Security Engineer

Bloomberg Industry Group
United States
4 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) JavaScript (Programming Language) Artificial Intelligence Software System Penetration Testing Architectural Patterns Cloud Computing Security Cloud Engineering Code Review Cyber Security DevOps Information Systems Security Architecture Professional Python (Programming Language)
+15 more
Machine Learning Open Web Application Security Systems Development Life Cycle Software Engineering Spring Cloud Large Language Models Software Security Kubernetes Devsecops Serverless Computing Static Application Security Testing Vulnerability Analysis Programming Languages Microservices Dynamic Application Security Testing

Job description

This role will require you to lead security engineering initiatives, perform advanced risk assessments, and design scalable security controls across critical applications. You will serve as a subject matter expert (SME) in application, guiding engineering teams, influencing security strategy, and driving automation across the SDLC. This role requires deep technical expertise, leadership potential, and the ability to shape long term Application Security direction. Key Responsibilities Design and implement security architectures and controls for large-scale, cloud-native applications. Conduct in-depth risk assessments, including penetration testing and code reviews. Collaborate with developers and DevOps teams to integrate security at all stages of the software development lifecycle (SDLC). Drive security for AI-powered features by defining secure architectures, assessing AI/ML risks, and implementing advanced testing and controls for AI models, agents, and MCP servers. Identify areas of improvements in security tools and practices, and remediate the identified gap by implementing innovative solutions. Evaluate third party security tools and vendor provided controls for technical effectiveness, enterprise fit, and alignment with organization s security architecture and standards. Collaborate with vendors to provide actionable technical feedback, drive product improvements, and ensure controls are implemented and configured appropriately for Bloomberg Industry Group s environment. Build, improve, and scale security automation, integrating tooling across CI/CD pipelines and cloud platforms. Provide guidance to junior engineers and cross-functional teams on security best practices. Participate in incident response efforts and investigations into security incidents. Stay ahead of the curve by keeping informed of industry trends and emerging threats, applying this knowledge to continually improve security

Requirements

6 years of relevant experience in Application Security, AppSec engineering, Cloud Security, or Software Engineering Deep expertise in application security, secure software design, and risk management, including frameworks such as OWASP ASVS, OWASP Top 10, and NIST 80053. Extensive experience conducting complex security assessments and building automated security controls for large engineering environments. Proficiency in multiple programming languages (e.g., Python, Java, JavaScript) and hands-on experience with SAST, DAST, SCA, IaC, container, and cloud security tools. Strong understanding of modern architectures (cloud-native, microservices, Kubernetes, containers, serverless) and DevSecOps processes. Advanced understanding of AI/ML security, including model vulnerability analysis, AI threat modeling, secure LLM integration patterns, and familiarity with NIST AI RMF or OWASP Top 10 for LLMs

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Analyzing differences between mobile and traditional backend DevOps

Mete Baydar Mete Baydar · World Congress 2025

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:15 min

Deploying local container pods to Kubernetes clusters

Stevan Le Meur Stevan Le Meur · World Congress 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:27 min

Defining DevOps through its historical origins and foundational texts

Sonal Patil · LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all