain, Data Logging, IT General Controls (ITGC), Large Language Models, Prompt Engineering, Software Security, Model Validation, GWAPT, AI Platforms, Information Technology, Atlassian Tools, Github Enterprise, Production Code, Software Version Control, Devsecops, Jenkins, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 18, 2026 - **Apply:** https://dejobs.org/x/x/7444E566B06B443D9037FAF69BED465A/job/ ## About the Role * Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, Information Technology, Engineering, or related field. * 10+ years of experience in application security, secure software engineering, DevSecOps, security architecture, or related cybersecurity roles. * Deep expertise in secure code review, vulnerability detection, threat modeling, exploitability analysis, and secure SDLC practices. * Experience with performing vulnerability and penetration test readouts/walkthroughs with stakeholders. * Hands-on experience with SAST, SCA, DAST, secrets scanning, API security testing, container security, infrastructure-as-code scanning, and developer workflow integrations. * Experience integrating security capabilities into SDLC pipeline tooling: Jenkins, GitHub Actions, GitHub Enterprise, Atlassian, developer portals, source-control workflows, and DevSecOps toolchains. * Practical experience using LLMs or AI models for code review, software engineering, vulnerability research, security analysis, or developer productivity use cases. * Understanding of prompt engineering and optimization, RAG, model evaluation, AI guardrails, human-in-the-loop review, prompt/model versioning, and vendor/open-source model trade-offs. * Experience designing or maintaining evaluation harnesses, benchmark suites, regression tests, validation pipelines, and test orchestration workflows. * Strong understanding of concepts: OWASP, CWE, CVSS, NIST SSDF, AI security risks, regulated source-code handling, auditability, and vendor/model governance. What Could Set You Apart: * Master's degree or relevant certifications such as CISSP, CSSLP, OSWE, GWAPT, CCSP, cloud security, Kubernetes security, or AI governance certifications. * Experience delivering AI-assisted AppSec capabilities in a Fortune 500 or highly regulated financial services environment. * Hands-on experience with enterprise AI platforms, approved vendor models, open-source models, secure hosting, RAG, and AI governance controls. * Experience building secure code review automation, custom static analysis rules, vulnerability detection pipelines, benchmark datasets, or AI-based developer tooling. * Demonstrated success reducing AppSec risk through improved detection accuracy, lower false positives, faster remediation, and stronger developer enablement. ## Description The Application Security Architect, Agentic Secure Code Architect is a hands-on architecture-focused IC responsible for designing, integrating, maintaining, and improving a CI/CD-integrated AI evaluation harness used to assess application and infrastructure source code for security vulnerabilities and insecure-design practices. This role combines AppSec, DevSecOps, AI engineering, secure SDLC governance, and financial-services compliance, with strong emphasis on source-code protection, enterprise controls governance, repeatability, auditability, measurable risk reduction, and developer trust. What You'll Do: * Architect the CI/CD-integrated AI secure-code evaluation harness as a hands-on IC for source code repositories and Secure SDLC lifecycles. * Integrate evaluation workflows with pipeline tooling and AppSec reporting platforms. * Design AI-assisted secure code review methods that complement SAST, SCA, DAST, secrets scanning, IaC scanning, threat modeling, security testing, and manual assessments. * Maintain benchmarks, golden test cases, prompt/model versions, retrieval configurations, scoring criteria, and regression tests for AI-generated findings. * Govern approved vendor and frontier AI models, including selection, routing, fallback patterns, accuracy, explainability, cost, and data-protection trade-offs. * Define safeguards for proprietary production code, including access controls, approved model endpoints, minimization, retention limits, secure logging, and evidence handling. * Route validated findings into developer workflows with actionable remediation guidance and feedback loops to reduce false positives and improve adoption. * Define metrics and control evidence aligned to internal governance processes, financial services industries authorities, and cyber security frameworks (NIST SSDF, NIST CSF 2.0, NYDFS, FINRA, SOX ITGC, FFIEC, GLBA). ## Related Videos - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)