$128,490.00 - $205,580.00
The Application & AI Security Engineer is a highly technical role responsible for advancing and embedding application and AI security across the software development lifecycle. This role drives automation of application security tooling, strengthens secure coding and design practices, secures AI- and LLM-powered applications, and promotes adherence to secure development principles. The engineer partners with developers, architects, cybersecurity teams, data engineers, stakeholders, and scrum masters to deliver secure, resilient applications. With a security-first mindset, the role continuously assesses application and AI threats, reduces enterprise risk, and supports secure development and deployment practices across multidisciplinary teams.
***MissionSquare cannot sponsor or hire candidates with H1B, STEM or OPT visas for this role.***Essential Functions for this role include:- Build relationships with developers, stakeholders, and scrum master to incorporate security principles into engineering design and application deployments.
- Perform security testing and validation of application security controls across projects, ensuring secure design and implementation.
- Oversee the implementation of defensive security practices and countermeasures across applications, including AI-enabled applications.
- Apply SAST, SCA, and DAST tools and methodologies to identify and reduce application security risk.
- Identify vulnerabilities in code through automated and manual assessments and promote efficient remediation.
- Apply threat modeling principles to improve design and development practices, including threat modeling for AI/LLM applications.
- Assess and secure AI/ML and generative AI applications, including model and LLM integration security, prompt injection, and data-leakage risks, and govern the safe use of AI coding assistants in the development lifecycle.
- Serve as a point of contact for security-based escalations and remain closely involved in resolution activities.
- Build services and tools that enable developers and engineers to easily adopt and use security components produced by the application security team.
- Support shift-left initiatives by incorporating security early and throughout the development lifecycle.
- Performs other duties as assigned
If you have the following skills, we encourage you to apply:- Bachelor's degree (BA/BS), or equivalent professional experience
- At least 7+ years of experience in information technology, information security administration, security operations, or a related technical security discipline
- Experience with agile workflows, including Scrum and Kanban
- Hands-on experience with application security testing, including Burp Suite
- Demonstrated experience with SAST, SCA, and DAST tools and methodologies
- Experience securing AI/LLM-powered applications and familiarity with the OWASP Top 10 for LLM Applications and MITRE ATLAS
- Experience using Claude and GPT models
- Familiarity with securing and governing AI-assisted coding tools in the software development lifecycle
- Ability to write code using Java, Python, Bash, Perl, or PowerShell
- Understanding of OWASP, CVSS, the MITRE ATT&CK framework, and the software development lifecycle (SDLC)
- Foundational knowledge of infrastructure and operating systems
- Preferred certifications: CISSP and/or GIAC Web Application Penetration Tester (GWAPT)
To benefit your career and support your wellbeing, we offer:- Competitive Total Rewards package, including base pay, incentive programs, benefits, and a 401(k) plan with matching contributions
- Flexible and hybrid work schedules to support work-life balance
- Tuition reimbursement to support continued education
- Professional and career development opportunities, including courses and certifications
- Comprehensive wellness programs promoting physical, mental, and emotional health
- Volunteerism initiatives to encourage community engagement
Click here to learn more about MissionSquare's benefits.