Lead Application Security Engineer
Core
Senior technical leader and primary architect for enterprise application security, focusing on building, securing, and governing AI-powered capabilities within software.
Role type
Senior IC application security engineer (AI security focus)
Builds
Enterprise application security architecture, secure-by-default patterns, AI security tooling, and DevSecOps pipelines
Domain
Retail / Application Security / AI Security
Deliverable
production ML models | product features | infrastructure
Required skills
Application security architecture, secure code review, API security (REST/GraphQL), SAST/DAST tooling, threat modeling, DevSecOps pipeline design, AI/ML security governance, vulnerability triage, security standards definition
Preferred skills
Red teaming/pentesting, security observability pipelines, cloud-native security (AWS/Azure/GCP), regulatory compliance (PCI-DSS/NIST/OWASP), AI/ML tool integration
Technologies
Python, Java, JavaScript, Go, Snyk, SonarQube, Semgrep, Checkmarx, Burp Suite, OWASP ZAP, CI/CD pipelines
Responsibilities
Define enterprise AppSec architecture and standards; conduct advanced secure code reviews and penetration testing; own DevSecOps toolchain and security gates; build and govern AI-powered security tooling; lead threat modeling and compliance audits
Seniority
Senior, hands-on IC with architectural leadership