> Markdown version of [/jobs/ext/2867513-information-security-engineer-application-security](https://www.wearedevelopers.com/jobs/ext/2867513-information-security-engineer-application-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Engineer (Application Security) - **Company:** Lam Research International Holding Company - **Location:** Fremont, CA, United States (Remote available) - **Experience:** Experienced - **Salary:** $92,000.0 - $211,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Software Applications, Software System Penetration Testing, User Authentication, Microsoft Azure, Code Review, Cyber Security, Data Validation, Information Leak Prevention, DevOps, Programming Tools, Key Management, Open Web Application Security, Systems Development Life Cycle, Software Tools, Secure Coding, Software Engineering, Software Vulnerability Management, Data Logging, Software Security, Git, Kubernetes, Information Technology, Bitbucket, Machine Learning Operations, Devsecops, Jenkins, Static Application Security Testing, Vulnerability Analysis, Artifactory, Dynamic Application Security Testing - **Published:** September 12, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87622980/1 ## About the Role * Bachelor's degree in computer science, Information Security, Information Technology, Engineering, or related field, or equivalent practical experience. * 3+ years of experience in information security, application security, product security, software engineering, DevSecOps, or related technical field. * Working knowledge of Secure SDLC practices, including threat modeling, secure design review, code review, vulnerability assessment, and security testing. * Familiarity with common application security frameworks and risks, including OWASP Top 10, API security, authentication/authorization, input validation, secrets management, and secure coding practices. * Hands-on or working experience with one or more application security tools such as SAST, DAST, SCA, secrets scanning, container scanning, or vulnerability management platforms. * Basic understanding of CI/CD pipelines and developer tools such as Git, Bitbucket, Jenkins, Azure DevOps, Artifactory, or similar platforms. * Ability to analyze technical information, identify security risks, and communicate findings clearly to engineering and security stakeholders. * Strong collaboration skills and ability to work with cross-functional global teams. Preferred qualifications * Experience supporting security reviews for cloud, product, or manufacturing/engineering software environments. * Experience with Azure, Microsoft DevOps, Kubernetes, containers, APIs, or modern application architectures. * Exposure to AI/ML security concepts, including generative AI, RAG, AI agents, model governance, prompt injection, model/data leakage, AI-assisted coding, and secure MLOps. * Familiarity with security requirements for AI-enabled applications, including approved model usage, data minimization, access control, logging, monitoring, human oversight, and secure tool/plugin integration. * Experience helping engineering teams remediate application vulnerabilities and validate fixes. * Security certifications such as Security+, CSSLP, CISSP, GIAC, or similar are preferred but not required. * Ability to break down complex security problems, document practical recommendations, and contribute to repeatable security review processes. ## Description This position will be part of Lam Information Security's Application Security team, supporting Secure SDLC, product security, application risk assessments, threat modeling, vulnerability validation, penetration testing, and AI-related security initiatives across Lam-developed applications and AI-enabled solutions. The impact you'll make This position will increase Lam's Application Security and Product Security capacity by helping scale Secure SDLC reviews, application risk assessments, threat modeling, vulnerability validation, penetration testing, and AI-related security reviews. The role will help reduce security risk earlier in the development lifecycle, improve consistency across Lam-developed applications and AI-enabled solutions, and support engineering teams in delivering secure software with appropriate controls for data, access, AI model usage, logging, and human oversight. What you'll do * Support the objectives of the Application Security team by contributing to secure design, Secure SDLC execution, and product security reviews. * Assist with application risk assessments, secure design reviews, threat modeling, code review, vulnerability assessment, and penetration testing. * Support the integration and operational use of application security tools, including SAST, SCA and DAST, and other DevSecOps capabilities in CI/CD pipelines. * Work with development teams to identify and document security requirements, common application risks, and required controls based on application risk level, data sensitivity, exposure, and system interconnections. * Help engineering teams interpret and apply secure coding standards, OWASP guidance, internal Secure SDLC requirements, and product security best practices. * Assist in reviewing AI-related security risks, including prompt injection, insecure model/tool integration, data leakage, excessive autonomy, insecure AI outputs, model sourcing, sensitive data exposure, and lack of human-in-the-loop controls. * Participate in AI-related security initiatives, including secure AI model usage, AI-assisted development governance, AI-enabled application review, and secure MLOps process improvement. * Research, evaluate, and help pilot new security capabilities, automation, and AI-assisted AppSec workflows under guidance from senior security engineers. * Document findings, recommendations, and review outcomes clearly for application teams, security leadership, and governance tracking. * Partner with cross-functional teams to improve secure development practices and reduce application and product security risk. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)