Principal Application & AI Security Engineer

Det Norske Veritas$175K — $225K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in application security or secure software engineering with responsibility for production software and security controls.
  • Deep expertise in application and API security, focusing on authentication, authorization, session management, and data protection.
  • Proficient in reviewing, writing, testing, and enhancing production-quality code in common cloud application languages.
  • Experience in leading source-code reviews, application security testing, and threat modeling for complex systems.
  • Capability to integrate security tooling in CI/CD processes, creating risk-based automated controls.
  • Hands-on experience with a major cloud provider (e.g., Azure, AWS) and understanding shared-responsibility models.
  • Strong communication skills for conveying security risks to technical and non-technical stakeholders.

Responsibilities

  • Design and implement secure patterns across applications, APIs, and cloud platforms.
  • Automate security checks within engineering workflows to catch issues early in delivery.
  • Identify and address root causes of recurring vulnerabilities in systems and platforms.
  • Review and test application designs for weaknesses, ensuring robust authentication and authorization.
  • Conduct targeted security testing for applications, APIs, and AI systems.
  • Collaborate with engineering teams to remediate weaknesses and validate fixes.
  • Establish practices for vulnerability triage, ensuring thorough analysis and accountability.

Benefits

  • Generous paid time off including vacation and sick days.
  • Multiple health and dental plans, along with vision care benefits.
  • Company contributions to flexible spending accounts and health savings accounts.
  • Employer-paid virtual therapy sessions through Talkspace.
  • 401(k) plan with company match.
  • Company-provided life insurance and disability benefits.
  • Education reimbursement program for professional development.
  • Flexible work schedule with hybrid working options.
  • Opportunities for charitable giving matched by the company and paid volunteer time off.
  • Clear pathways for career advancement and growth.
Full Job Description
Job Description

DNV Energy Systems' Platform Services is seeking Principal Application & AI Security Engineer.

DNV Energy Systems' Platform Services runs the software products and digital platforms our customers depend on, including systems with significant operational importance in enterprise and energy environments. As we evolve toward agentic AI architectures, security must move from after-the-fact review into architecture, development workflows, and runtime operations - engineered into the platform and the delivery pipeline, with evidence that controls are implemented and operating effectively.

This is a builder's role for a senior technical leader who can read and improve code, design reusable controls, model complex threats, conduct authorized security testing, and work directly with engineering teams to ship durable fixes. The goal is not simply to identify vulnerabilities. It is to eliminate recurring vulnerability classes, reduce exposure, and make the secure path the easiest path.

This role is based at our DNV office in Houston, TX or Oakland, CA, presenting a dynamic hybrid schedule where employees will typically spend three (3) days per week working from either a DNV office or client location/site. Further details regarding role-specific requirements will be shared during the interview process.

What you'll do
You'll be a technical leader within our organization focused on three core priorities:
  • Securing application and AI architecture. Design and implement secure patterns across applications, APIs, cloud platforms, and AI-agent systems, with particular emphasis on identity, authorization, tenant isolation, data access, tool use, and runtime guardrails.
  • Automating security in engineering workflows. Build and tune risk-based controls so material issues are caught and acted on inside delivery workflows, rather than at manual checkpoints.
  • Eliminating recurring vulnerabilities. Find root causes, fix weaknesses at the architecture or platform-pattern level, and make the same class of issue structurally difficult to reintroduce


The responsibilities below describe how this work shows up day-to-day across architecture, delivery, AI systems, remediation, and engineering.

Build security into delivery and platform engineering
  • Design and implement scalable controls for software and AI supply chains, including dependency integrity, SCA, SAST, DAST, build provenance, artifact security, secrets protection, container and infrastructure-as-code assurance, and software or AI bills of materials where appropriate.
  • Implement platform-level controls: policy as code, authorization enforcement, data-access guardrails, secure defaults, and reusable reference implementations.
  • Design AI-assisted security-testing environments, automated attack scenarios, and security-regression suites that prevent resolved issues from silently returning.
  • Implement risk-based quality gates with documented exception paths, accountable ownership, and service-level expectations, so material issues block release.


Find, prove, and fix material weaknesses
  • Review source code, APIs, and application designs for weaknesses in authentication, authorization, session management, input handling, data-access scope, and multi-tenant isolation, including row- and field-level boundaries.
  • Conduct authorized application, API, and AI security testing, including targeted manual testing of business logic and trust boundaries that automated tools cannot adequately validate.
  • Work alongside engineers to remediate root causes, validate fixes, create regression tests, and put preventive controls or secure patterns in place.
  • Establish vulnerability triage and remediation practices, including exploitability and exposure analysis, accountable ownership, target dates, exception handling, retesting, closure evidence, and escalation of overdue material risk.

Secure AI agents and AI-assisted development
  • Establish agent identities and least-privilege permissions, with clear separation of read, write, execute, approval, and administrative capabilities.
  • Govern model, tool, skill, connector, plug-in, memory, and data access, including tenant isolation and boundaries between trusted and untrusted context.
  • Validate untrusted inputs and tool outputs, and design defenses against direct and indirect prompt injection, goal manipulation, tool misuse, privilege escalation, sensitive-data exposure, memory poisoning, unsafe delegation, and cascading failures.
  • Assess multi-agent workflows to implement approval requirements for consequential or irreversible actions, runtime policy enforcement, rate and resource limits, and tamper-resistant auditability.

Shape secure architecture at scale
  • Lead high-risk threat modeling and architecture reviews for complex, multi-tenant, cloud-native, event-driven, and AI-enabled systems.
  • Develop and demonstrate reusable secure patterns for microservices, APIs, event-driven systems, containers, Kubernetes, cloud services, and agentic AI applications.
  • Contribute to platform roadmaps and engineering practice so controls are implemented at the most effective layer and reused across products.
  • Provide evidence from implementation, testing, and incidents to help Information Security team continuously improve enterprise standards and assurance expectations.

Support engineering teams and incidents
  • Partner across distributed engineering hubs, including North America and Chennai, to drive adoption of secure patterns and automation at scale.
  • Translate findings into prioritized, actionable engineering work reflecting technical severity, exploitability, customer impact, and delivery context.
  • Mentor senior engineers and technical leaders in secure design, development, threat modeling, and remediation.
  • Serve as the application and AI security technical lead during relevant incidents - coordinating with designated incident lead and Information Security team to support investigation, containment, eradication, recovery, remediation validation, and lessons learned.
  • Represent application and AI security in significant technical, executive, customer, audit, and assurance discussions when needed.


Responsibilities

  • Generous paid time off (vacation, sick days, company holidays, personal days)
  • Multiple Medical and Dental benefit plans to choose from, Vision benefits
  • Spending accounts - FSA, Dependent Care, Commuter Benefits, company-seeded HSA
  • Employer-paid, therapist-led, virtual care services through Talkspace
  • 401(k) with company match
  • Company provided life insurance, short-term, and long-term disability benefits
  • Education reimbursement program
  • Flexible work schedule with hybrid opportunities
  • Charitable Matched Giving and Volunteer Rewards through our Impact Program
  • Volunteer time off (VTO) paid by the company
  • Career advancement opportunities

**Benefits vary based on position, tenure, location, and employee election**

DNV provides a reasonable range of compensation for this role. The actual compensation is influenced by a wide array of factors, including but not limited to skill set, level of experience, and specific location. For the states of California, Connecticut, Illinois, Maine, Massachusetts, New Jersey, New York, Virginia and Washington only, the starting pay range for this role is $175,000 - $225,000.

Qualifications

What Is Required
  • 8+ years of experience in application security or secure software engineering, with demonstrated responsibility for production software and security controls.
  • A degree in computer science, cybersecurity, engineering, or a related field is welcome but not required. Equivalent practical experience is fully recognized.
  • Deep application and API security expertise, including authentication, authorization, session management, data protection, input validation, and multi-tenant isolation. This is the core of the role.
  • Ability to review, write, test, and improve production-quality code in one or more languages commonly used in cloud applications, automation, and security engineering.
  • Experience leading source-code reviews, application and API security testing, threat modeling, and architecture reviews for complex systems.
  • Experience integrating and tuning security tooling in CI/CD and converting findings into risk-based automated controls.
  • Production experience with a major cloud provider (Azure, AWS, or comparable) and practical understanding of cloud identity, platform services, and the shared-responsibility model.
  • Demonstrated ability to set technical direction, create reusable capabilities across multiple products, and influence senior stakeholders without relying on formal authority.
  • Ability to explain material security risk clearly to engineers, product leaders, executives, customers, and assurance stakeholders.
  • Strong written and verbal English communication skills.
  • We conduct pre-employment drug and background screening.

What Is Preferred
  • Practical AI-agent security experience, including excessive permissions, insecure tool invocation, untrusted inputs, memory or context risks, sensitive-data exposure, insufficient human oversight, and unsafe autonomous action.
  • Experience applying AI to security testing, code analysis, vulnerability triage, or security automation.
  • Experience securing distributed, event-driven, multi-tenant, or critical enterprise systems where authorization and data boundaries are material risks.
  • Container, Kubernetes, infrastructure-as-code, and software-supply-chain security.
  • Incident response, vulnerability investigation, exploit validation, and remediation verification.
  • Hands-on depth with Veracode, Burp Suite Professional, or equivalents, and practical familiarity with OWASP application, API, and agentic AI security guidance.
  • Certifications are a plus, demonstrated hands-on ability matters more. Relevant credentials include OSCP, GIAC GWAPT, GWEB, GCSA, AZ-500, AWS Certified Security - Specialty, CISSP, or CCSP.

*Immigration-related employment benefits, for example visa sponsorship, are not available for this position*

About Det Norske Veritas

Det Norske Veritas Careers

Joining Det Norske Veritas presents an unparalleled opportunity to become part of a global team of professionals dedicated to fostering innovation, leadership, and growth in the industry. Det Norske Veritas, a leader in risk management and quality assurance, offers a range of job opportunities that empower professionals to advance their careers in meaningful directions.

Explore Career Opportunities

Det Norske Veritas is actively hiring and offers a variety of positions that cater to different skills and career aspirations. From entry-level roles to senior leadership positions, the company is committed to diversity and professional growth. Explore open positions that match your skills and interests on the Det Norske Veritas Jobs portal.

Innovative Work Environment

Professionals at Det Norske Veritas lead the industry in developing solutions that enhance safety, performance, and environmental sustainability. With a culture that thrives on innovation and digital transformation, team members are encouraged to engage in projects that push the boundaries of technology and service.

Professional Growth and Development

Det Norske Veritas is dedicated to the professional development of its team members. The company supports career advancement through comprehensive training programs, leadership development courses, and opportunities for networking and career mobility. Employees are equipped with the resources and mentorship needed to excel and lead in their fields.

Internship Programs

For those starting their careers, Det Norske Veritas offers internship programs that provide hands-on experience and a chance to develop essential industry skills. Internships are a gateway to full-time employment and offer a deep insight into the company’s operations and culture.

Commitment to Diversity and Inclusion

Det Norske Veritas believes that a diverse workforce is key to driving innovation and maintaining a competitive edge. The company is committed to creating an inclusive environment where all employees can thrive. Diversity training and initiatives are integral to the company’s ethos.

Benefits and Employee Well-being

Employees at Det Norske Veritas enjoy a range of benefits designed to support their professional and personal lives. From health and wellness programs to flexible working conditions, the company prioritizes employee well-being and job satisfaction.

Join the Det Norske Veritas Team

Candidates interested in pursuing a career with Det Norske Veritas are encouraged to prepare their resume and apply through the Det Norske Veritas Careers page. The hiring process is designed to be transparent and engaging, ensuring that both the company and potential employees are well-matched.

Stay Connected

Keep up to date with the latest career tips, industry insights, and company news by subscribing to the Det Norske Veritas Careers newsletter. Tailor your subscription to receive updates that align with your career interests and professional goals.

Networking Opportunities

Det Norske Veritas fosters a vibrant professional community where employees can connect, share ideas, and innovate together. Networking events and professional groups within the company offer rich opportunities for collaboration and personal growth. Embark on a rewarding career journey with Det Norske Veritas and be part of a team that values integrity, safety, and reliability in every aspect of their work.
Learn more about Det Norske Veritas

Similar Jobs

More Jobs at Det Norske Veritas

More Information Technology Jobs

Find similar Principal Application & AI Security Engineer jobs: