Principal Consultant, Agentic AI Cybersecurity Engineer

Toronto, ON, US • Posted 2 hours ago • Updated 1 hour ago
Contract W2
On-site
DOE
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Cyber Security
  • Management
  • FOCUS
  • Automated Testing
  • SAFE
  • GitHub
  • Jenkins
  • Software Engineering
  • Research
  • Programming Languages
  • Java
  • C#
  • C
  • C++
  • Python
  • JavaScript
  • TypeScript
  • .NET
  • Authentication
  • Authorization
  • Supply Chain Management
  • Penetration Testing
  • Reverse Engineering
  • Code Review
  • OWASP
  • SANS
  • Software Security
  • Testing
  • SCA
  • Security QA
  • Fluency
  • Microsoft Certified Professional
  • Prompt Engineering
  • Orchestration
  • Artificial Intelligence
  • Evaluation
  • Continuous Integration
  • Continuous Delivery
  • Docker
  • Kubernetes
  • Cloud Computing
  • Workflow
  • Financial Services
  • Sarbanes-Oxley
  • System On A Chip
  • Auditing
  • Presentations
  • Open Source
  • Vulnerability Management
  • OSCP
  • CISSP

Summary

Job Summary We are seeking a Principal Consultant, Agentic AI Cybersecurity Engineer to work hands-on with cybersecurity engineering and application security teams to build, operate, and advance agentic AI systems that identify, validate, and remediate vulnerabilities across application and infrastructure environments. This role operates at a principal engineering level and combines offensive and defensive security expertise, penetration testing, software engineering, and agentic AI. The ideal candidate will have experience directing advanced AI models to discover vulnerabilities, develop proof-of-concept exploits, generate and validate fixes, and integrate remediation capabilities into CI/CD pipelines with appropriate human-in-the-loop controls. The role will also focus on developing reusable AI skills, prompts, tooling, guardrails, and evaluation frameworks to enable scalable agentic vulnerability management within a regulated enterprise environment. Key Responsibilities Architect and operationalize end-to-end agentic AI patching pipelines spanning vulnerability detection, fix generation, automated testing, and release across SAST, DAST, SCA, IAST, container, and server vulnerabilities. Use advanced AI models to identify vulnerabilities in production application and infrastructure code, develop proof-of-concept exploits, and validate AI-generated fixes. Build and maintain reusable AI skills, prompts, evaluation harnesses, and tooling for vulnerability discovery, triage, remediation, false positive analysis, and exemption workflows. Design and operationalize AI-driven false positive analysis and exemption processes to reduce manual triage and surface actionable findings to development teams. Conduct hands-on penetration testing and red team exercises against critical applications and infrastructure to validate defensive controls and AI-generated remediations. Extend agentic remediation capabilities across SAST, SCA, DAST, IAST, container, and server vulnerabilities, including the data and tooling required to connect findings to source code. Design agent prompts, guardrails, evaluation frameworks, and human-in-the-loop controls to support safe autonomous code changes, testing, and deployment. Integrate agentic remediation capabilities into enterprise CI/CD pipelines, including GitHub and Jenkins. Communicate technical designs, risk trade-offs, and delivery progress to senior stakeholders, including CIO, CISO, second-line-of-defense, and Audit functions. Required Qualifications 10+ years of hands-on experience across software engineering, offensive security, and defensive security at a principal engineering level. Demonstrated experience contributing directly to production codebases and conducting vulnerability research or penetration testing engagements. Advanced technical proficiency in multiple programming languages and technologies, including Java, C#, C, C++, Python, JavaScript/TypeScript, .NET, and Go. Proven ability to write, review, and remediate production code. Deep knowledge of vulnerability classes including memory safety, injection, authentication and authorization flaws, cryptographic misuse, deserialization, race conditions, and supply chain attacks. Extensive hands-on experience with penetration testing, red teaming, exploit development, reverse engineering, and secure code review. Experience identifying and addressing vulnerabilities aligned with OWASP Top 10 and SANS Top 25. Defensive engineering experience developing security detection and remediation capabilities. Extensive experience with application security testing tools and practices, including SAST, DAST, IAST, and SCA. Experience with security testing tool tuning, false positive analysis, exemption workflow design, and enterprise vulnerability management at scale. Strong technical fluency with agentic AI coding tools and frameworks, including Claude, Devin, Copilot, Windsurf, Cursor, and MCP. Experience with prompt engineering, agent orchestration, reusable AI skill and tool design, guardrail design, and evaluation frameworks. Strong architectural knowledge of modern CI/CD practices, container platforms such as Docker and Kubernetes, cloud-native deployment patterns, and security automation within developer workflows. Preferred Qualifications Experience with relevant security certifications such as OSCP, OSCE, OSEP, GXPN, GWAPT, CISSP, or equivalent. Experience in financial services or other highly regulated industries, including exposure to SOX, SOC 1, and regulatory audits. Public evidence of offensive security expertise through published CVEs, bug bounty participation, conference presentations, CTF placements, or open-source security tooling contributions. Hands-on experience with enterprise vulnerability management tools such as Tenable, Aqua, Snyk, or BrightSec. Demonstrated ability to advise senior technology leaders and deliver solutions within complex, multi-stakeholder enterprise environments. Education: Bachelors Degree Certification: OSCP , OSCE , OSEP , GXPN , GWAPT , CISSP
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: compun
  • Position Id: KUMDC5877830
  • Posted 2 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

No location provided

Today

Easy Apply

Contract, Third Party

Remote

3d ago

Easy Apply

Contract

Depends on Experience

Remote

Today

Full-time

USD 200,000.00 - 290,000.00 per year

Remote

Today

Full-time

USD 168,000.00 - 210,000.00 per year

Search all similar jobs