Location: Charlotte, NC
Salary: $89.00 USD Hourly - $95.00 USD Hourly
Description: Senior Lead Application Security Engineer (AppSec SME) - AI & DCMS SecurityWe are not accepting C2C or 1099 arrangements.Location: Charlotte, NC (Hybrid)
Employment Type: Contract
Vendor Opportunities: TEKsystems, Judge Group, Experis, Dexian, Motion Recruitment, Innova Solutions
About the RoleWe are seeking a
Senior Lead Application Security Engineer (AppSec SME) to lead the Application Security strategy supporting the
Data Center Modernization and Simplification (DCMS) program. This role combines deep technical expertise with strategic leadership to strengthen enterprise application security, drive modernization initiatives, and implement innovative AI-powered security solutions.
The ideal candidate will have extensive experience in Application Security, Secure Software Development Lifecycle (SSDLC) practices, DevSecOps, and emerging AI/GenAI security technologies. This individual will partner with engineering, architecture, development, and security teams to reduce risk, improve security posture, and enable secure software delivery at enterprise scale.
Key ResponsibilitiesApplication Security Strategy & Governance- Define and execute the Application Security strategy for DCMS applications using risk-based and tiered control frameworks.
- Assess existing Application Security controls and establish baseline security requirements across application portfolios.
- Identify security gaps and develop remediation roadmaps in partnership with application owners and technical stakeholders.
- Collaborate with Application Security Champions, development teams, and engineering leaders to drive adoption of security controls.
- Ensure compliance with enterprise Secure Software Development Lifecycle (SSDLC) standards and vulnerability remediation requirements.
- Establish metrics, reporting, and governance processes to measure security effectiveness and program maturity.
AI & Generative AI Security Innovation- Identify, design, and implement AI-driven security solutions that improve coverage, efficiency, and risk reduction.
- Develop automated threat modeling capabilities leveraging source code, infrastructure-as-code (IaC), architecture data, and application metadata.
- Lead security assessments and adversarial testing of GenAI and Large Language Model (LLM) applications.
- Design defenses against prompt injection, model abuse, unauthorized tool usage, data leakage, and secrets exposure.
- Evaluate and implement AI model scanning, integrity validation, and secure model onboarding processes.
- Research emerging AI security threats and apply best practices to enterprise environments.
Application Security Modernization & Automation- Drive modernization initiatives through security automation, tool integration, and process optimization.
- Build proof-of-concepts (POCs) and pilot programs to evaluate emerging security technologies.
- Scale successful security solutions across enterprise environments.
- Improve developer experience by simplifying security processes while maintaining strong risk management controls.
- Advance DevSecOps capabilities through seamless integration with CI/CD pipelines and developer workflows.
Leadership & Strategic Influence- Serve as a trusted security advisor to senior technology and business leaders.
- Provide recommendations on Application Security priorities, investments, and risk management strategies.
- Lead cross-functional initiatives and influence stakeholders without direct reporting authority.
- Mentor engineering teams on secure design principles and security best practices.
- Translate emerging technologies, threat intelligence, and industry trends into actionable security strategies.
Required Qualifications- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or related field, or equivalent practical experience.
- 7+ years of experience in Application Security, Cybersecurity Engineering, or Information Security Engineering within large-scale enterprise environments.
- Strong expertise in Secure Software Development Lifecycle (SSDLC) methodologies and controls.
- Hands-on experience with:
- Threat Modeling
- Secure Architecture and Secure Design Reviews
- Static Application Security Testing (SAST)
- Software Composition Analysis (SCA)
- Dynamic Application Security Testing (DAST)
- Penetration Testing
- Vulnerability Management
- Proven experience developing and implementing enterprise security strategies.
- Strong stakeholder management and leadership skills with the ability to drive outcomes through influence.
- Experience working in Agile and DevSecOps environments.
Preferred Qualifications- Experience securing Generative AI (GenAI) and Large Language Model (LLM) applications.
- Expertise in adversarial AI testing, prompt injection mitigation, and AI security frameworks.
- Experience building AI-enabled security automation and intelligent security workflows.
- Strong understanding of CI/CD pipeline security and cloud-native application security.
- Experience within highly regulated industries, including financial services, banking, insurance, or healthcare.
- Knowledge of cloud security architectures across AWS, Azure, and Google Cloud Platform (Google Cloud Platform).
- Relevant industry certifications, including:
- CISSP
- CSSLP
- CISM
- GIAC Certifications
- Equivalent cybersecurity certifications
Technical SkillsApplication Security- SSDLC
- Threat Modeling
- Secure Design Reviews
- SAST
- SCA
- DAST
- Penetration Testing
- Vulnerability Management
DevSecOps & Automation- CI/CD Security
- Security Automation
- Infrastructure as Code (IaC)
- Secure Pipelines
- Developer Security Tooling
AI Security- Generative AI Security
- LLM Security
- Prompt Injection Defense
- Adversarial Testing
- AI Model Validation
- Model Risk Management
- AI Governance
Leadership- Security Strategy Development
- Stakeholder Management
- Cross-Functional Leadership
- Program Management
- Risk Assessment & Governance
Why Join This Opportunity?This role offers the opportunity to shape the future of Application Security within a large-scale modernization program while leading cutting-edge initiatives in AI and GenAI security. You'll drive enterprise-wide security strategy, influence senior leadership, and help build next-generation security capabilities that protect critical business systems.
Work Location: Charlotte, NC (Hybrid)
Position: Senior Lead Application Security Engineer (AppSec SME)
Industry: Financial Services / Enterprise Technology
Keywords: Application Security Engineer, AppSec SME, SSDLC, DevSecOps, Threat Modeling, SAST, DAST, SCA, Penetration Testing, GenAI Security, LLM Security, AI Security, Cybersecurity Engineer, Security Architect, Application Security Lead, Charlotte NC Jobs, Hybrid Security Jobs.
By providing your phone number, you consent to: (1) receive automated text messages and calls from the Judge Group, Inc. and its affiliates (collectively "Judge") to such phone number regarding job opportunities, your job application, and for other related purposes. Message & data rates apply and message frequency may vary. Consistent with Judge's Privacy Policy, information obtained from your consent will not be shared with third parties for marketing/promotional purposes. Reply STOP to opt out of receiving telephone calls and text messages from Judge and HELP for help.
Contact: This job and many more are available through The Judge Group. Please apply with us today!