> Markdown version of [/jobs/ext/596800-senior-ai-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/596800-senior-ai-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior AI & Application Security Engineer - **Company:** National Futures Association - **Location:** Chicago, IL, United States - **Experience:** Expert - **Salary:** $152,950.0 - $272,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Application Firewall, Application Layers, Software Applications, Application Testing, User Authentication, Automation of Tests, Cloud Computing Security, Cloud Engineering, Code Review, Cyber Security, DDoS Mitigation, Programming Tools, Information Systems Security Architecture Professional, Network Architecture, Open Web Application Security, Systems Development Life Cycle, Cloud Services, Zero Trust Network Access, Secure Coding, Web Application Security, Software Engineering, Systems Integration, Software Vulnerability Management, Web Applications, Spring Cloud, Large Language Models, Software Security, Generative AI, Containerization, Cloudflare, Software Coding, Ddos, Devsecops, Vulnerability Analysis, Programming Languages - **Published:** June 20, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=57c714636c62e5e2 ## About the Role Do you have experience in Threat Modeling (Architecture security)?, * Hands on experience reviewing and writing code in one or more modern programming languages. * Strong knowledge of secure coding practices, threat modeling, vulnerability management, and Secure SDLC methodologies. * Expertise with OWASP Top 10, API Security, authentication, authorization, and application layer security controls. * Experience securing and assessing cloud-native applications and architectures within various cloud platforms, as well as designing secure AI/LLM technologies. * Experience architecting, implementing, and maintaining Cloudflare-based security protections, including WAF, API security, DDoS defenses, and other web application security controls. * Strong communications skills with the ability to influence technical teams and drive security initiatives across the organization. * Demonstrated experience guiding secure applications through the full lifecycle from requirements gathering, and architecture reviews to design, development, deployment, remediation and on-going optimization. * Deep knowledge of how applications reside and interact across the cloud, network, an infrastructure environment, enabling the development of comprehensive security strategies and roadmaps. * Experience interpreting and implementing enterprise security architecture principles and governance frameworks, with practical application of NIST SP 800-53, NIST Cybersecurity Framework (CSF) 2.0, NIST AI Risk Management Framework (AI RMF), NIST SP 800-218 (SSDF), and NIST SP 800-207 within application security programs. ## Description When you join NFA as a Senior AI & Application Security Engineer, you'll play a critical role in advancing secure-by-design practices across our applications, APIs, cloud platforms, and emerging AI solutions. You will be a hands-on technical leader and subject matter expert developing, designing, and automating secure applications while partnering closely with developers, architects, data, and governance teams. Your expertise will help protect business critical systems while enabling innovation through secure development practices and modern security architecture. Bring your analytical and innovative mindset to identify and mitigate security risks across traditional and AI-enabled applications. This role requires deep knowledge of application security principles, including OWASP Top 10, API security, threat modeling, secure coding practices, vulnerability management, and application testing tools. You will leverage your experience with Large Language Models (LLMs), Generative AI, and cloud native technologies to help establish security standards, evaluate emerging risks, and guide secure adaptation of AI capabilities across the organization. Beginning your first day, and throughout your career at NFA, you will work closely with development and architecture teams to create secure applications, perform code reviews, assess cloud security controls, and strengthen our security posture through automation and DevSecOps practices. You will serve as a trusted advisor on Cloudflare security architecture, Web Application Firewall (WAF) technologies, secure API design, and cloud security while helping teams deliver scalable, resilient, and secure solutions that support our mission at NFA. What you'll do: In this role you will lead the secure design and implementation of both traditional enterprise and AI-powered applications by integrating security throughout the SDLC, performing architecture reviews, threat modeling, and application security testing across cloud and AI environments. In addition, you will: * Lead application security architecture reviews, threat modeling exercises, vulnerability assessments, and secure design assessments for web applications, APIs, cloud native platforms, and AI-enabled solutions * Develop the vision, roadmap, and operating model for securing applications, that illustrates how applications, integrations, cloud services, infrastructure, and network architecture work together as a cohesive ecosystem. * Partner across technology and business teams to define security standards, identify emerging risk, implement proactive controls while developing meaningful metrics that demonstrate risk reduction and program effectiveness. * Perform secure code reviews and implement remediation of application vulnerabilities. * Assess and mitigate risks associated with Large Language Models (LLMs), Generative AI, AI agents, and AI assisted development tools. * Develop, maintain, and adapt to application security standards that are aligned with OWASP Top 10, and industry best practices. * Utilize security testing tools including BURP, to identify vulnerabilities, validate security controls, and follow through with remediation. * Design, implement, and optimize Cloudflare security services including WAF, API security, DDoS protection, and Zero Trust capabilities. * Integrate security controls automated testing, and policy validation into CI/CD pipelines and DevSecOps workflows. * Collaborate with engineering teams to secure cloud environments and applications hosted in diverse cloud platforms. * Serve as a SME on application security, AI security, cloud security, and secure software development practices. * Present security assessments, risk findings, and strategic recommendations to senior leadership and key stakeholders, translating complex technical concepts into actionable outputs. ## Related Videos - [Fireside Chat with Cloudflare's Chief Strategy Officer, Stephanie Cohen (with Mike Butcher MBE)](https://www.wearedevelopers.com/videos/1366-fireside-chat-with-cloudflare-s-chief-strategy-officer-stephanie-cohen-with-mike-butcher-mbe) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [WebAssembly: The Next Frontier of Cloud Computing](https://www.wearedevelopers.com/videos/886-webassembly-the-next-frontier-of-cloud-computing) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)