Match Score
Against your primary resumeLogin to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Protocol Intelligence
Data-driven signals on your job's competitivenessSenior niche AppSec role in a metro with regional brand yields moderate competition.
Requires specialized AppSec and AI red-team expertise, reducing cross-industry transferability.
Mandatory 8+ years, deep AppSec, AI red-team, and CI/CD/IaC tool experience increases strictness.
Job Description
Structured overview of role & requirementsAbout This Role
Lead development and execution of Application Security strategy across web, mobile, API, data, and AI/ML products, defining standards and secure-by-default patterns.
Conduct threat modeling sessions for critical services and AI/ML pipelines, lead AI red teaming and adversarial testing, translating findings into actionable engineering fixes.
Embed security automation across SDLC pipelines including SAST, DAST, container scanning, and manage vulnerability lifecycle and security assurance activities.
Minimum Requirements
Bachelor’s or Master’s degree in Computer Science, Engineering, Cybersecurity, or equivalent practical experience.
8+ years in security engineering, DevSecOps, automation, or application vulnerability management with leadership or staff-level scope experience.
Experience in threat modeling and security architecture reviews, plus red-teaming or adversarial testing of AI/LLM systems.
Proficiency in security tools across SDLC (SAST, DAST, ASPM, secrets scanning), scripting skills in Python/Bash, and familiarity with CI/CD and cloud environments.
Ideal Candidate Profile
Senior technical contributor with strong expertise in AppSec strategy and threat modeling for complex, multi-domain applications including AI/ML.
Demonstrated ability to lead AI-specific adversarial testing and integrate security engineering within fast-moving software development environments.
Experienced in mentoring and influencing across engineering and product teams to embed security, improve workflows, and deliver measurable security outcomes.
