Application Security Engineer - Threat & Vulnerability Management (AI Focus) for

Remote • Posted 4 hours ago • Updated 4 hours ago
Contract Independent
Contract W2
12 Months
No Travel Required
Remote
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Application Security
  • DevSecOps
  • Product Security
  • Vulnerability Management
  • SAST
  • DAST
  • Software Composition Analysis (SCA
  • CI/CD security
  • OWASP Top 10
  • OWASP API Security Top 10
  • OWASP LLM Top 10
  • OWASP Agentic AI

Summary

Job Title: Application Security Engineer - Threat & Vulnerability Management (AI Focus)
Location: Remote
Duration: 6+ Months

Position Overview: 
The Application Security Engineer - Threat & Vulnerability Management (AI Focus) is responsible for driving secure-by-design practices across AI and agentic application development lifecycles. This role partners closely with engineering, platform, security, and AI teams to ensure that AI-powered applications, agents, and supporting pipelines are developed, tested, deployed, and maintained securely.
The ideal candidate will lead vulnerability management initiatives for AI workloads, establish security controls throughout AI development pipelines, and proactively assess emerging threats associated with Large Language Models (LLMs), AI agents, and AI supply chains.

Job Description:
Key Responsibilities

Secure Development & DevSecOps
•    Integrate and optimize SAST, DAST, SCA, and other application security tooling within AI and agentic CI/CD pipelines.
•    Develop and maintain secure SDLC controls for AI application development.
•    Establish security guardrails and best practices for developers, makers, and AI engineering teams.
•    Collaborate with platform and engineering teams to embed security requirements into AI development workflows.

Threat Modeling & Risk Management
•    Lead threat modeling exercises for AI applications, agents, and LLM-powered systems.
•    Assess risks associated with OWASP LLM Top 10, OWASP Agentic AI Top 10, and other emerging AI security frameworks.
•    Identify and mitigate AI-specific attack vectors including:

Vulnerability Management
•    Define and enforce vulnerability management standards and SLAs across AI workloads.
•    Conduct vulnerability assessments and coordinate remediation efforts with development teams.
•    Track, prioritize, and report application security risks using risk-based methodologies.
•    Monitor security posture and provide recommendations for continuous improvement.

AI Supply Chain Security
•    Build and manage Software Bill of Materials (SBOM) capabilities for AI, LLM, and traditional software assets.
•    Evaluate risks associated with open-source models, libraries, plugins, and third-party AI services.
•    Ensure governance and compliance of AI dependencies throughout the software lifecycle.

Governance & Security Enablement
•    Develop security standards, policies, and guidance for AI application development.
•    Provide training and consultation to development teams on secure AI coding practices.
•    Participate in architecture reviews and security assessments for AI initiatives.
•    Support audits, compliance assessments, and security reviews related to AI systems.
 
Experience
•    5+ years of experience in Application Security, DevSecOps, Product Security, or Vulnerability Management.
•    Experience implementing and managing:
o    SAST
o    DAST
o    Software Composition Analysis (SCA)
o    CI/CD security controls
•    Hands-on experience integrating security solutions into modern software delivery pipelines.
•    Experience conducting threat modeling and security architecture reviews.

Technical Skills
•    Deep understanding of secure application development methodologies.
•    Knowledge of AI/LLM attack surfaces and emerging AI security risks.
•    Familiarity with OWASP Top 10, OWASP API Security Top 10, OWASP LLM Top 10, and OWASP Agentic AI guidance.
•    Experience with container, cloud, and API security.
•    Knowledge of Software Bill of Materials (SBOM) frameworks and supply chain security practices.
•    Strong understanding of DevOps, CI/CD, and cloud-native architectures.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91170859
  • Position Id: 9097236
  • Posted 4 hours ago
Contact the job poster
KS

Kevin Smith

Recruiter @ Tetra Computing
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote or Virginia

•

Today

Full-time

USD 120,000.00 - 160,000.00 per year

Remote

•

Today

Full-time

USD 120,000.00 - 140,000.00 per year

Remote or North Carolina

•

Today

Full-time

Remote

•

Today

Full-time

USD 157,675.00 - 238,500.00 per year

Search all similar jobs