Staff Application Security Engineer – AI & Agentic Systems
Job Description
Staff Application Security Engineer focused on embedding security into AI-enabled applications, LLM integrations, and agentic systems across design, development, and operations.
Responsibilities
- Develop and maintain application and AI security standards, best practices, and guardrails
- Promote secure-by-design principles across application and AI development lifecycles
- Create secure design patterns for AI agents, prompt management, tool integrations, memory handling, and autonomous workflows
- Partner with engineering teams to identify and mitigate AI-specific security risks (prompt injection, model abuse, data leakage, unauthorized agent actions)
- Act as a subject matter expert for securing AI-enabled applications and agentic systems
- Review and advise on architectures using large language models, retrieval augmented generation pipelines, AI agents, and AI-powered workflows
- Define and recommend identity, authorization, data protection, observability, and governance controls for AI environments
- Collaborate with AI platform, engineering, product, and data teams to enable secure and responsible AI adoption
- Perform threat modeling, architecture reviews, and security assessments for applications and AI-enabled systems
- Conduct security analysis across AI workflows, model integrations, agent interactions, and data flows
- Support prioritization and remediation of security findings with engineering teams
- Evaluate emerging AI security tools and technologies to strengthen organizational security posture
- Influence engineering teams to integrate security controls into development processes and product roadmaps
- Coordinate with privacy, compliance, legal, and risk teams to align security controls with organizational requirements
- Provide guidance on AI security considerations, emerging threats, and industry best practices
- Participate in strategic initiatives for secure AI adoption across the enterprise
- Support investigation and response for application and AI-related security events
- Assist with root cause identification and implement long-term security improvements
- Drive continuous improvement of security controls, processes, and engineering practices
- Mentor security engineers and development teams on secure coding, threat modeling, and AI security best practices
- Contribute to evaluating emerging AI security research, technologies, and industry standards
- Advance the application and AI security strategy through innovation and technical leadership
Requirements
- 7+ years of experience designing, building, or securing enterprise-scale applications and platforms
- 5+ years of application security experience (threat modeling, secure design, code review, vulnerability management)
- 5+ years of programming experience in one or more languages: Python, Java, JavaScript, C#, or Go
- 3+ years of experience developing or securing AI, machine learning, or generative AI solutions
- 3+ years of experience with public cloud platforms: AWS, Azure, or Google Cloud Platform
Technologies
- Python, Java, JavaScript, C#, Go
- AWS, Azure, Google Cloud Platform
- Large language models
- Retrieval augmented generation
- AI agents
Preferred Qualifications
- Experience securing modern application architectures including APIs, containers, microservices, and serverless technologies
- Strong understanding of secure software development lifecycle practices and application security testing methodologies
- Hands-on experience securing AI agents, retrieval augmented generation solutions, and large language model integrations
- Experience conducting threat modeling and security assessments for AI-enabled systems
- Familiarity with responsible AI principles, AI governance, and emerging AI security frameworks
- Experience integrating security controls into CI/CD pipelines
- Knowledge of common compliance frameworks such as PCI DSS, HIPAA, NIST, HITRUST, and CSA
- Ability to influence technical decisions across multiple teams and organizations
- Experience contributing to security research, open-source projects, or industry communities
Pay Range
- Typical pay range: USD 106,605 - 284,280 per year
- Eligible for a CVS Health bonus, commission, or short-term incentive program in addition to base pay range
- Includes an award target in the company’s equity award program
Location & Work Model
- Denver, CO (onsite)
Education
- Bachelor’s degree from an accredited college or university
- Or equivalent combination of education and relevant work experience (High School Diploma/GED plus 4 years of related experience)
Benefits
- Comprehensive benefits package designed to support physical, emotional, and financial well-being of colleagues and their families
- Medical, dental, and vision coverage (based on eligibility)
- Paid time off (based on eligibility)
- Retirement savings options (based on eligibility)
- Wellness programs (based on eligibility)
- Other resources (based on eligibility)
Incident Response & Continuous Improvement
- Support investigation and response efforts involving application and AI-related security events
- Assist in identifying root causes and implementing long-term security improvements
- Drive continuous improvement of security controls, processes, and engineering practices
Mentorship & Innovation
- Mentor security engineers and development teams on secure coding, threat modeling, and AI security best practices
- Contribute to evaluating emerging AI security research, technologies, and industry standards
- Help advance the organization’s application and AI security strategy through innovation and technical leadership