Senior Application Security Engineer
Core
Prevent and mitigate application vulnerabilities by integrating AI/ML-driven security solutions into DevSecOps pipelines and collaborating with development teams.
Role type
Senior Application Security Engineer (DevSecOps & AI integration)
Builds
AI-powered security capabilities, automated security testing tooling, and secure development processes
Domain
Application Security, DevSecOps, AI/ML in Security
Deliverable
production ML models | infrastructure | product features
Required skills
Multi-language development (Ruby, Go, Rust, JavaScript), AI/ML model integration into pipelines, Static and Dynamic Application Security Testing (SAST/DAST), Threat modeling, Penetration testing, Security code reviews, CI/CD pipeline automation, Bug Bounty program management, Container orchestration (Kubernetes), Infrastructure as Code (Terraform), Cloud security (GCP, Cloud Armor), Log management (Graylog), Web application analysis (Burp Suite)
Preferred skills
Experience with Software Composition Analysis (SCA), Incident response coordination, Security roadmap planning, Delivering secure development training
Technologies
Ruby, Go, Rust, JavaScript, Cloud Armor WAF, SAST tools, DAST tools, SCA tools, Git, Containers, Kubernetes, Terraform, Graylog, GCP, Burp Suite
Responsibilities
Manage end-to-end engineering of AI/ML security solutions in DevSecOps; Architect and maintain infrastructure for AI-powered security capabilities; Evaluate and pilot AI for vulnerability detection and risk assessment; Provide security guidance via threat modeling; Conduct security code reviews and product assessments; Triage and fix bug bounty and pentest findings; Respond to high-severity application vulnerabilities; Implement product security features and automate security testing in CI/CD; Coordinate incident response plans; Perform penetration tests on code changes
Seniority
Senior, hands-on IC