Senior Lead Application Security Engineer
Core
Embed application security into the Cloud Platform and CI/CD pipelines, building autonomous AI agents to proactively detect, triage, and remediate security risks at machine speed.
Role type
Senior Lead Application Security Engineer (Agentic Defense)
Builds
AI-driven security agents, secure CI/CD pipelines, and hardened cloud-native infrastructure for R&D teams.
Domain
Cloud Security & Application Security (DevSecOps) with a focus on Agentic/AI Security
Deliverable
production ML models | infrastructure
Required skills
Application security fundamentals, Agentic and AI security (prompt injection, tool/MCP security), DevSecOps pipeline security, Cloud-native security (AKS), Identity and access management, Infrastructure-as-code, Scripting and automation
Preferred skills
OWASP Top 10 for LLMs, MITRE ATLAS frameworks, LLM red-teaming, Runtime guardrails
Technologies
Azure DevOps, Mend, Azure Defender for Cloud, Keycloak, Azure Active Directory, Bicep, Terraform, Python, PowerShell, C#, Semgrep, Snyk, GitHub Copilot, garak, Microsoft PyRIT, Lakera Guard, NVIDIA NeMo Guardrails
Responsibilities
Embed application security into CI/CD pipelines; Design and operate AI-driven security agents; Establish SSDLC practices and integrate automated enforcement; Lead security of agentic systems against prompt injection and supply-chain risks; Drive proactive vulnerability management; Partner with engineering to harden AKS workloads and IAM; Contribute to compliance programs (SOC 2, ISO 27001); Define security runbooks and incident response procedures; Act as a security skill set within the platform team via code review and pairing.
Seniority
Senior, hands-on IC with leadership responsibilities