> Markdown version of [/jobs/ext/913109-application-security-ai-engineer](https://www.wearedevelopers.com/jobs/ext/913109-application-security-ai-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security AI Engineer - **Company:** HonorVet Technologies - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Temporary contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Bash Shell, Software as a Service, Static Program Analysis, Code Review, Continuous Integration, Data Governance, Programming Tools, Python (Programming Language), Open Source Technology, Package Management Systems, Windows PowerShell, Systems Development Life Cycle, Software Engineering, Software Vulnerability Management, Software Repository, Scripting, Enterprise Software Applications, Delivery Pipeline, Large Language Models, Software Security, Model Validation, Cyber Threat Analysis, Enterprise Integration, Devsecops, Security Orchestration, Automation & Response, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** June 30, 2026 - **Apply:** https://www.dice.com/job-detail/bd7cea17-2591-4525-a24a-d25e622bf8a5 ## About the Role * Minimum 3+ years of experience with Code Scanning. * Minimum 3+ years of experience with Software Composition Analysis (Open Source Scanning). * Minimum 3+ years of experience with Static (SAST) and Dynamic (DAST) Application Security Testing. * Strong experience triaging application security findings and managing high-severity vulnerabilities through remediation and closure. * Hands-on experience with scripting, automation, APIs, CI/CD pipelines, developer tools, or security platform integrations. * Practical experience working with AI-enabled security tools, large language models (LLMs), coding assistants, AI governance, model evaluation, or AI-assisted security workflows. * Solid understanding of software supply chain security, including open-source dependency management, SBOM, package security, and developer tooling protection. * Experience securing developer environments, including IDEs, plugins, package managers, CI/CD platforms, and code repositories. * Strong analytical, troubleshooting, and problem-solving skills. * Excellent communication skills with the ability to explain technical security findings and remediation recommendations to both technical and non-technical stakeholders., * Application Security * Software Composition Analysis (SCA) * Static Application Security Testing (SAST) * Dynamic Application Security Testing (DAST) * Code Scanning * Open Source Security * Vulnerability Management * Threat Intelligence * Software Supply Chain Security * Secure SDLC * AI Security Tools * Large Language Models (LLMs) * APIs & Automation * CI/CD Security * Developer Tooling Security * Scripting (Python, PowerShell, Bash, or similar) Preferred Qualifications * Experience implementing AI-powered security solutions or security automation. * Knowledge of secure software development lifecycle (SSDLC) practices. * Familiarity with cloud application security and DevSecOps methodologies. * Experience working with enterprise vulnerability management platforms and modern application security tools. ## Description We are seeking an experienced Application Security AI Engineer to join a dynamic Application Security team. This role focuses on securing enterprise applications by managing application security vulnerabilities, supporting software supply chain security initiatives, and implementing AI-powered security solutions to improve vulnerability detection, analysis, and remediation. The ideal candidate will have strong hands-on experience with application security testing, vulnerability management, secure software development practices, and emerging AI-driven security technologies. Key Responsibilities * Perform application security triage across Software Composition Analysis (SCA), Static Application Security Testing (SAST), and Dynamic Application Security Testing (DAST) findings. * Validate and prioritize critical and high-risk vulnerabilities through exploitability analysis, false-positive verification, risk assessment, and remediation guidance. * Investigate and coordinate responses for critical security events, threat intelligence alerts, and emergency patching activities, ensuring timely mitigation and resolution. * Monitor newly disclosed vulnerabilities and emerging security threats, providing actionable recommendations to development and security teams. * Design, evaluate, and implement AI-assisted application security solutions that improve vulnerability detection, code analysis, remediation recommendations, and security workflow automation while maintaining appropriate human oversight. * Support the evaluation, testing, and secure adoption of AI-based security tools by conducting proof-of-concept assessments, validating security controls, reviewing data handling practices, and documenting governance requirements. * Enhance software supply chain security by securing open-source dependencies, managing Software Bill of Materials (SBOM), identifying malicious packages, evaluating dependency health, and enforcing security policies across development pipelines. * Improve the security of developer environments by assessing IDEs, plugins, extensions, package managers, code-assist tools, and CI/CD integrations for potential security risks and misconfigurations. * Develop automation using scripting, APIs, and security platform integrations to streamline application security operations and vulnerability management processes. * Collaborate closely with development, DevSecOps, and security teams to communicate security risks, recommend remediation strategies, and support secure software development practices. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)