Senior Security Engineer - Secure SDLC
Core
Senior Security Engineer embedding security into the software development lifecycle (SDLC) and AI-assisted development workflows for a health and insurance organization.
Role type
Senior IC security engineer (shift-left & AI security)
Builds
Enterprise application security toolchain, security guardrails, and AI security governance controls
Domain
Health insurance / Application Security / AI Security
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Shift-left security strategy, SAST/DAST/SCA/Container scanning, CI/CD pipeline security, security-as-code, vulnerability triage, AI security risk assessment, developer enablement, threat modeling
Preferred skills
GitLab Ultimate security features, JFrog Xray/Curation, STRIDE/PASTA methodologies, AI security risks (prompt injection, model poisoning, agentic workflows)
Technologies
GitLab Ultimate, Jfrog Xray, Jfrog Curation, SAST, DAST, SCA, Container Scanning, Secret Detection, AI security assessment tools
Responsibilities
Design and implement security guardrails for AI-assisted development; Configure and enforce pipeline security gates; Lead risk-based triage of vulnerabilities; Architect and maintain the enterprise application security toolchain; Serve as embedded security advisor to engineering teams; Define and report on AppSec and AI security KPIs
Seniority
Senior, hands-on IC
