Lead Cybersecurity - Application Security Engineer - Dynamic, Runtime & API Security
Core
Strengthen security of applications and APIs through dynamic application security testing (DAST), runtime application self-protection (RASP), and API security engineering, including AI-assisted security capabilities.
Role type
Senior IC application security engineer (DAST, RASP, API security)
Builds
Security controls for web applications and APIs, AI-assisted security workflows, and automation integrated into CI/CD pipelines
Domain
Telecommunications / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
DAST automation and CI/CD integration, RASP and runtime instrumentation, API security engineering (gateways, discovery, abuse prevention), exploitability analysis and validation, secure design and remediation guidance, scripting/programming (Python, Go, JavaScript, Bash), cloud-native architecture understanding, OWASP Top 10 and API Security Top 10 expertise
Preferred skills
AI-assisted security tooling development, offensive security or bug bounty background, analytics/ML concepts for security telemetry, GraphQL-specific risk mitigation, service mesh and edge protection patterns
Technologies
DAST tools, RASP agents (JVM/.NET CLR), API gateways, Kubernetes, Python, Go, JavaScript, Bash, OWASP frameworks
Responsibilities
Own DAST lifecycle and integrate automated testing into CI/CD pipelines, deploy and tune runtime security solutions (RASP) for production environments, implement API security controls and drive discovery of shadow/zombie APIs, evaluate and implement AI-assisted security workflows to improve triage and remediation, partner with developers to validate findings and ensure effective remediation, build automation and lightweight internal tooling to extend security capabilities
Seniority
Senior, hands-on IC