Senior Application Security Engineer II
Core
Maturing application security programs (SAST, SCA, DAST) and building a Secure AI Development Lifecycle (ADLC) for an AI-native mental health platform.
Role type
Senior Application Security Engineer (AI/ML focus)
Builds
Secure AI features, threat modeling programs, and security automation tooling for a global mental health platform.
Domain
AI/ML security, Cloud Infrastructure, Digital Health
Deliverable
production ML models | infrastructure
Required skills
Application security engineering, SAST/SCA/DAST tooling, CI/CD pipeline security, Cloud infrastructure (AWS/Azure/GCP), Container technologies, Security automation (Go/Python/JS/Ruby), AI/ML security concepts (prompt injection, adversarial inputs), LLM tooling assessment, Compliance frameworks (NIST/HIPAA/HITRUST/SOC-2)
Preferred skills
Security architecture design, Formal threat modeling program leadership, AI security tooling evaluation, Bug bounty program management, HIPAA-regulated environment experience
Technologies
Go, Python, JavaScript, Ruby, AWS, Azure, GCP, OpenAI, Anthropic, LangChain, OWASP Top 10 for LLM Applications
Responsibilities
Participate in architecture reviews and design consultations for secure-by-design practices; Mentor engineers on secure coding and AppSec fundamentals; Develop AI-assisted threat modeling programs; Tune and improve SAST, SCA, and DAST capabilities; Perform security-focused code reviews; Support vulnerability remediation and validation; Implement security automation and AI tooling integrations; Assess security risks of AI-integrated product features (LLM APIs, vector databases, RAG pipelines); Design and develop the Secure AI Development Lifecycle (ADLC)
Seniority
Senior, hands-on IC