Lead Engineer, Information Security (Application Security)
Ai Security
Application Security
Cloud Native Security
Cloud Platforms
DevSecOps
Dynamic Application Security Testing
Information Security
InfoSec
Owasp Top Ten
Security Automation
Security Standards
Security Testing
Solution Architecture
Static Application Security Testing
Static Code Analysis
Technical Lead
Threat Modeling
Web Application Firewall
Web Security
Job Description
Lead Engineer, Application Security is a senior individual contributor role focused on scaling secure software practices across a multi-cloud environment.
Responsibilities
- Own application security standards, secure architecture principles, and threat modeling governance across the enterprise.
- Run security assessments and threat modeling for emerging technologies, including agentic AI solutions, LLMs, and autonomous AI workflows.
- Review and optimize Web Application Firewall (WAF) configurations to support application protection goals.
- Integrate and optimize automated security tooling such as SAST, DAST, and Software Composition Analysis (SCA) within CI/CD and DevSecOps processes.
- Collaborate with software engineering teams to identify vulnerabilities and provide code-level remediation guidance aligned to secure coding best practices.
- Support security awareness and enablement efforts by mentoring developers and facilitating Security Champion programs across engineering teams.
- Evaluate cloud-native applications and services in Azure, GCP, and OCI to ensure alignment with security standards.
- Help implement security controls in development pipelines, including mechanisms intended to block deployments with unresolved critical or high-risk vulnerabilities.
- Drive continuous improvement to enhance application security processes, tooling, and developer enablement.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field (or equivalent combination of education and experience).
- 3+ years of experience in Application Security, Security Engineering, DevSecOps, or a related cybersecurity discipline.
- Experience identifying and remediating security vulnerabilities within application code and software development environments.
- Experience with enterprise WAF platforms such as Akamai App & API Protector, F5 Advanced WAF, or similar technologies.
- Experience securing cloud-native workloads and applications in Azure, GCP, and/or OCI.
- Experience with container technologies, including Docker and Kubernetes.
- Experience integrating security tools into CI/CD pipelines and development workflows.
- Knowledge of OWASP Top 10, CWE, secure API design principles, and application security best practices.
- Strong analytical, problem-solving, and communication skills with the ability to collaborate across technical teams.
Technologies
- Web Application Firewall (WAF)
- Akamai App & API Protector
- F5 Advanced WAF
- SAST, DAST, Software Composition Analysis (SCA)
- CI/CD, DevSecOps
- Azure, Google Cloud Platform (GCP), Oracle Cloud Infrastructure (OCI)
- Docker, Kubernetes
- OWASP Top 10, Common Weakness Enumeration (CWE)
- Agentic AI solutions, Large Language Models (LLMs)
Benefits
- Comprehensive medical, dental, and vision plans
- 401(k) retirement plan with up to 5% company match
- Pre-tax accounts to help streamline eligible expenses
- Company-paid disability and life insurance
- Employee Assistance Program (EAP)
- Career and Leadership Development Programs
- Paid time off, company holidays, and volunteer days
It’d be great if you also have
- Experience securing AI-enabled applications, LLM-based solutions, or autonomous agent workflows.
- Experience with security certifications such as Microsoft Certified: Azure Security Engineer Associate, GCP Professional Cloud Security Engineer, CISSP, CSSLP, CASE, GWEB, or related security certifications.
- Experience with Akamai and/or F5 security platforms in large-scale enterprise environments.
- Experience leading Security Champion programs or mentoring engineering teams on secure development practices.
- Ability to influence cross-functional teams and drive security improvements through collaboration and technical expertise.
- Experience developing scalable security frameworks that support innovation while managing enterprise risk.