Application Security AI Engineer

HonorVet Technologies
United States
about 1 month ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Bash Shell Software as a Service Static Program Analysis Code Review Continuous Integration Data Governance Programming Tools Python (Programming Language) Open Source Technology Package Management Systems
+18 more
Windows PowerShell Systems Development Life Cycle Software Engineering Software Vulnerability Management Software Repository Scripting Enterprise Software Applications Delivery Pipeline Large Language Models Software Security Model Validation Cyber Threat Analysis Enterprise Integration Devsecops Security Orchestration, Automation & Response Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

We are seeking an experienced Application Security AI Engineer to join a dynamic Application Security team. This role focuses on securing enterprise applications by managing application security vulnerabilities, supporting software supply chain security initiatives, and implementing AI-powered security solutions to improve vulnerability detection, analysis, and remediation. The ideal candidate will have strong hands-on experience with application security testing, vulnerability management, secure software development practices, and emerging AI-driven security technologies. Key Responsibilities

  • Perform application security triage across Software Composition Analysis (SCA), Static Application Security Testing (SAST), and Dynamic Application Security Testing (DAST) findings.
  • Validate and prioritize critical and high-risk vulnerabilities through exploitability analysis, false-positive verification, risk assessment, and remediation guidance.
  • Investigate and coordinate responses for critical security events, threat intelligence alerts, and emergency patching activities, ensuring timely mitigation and resolution.
  • Monitor newly disclosed vulnerabilities and emerging security threats, providing actionable recommendations to development and security teams.
  • Design, evaluate, and implement AI-assisted application security solutions that improve vulnerability detection, code analysis, remediation recommendations, and security workflow automation while maintaining appropriate human oversight.
  • Support the evaluation, testing, and secure adoption of AI-based security tools by conducting proof-of-concept assessments, validating security controls, reviewing data handling practices, and documenting governance requirements.
  • Enhance software supply chain security by securing open-source dependencies, managing Software Bill of Materials (SBOM), identifying malicious packages, evaluating dependency health, and enforcing security policies across development pipelines.
  • Improve the security of developer environments by assessing IDEs, plugins, extensions, package managers, code-assist tools, and CI/CD integrations for potential security risks and misconfigurations.
  • Develop automation using scripting, APIs, and security platform integrations to streamline application security operations and vulnerability management processes.
  • Collaborate closely with development, DevSecOps, and security teams to communicate security risks, recommend remediation strategies, and support secure software development practices.

Requirements

  • Minimum 3+ years of experience with Code Scanning.
  • Minimum 3+ years of experience with Software Composition Analysis (Open Source Scanning).
  • Minimum 3+ years of experience with Static (SAST) and Dynamic (DAST) Application Security Testing.
  • Strong experience triaging application security findings and managing high-severity vulnerabilities through remediation and closure.
  • Hands-on experience with scripting, automation, APIs, CI/CD pipelines, developer tools, or security platform integrations.
  • Practical experience working with AI-enabled security tools, large language models (LLMs), coding assistants, AI governance, model evaluation, or AI-assisted security workflows.
  • Solid understanding of software supply chain security, including open-source dependency management, SBOM, package security, and developer tooling protection.
  • Experience securing developer environments, including IDEs, plugins, package managers, CI/CD platforms, and code repositories.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent communication skills with the ability to explain technical security findings and remediation recommendations to both technical and non-technical stakeholders., * Application Security
  • Software Composition Analysis (SCA)
  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Code Scanning
  • Open Source Security
  • Vulnerability Management
  • Threat Intelligence
  • Software Supply Chain Security
  • Secure SDLC
  • AI Security Tools
  • Large Language Models (LLMs)
  • APIs & Automation
  • CI/CD Security
  • Developer Tooling Security
  • Scripting (Python, PowerShell, Bash, or similar)

Preferred Qualifications

  • Experience implementing AI-powered security solutions or security automation.
  • Knowledge of secure software development lifecycle (SSDLC) practices.
  • Familiarity with cloud application security and DevSecOps methodologies.
  • Experience working with enterprise vulnerability management platforms and modern application security tools.

About the company

HonorVet Technologies. We’‘re a veteran-owned IT staffing firm, ISO 9001 and ISO 27001 certified, working with federal agencies, state governments, and Fortune 500 enterprise clients across the US. What makes us different isn’‘t a tagline; it’’s the way we work. We don’‘t forward resumes and hope for the best. We take the time to understand where a professional like you is headed and only reach out when we genuinely believe there’’s a fit worth exploring.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · WWC 2022

1:29 min

Assisting security analysis using AI code review tools

Matteo Meucci Matteo Meucci · Europe 2026 Virtual

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney +2 · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all