Senior Application Security Engineer
Core
Embed security into the SDLC for applications, APIs, and CI/CD pipelines, while securing AI/LLM capabilities and supply chains.
Role type
Senior Application Security Engineer (DevSecOps)
Builds
Secure CI/CD pipelines, WAF policies, API security controls, and AI/LLM application safeguards.
Domain
Cybersecurity, Application Security, DevSecOps, AI/LLM Security
Deliverable
production ML models | product features | infrastructure
Required skills
Application security, CI/CD pipeline security, WAF tuning, API security, SAST/DAST/SCA/container scanning, secrets management, artifact signing, cloud security, secure coding, threat modeling, programming (Python/Java/Go/JS)
Preferred skills
SBOM generation, GitOps, IaC scanning, policy-as-code, runtime protection, supply chain incident response, security certifications (OSWE/CSSLP/GPCS)
Technologies
GitHub Actions, Jenkins, GitLab, Azure DevOps, Sigstore, Cosign, Terraform, CloudFormation, AWS, Azure, GCP
Responsibilities
Integrate security practices throughout the SDLC; Design, implement, and maintain security controls within CI/CD platforms; Automate SAST, DAST, SCA, and container image scanning; Design, deploy, and tune WAF rules and API security protections; Conduct API risk assessments and promote secure API design patterns; Perform secure code reviews and support automated security testing coverage; Triage, prioritize, and track vulnerabilities across source code, CI/CD pipelines, and deployed services; Facilitate threat modeling for applications, APIs, and delivery pipelines; Mentor engineering teams on secure coding and secure pipeline practices; Act as a trusted advisor to product, platform engineering, and DevOps teams; Partner with SOC/IR teams during software supply chain or pipeline-related security incidents; Assess and guide the secure adoption of AI capabilities within enterprise applications.
Seniority
Senior, hands-on IC