We are seeking an Application Security Engineer — Threat & Vulnerability Management (AI Focus) to drive secure-by-design engineering for agent code and pipelines, and to own vulnerability management for AI workloads. Production experience with security for AI Agents and Agentic AI Architecture is an absolute must. This role keeps agentic AI development moving fast while ensuring every agent is built, tested, and shipped securely.
Responsibilities
- Embed SAST, DAST, and SCA into agent CI/CD pipelines
- Build and maintain an AI/LLM software bill of materials (SBOM) capability
- Lead threat modeling for agents against the OWASP LLM Top-10 and Agentic Top-10
- Define and enforce vulnerability-management SLAs for AI workloads
- Establish secure-SDLC guardrails for maker and developer teams
Requirements
- 3+ years of experience in application security, including SAST, DAST, and SCA tooling and triage
- Expertise in threat modeling with working knowledge of LLM/agent attack surfaces (prompt injection, tool abuse, data exfiltration)
- Familiarity with AI/LLM supply-chain risk and SBOM practices
- Background in secure SDLC and DevSecOps pipeline integration
- Proficiency in AI Security, LLM security, and GRC platforms
- Skills in Python for security tooling and automation
- Understanding of SOC-2 auditing procedures
- Excellent command of written and spoken English (B2+ level)
Nice to have
- Relevant certifications such as GWAPT, CSSLP, or OSCP
- Knowledge of AI Governance frameworks
- Experience collaborating with or supporting CISO functions
- Familiarity with SOX (Sarbanes-Oxley Act) compliance requirements