Prosum Inc

Manager - Application & AI Security

Prosum Inc$120K — $145K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, IT, or equivalent experience.
  • 5+ years of experience in application security, DevSecOps, or related fields.
  • Hands-on experience in building security controls in CI/CD pipelines.
  • Experience with CI/CD platforms like Azure DevOps, GitHub Actions, or Jenkins.
  • Strong experience in application security testing methods (SAST, DAST, SCA).
  • Deep understanding of API security architectures and standards.
  • Practical experience with AI security including governance and vulnerability testing.

Responsibilities

  • Lead secure software development lifecycle and implement NIST SSDF and ISO/IEC 27001 practices.
  • Establish application security requirements and conduct security evaluations for software releases.
  • Integrate security guardrails within CI/CD workflows, creating secure "golden pipelines."
  • Oversee application security testing, including SAST, DAST, and API security assessments.
  • Manage the security of AI and model inventories, ensuring compliance and governance.
  • Conduct risk assessments for emerging AI technologies and oversee prompt-injection testing.
  • Collaborate with teams to translate AI risks into actionable security practices.

Benefits

  • Hybrid work environment with the flexibility of remote and in-office.
  • Opportunities for professional growth and development.
  • Access to cutting-edge security tools and technology.
  • Collaborative work culture with a focus on innovation.
  • Participation in shaping security policies and frameworks.
Full Job Description
Job Description

Manager, Application & AI Security
Location: Scottsdale, AZ (hybrid)
About the Role
We are seeking a Manager, Application & AI Security to lead the security of internally developed applications, cloud application environments, CI/CD pipelines, and enterprise AI usage.

This role will establish and operate secure-by-default practices across the software development lifecycle while serving as a central technical leader for AI security and governance. The ideal candidate brings strong hands-on experience in application security and DevSecOps, along with a practical understanding of emerging AI security risks.

You will build security guardrails into development and deployment processes, oversee application security testing, manage AI and model inventories, assess prompt-injection and jailbreak risks, and establish controls for MCPs and AI-agent runtimes.

This is a highly technical leadership role focused on building scalable security capabilities rather than simply reviewing or documenting controls.
What You'll DoApplication Security & DevSecOps
  • Lead the secure software development lifecycle, incorporating NIST SSDF and ISO/IEC 27001 practices.
  • Establish application security requirements and conduct security reviews for major releases and critical applications.
  • Build and maintain secure CI/CD "golden pipelines," embedding security guardrails directly into development and deployment workflows.
  • Implement pipeline and artifact integrity controls and monitor production pipelines for security risks.
  • Lead application security testing across SAST, DAST, software composition analysis (SCA), secrets detection, API security, and related capabilities.
  • Establish API security practices aligned with OWASP standards, including the OWASP Top 10 and API Security Top 10.
  • Oversee container, Kubernetes, and Infrastructure-as-Code security scanning.
  • Lead application threat modeling and secure-code development practices.
  • Establish and maintain SBOM generation for internally developed applications.
  • Develop and deliver secure development training for engineering teams.
  • Establish application- and PaaS-level cloud security guardrails in partnership with cloud and infrastructure teams.
  • Provide application and cloud security expertise during broader technology and security reviews.
  • Help establish security guardrails for customer-facing platforms, workflows, and contact-center technologies.
AI Security & Governance
  • Serve as the technical owner for enterprise AI security controls and AI usage governance.
  • Establish controls for LLM and AI assistant usage, including public and internally hosted models.
  • Identify and manage risks associated with shadow AI, unauthorized AI tools, and potential data leakage.
  • Maintain an enterprise AI/model inventory, AI bill of materials (AI-BOM), model registry, and approval workflows.
  • Assess AI applications and models for security risks before production use.
  • Conduct prompt-injection and jailbreak testing and lead LLM security red-teaming.
  • Apply relevant AI security practices, including the OWASP Top 10 for LLM Applications and MITRE ATLAS.
  • Establish security controls for MCPs (Model Context Protocol) and AI-agent runtimes, including per-tool authorization, runtime guardrails, and containment.
  • Partner with governance, risk, compliance, data security, identity, infrastructure, and other teams to ensure AI security controls are implemented effectively.
  • Translate emerging AI security risks into practical technical controls and repeatable processes.
Key Initiatives
  • Enterprise AI Governance & Shadow AI: Establish AI usage policies, discovery, risk assessment, and security controls.
  • Secure CI/CD Golden Pipelines: Build DevSecOps guardrails-as-code and automated blocking of critical security findings.
  • Cloud Application Security: Strengthen security controls across cloud tenants, SaaS, and PaaS environments.
  • AI Agent & MCP Security: Develop runtime security capabilities for AI agents and tool integrations, including authorization and containment.
What Success Looks Like
In this role, success will include:
  • AI tools are risk-assessed and governed before approved enterprise use.
  • Shadow AI is identified, assessed, and addressed within established service levels.
  • Production CI/CD pipelines are covered by security guardrails and monitoring.
  • Major application releases receive appropriate security reviews.
  • Critical application security findings are prevented from reaching production.
  • SAST, DAST, SCA, API security, and secrets scanning are automated across applicable development pipelines.
  • AI/model inventories and approval workflows are accurate, current, and operational.
  • Prompt-injection, jailbreak, and AI-agent security risks are regularly assessed.
  • Application and AI security practices are embedded into engineering workflows rather than operating as a separate manual review process.
What We're Looking For
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent professional experience.
  • 5+ years of experience in application security, DevSecOps, software security, or a closely related discipline.
  • Experience leading or mentoring security engineers or technical security teams.
  • Hands-on experience building security controls into CI/CD pipelines and development workflows.
  • Experience with CI/CD platforms such as Azure DevOps, GitHub Actions, GitLab, Jenkins, or similar technologies.
  • Strong experience with application security testing, including SAST, DAST, SCA/open-source security, secrets scanning, and API security.
  • Strong understanding of API security architecture and standards, including OAuth 2.0, OWASP, and related security practices.
  • Experience securing containers, Kubernetes environments, and Infrastructure-as-Code.
  • Experience with threat modeling and software supply-chain security, including SBOMs.
  • Practical experience with AI/LLM security, including AI usage governance, prompt-injection and jailbreak testing, red-teaming, or AI-agent security.
  • Understanding of AI security and governance frameworks such as NIST AI RMF and ISO/IEC 42001.
  • Familiarity with NIST and ISO/IEC 27001 security frameworks and practices.
  • Experience translating complex technical security issues into clear recommendations for technical and non-technical audiences.
  • Strong communication, collaboration, prioritization, and problem-solving skills.
Helpful Experience
  • Familiarity with AI productivity and development tools such as Claude, GitHub Copilot, or similar platforms.
  • Experience securing MCPs or AI-agent architectures.
  • Experience with AI/model registries, AI inventories, or AI-BOM initiatives.
  • Experience with security platforms and tools such as Checkmarx, Veracode, Snyk, or comparable solutions.
  • CISSP or another relevant security certification is preferred. Additional certifications such as CSSLP, CCSP, or CISM are a plus.


About Prosum Inc

Prosum Inc. is an information technology services company that provides a wide range of services to clients in the healthcare, financial services, and technology sectors. The company was founded in 2002 and is headquartered in Irvine, California. Prosum has a team of over 200 professionals who specialize in software development, cloud computing, and cybersecurity. The company has completed projects for clients such as Kaiser Permanente, Wells Fargo, and Microsoft. Prosum is committed to providing innovative solutions that help clients achieve their business goals.
Learn more about Prosum Inc
Size
200 employees
Industry
Net Income
$2 million
Founded
2002
5 Year Trend
+20%
Revenue
$50 million

Similar Jobs

More Jobs at Prosum Inc

More Information Technology Jobs

Find similar Manager - Application & AI Security jobs: