Principal / Staff Application Security Engineer
Core
Own the AppSec program and lead AI/LLM security hardening for a SaaS platform serving critical infrastructure operators.
Role type
Principal / Staff Application Security Engineer
Builds
SaaS products for electric utilities integrating GenAI and agentic services
Domain
Cybersecurity, Generative AI, Cloud Infrastructure
Deliverable
production ML models | product features | infrastructure
Required skills
Application security engineering, LLM/Agentic AI security, AWS cloud security, Infrastructure as Code policy-as-code, SBOM/AIBOM management, Compliance auditing
Preferred skills
MCP (Model Context Protocol) design and hardening, LLM eval-as-gate implementation, Prompt-layer DLP and runtime guardrails, ISO 42001 familiarity, Regulated sector SaaS experience
Technologies
AWS, Kubernetes, OPA/Rego, Checkov, Kyverno, Semgrep, CodeQL, Snyk, Veracode, Promptfoo, Garak, DeepEval, Giskard, Nightfall, Lakera Guard, Cyberhaven, Harmonic Security, NVIDIA NeMo Guardrails, CrowdStrike, SentinelOne, Defender
Responsibilities
Own and mature the AppSec toolchain across CI/CD; Harden production GenAI deployments on AWS; Write and enforce IaC policy-as-code in live pipelines; Support the company's path to ISO 27001 and ISO 42001 certifications
Seniority
Principal / Staff, hands-on IC with strategic leadership