EngineerJobs.io
← Back to all jobs

Job Description

What you get

Join an on-site team in Atlanta where you will shape the enterprise AppSec program. This senior technical leadership role lets you own the strategy, standards, and tooling for application security while getting hands-on with AI security initiatives. You will report to the Sr. Director, IT Security, and collaborate closely with engineering leaders to embed security into system design, SDLC processes, and platform decisions. Expect a role centered on impact, collaboration, and measurable risk reduction, with opportunities to build AI powered security tooling and governance around AI/ML integrations.

Responsibilities

  • Define and own the enterprise AppSec architecture, standards, and secure-by-default patterns across the organization.
  • Establish and evolve the AppSec tooling strategy, evaluate vendors, and drive adoption across engineering teams.
  • Lead threat modeling sessions for critical applications and new product features.
  • Serve as the final technical authority on AppSec decisions, including security design reviews and architecture signoffs.
  • Oversee advanced secure code reviews, SAST/DAST assessments, and manual penetration testing across web, mobile, and API surfaces.
  • Own API security standards for REST and GraphQL, enforcing OWASP API Top 10 controls and authentication/authorization design patterns.
  • Drive vulnerability triage, risk prioritization, and remediation accountability across development teams at scale.
  • Own the DevSecOps toolchain by designing, deploying, and maturing security gates within CI/CD pipelines.
  • Partner with engineering leadership to embed security into system design, SDLC processes, and platform decisions.
  • Develop and monitor AppSec metrics, dashboards, and KPIs to demonstrate program maturity and risk reduction.
  • Hands-on development of AI powered security tooling and automation, including AI assisted code review, threat detection, and vulnerability triage.
  • Secure AI/ML integrations by assessing prompt injection, data leakage, model supply chain, and third-party AI service risks.
  • Develop and enforce AI governance policies, including acceptable use, security review gates, and risk acceptance criteria for AI adoption.
  • Represent the IT Security team in architecture reviews, cross functional planning, and executive risk reporting.
  • Maintain security policy and standards documentation related to AppSec, AI use, and API governance.
  • Lead AppSec representation in PCI-DSS, NIST, and OWASP audits, including evidence collection and coordination.

Requirements

  • 5+ years of experience in application security, software engineering, or secure code review.
  • Strong proficiency in one or more programming languages (Python, Java, JavaScript, or Go) with capability for in-depth code review and threat modeling.
  • Experience with SAST/DAST tooling (Snyk, SonarQube, Semgrep, Checkmarx, Burp Suite, OWASP ZAP) and ownership of AppSec program design.
  • Proven communication and presentation skills across multiple stakeholder levels.
  • Ability to meet deadlines and collaborate with management across diverse disciplines.
  • Proven track record of collaboration with cross functional teams.
  • Willingness to perform on-call duties during off hours and holidays.
  • Adaptable and flexible attitude toward changing business needs.
  • Bachelor's degree in computer science or a related field.
  • Experience leading red team, penetration testing, or adversarial simulations.
  • Experience designing and scaling security observability pipelines, including log analysis and application telemetry.
  • Working knowledge of PCI-DSS, NIST, OWASP, and other regulatory frameworks; experience representing security in audits and compliance reviews.
  • Proven ability to secure cloud native or hybrid cloud environments (AWS, Azure, or GCP).
  • Hands-on experience building, deploying, or integrating AI/ML powered tools and the ability to assess and govern their security posture (prompt injection, data leakage, model supply chain risks).
  • Demonstrated ability to define and enforce security standards across engineering organizations and to own a security capability or domain.
  • Certifications such as Security+, ISC2 CC, CompTIA A+, CompTIA Network+, SSCP, CCT, GWEB, CSSLP, CEH, or OSCP.

Technologies

  • Python, Java, JavaScript, Go
  • Snyk, SonarQube, Semgrep, Checkmarx, Burp Suite, OWASP ZAP
  • REST, GraphQL
  • AWS, Azure, GCP
  • PCI-DSS, NIST, OWASP

Travel

Open to travel between Carter's offices as needed.

Similar Jobs