Lead Application Security Engineer, IT Security
Core
Lead application security engineering activities across web, API, mobile, and cloud-native services to integrate security into the SDLC and automate vulnerability management.
Role type
Senior IC application security engineer (AI-assisted security)
Builds
Automated security controls in CI/CD pipelines, reusable security patterns, and AI-governed vulnerability workflows
Domain
Financial services / Application Security Engineering
Deliverable
production ML models | product features
Required skills
Application security engineering, SDLC security integration, SAST/DAST/IAST/SCA, AI-assisted vulnerability analysis, Python, Cloud security (Azure/AWS/GCP), Threat modeling, Secure architecture
Preferred skills
Penetration testing, Infrastructure-as-code scanning, Container security, Software supply-chain security, AI governance
Technologies
Python, PowerShell, JavaScript, TypeScript, Go, Java, C#, Shell, GitHub, GitLab, Azure DevOps, Jenkins, Jira, Kubernetes, OWASP tools
Responsibilities
Design automated security testing in CI/CD pipelines; Perform manual and tool-assisted application/API security assessments; Lead application threat modeling and architecture risk reviews; Develop secure coding standards and developer enablement materials; Mentor application security engineers and developers; Serve as technical escalation point for complex vulnerabilities
Seniority
Senior, hands-on IC
