AI-Powered AppSec Architect for Secure Code & SDLC

Information Technology Senior Management Forum

Tempe (AZ)

Hybrid

USD 120,000 - 204,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

The Information Technology Senior Management Forum seeks an Application Security Architect to design and operate a CI/CD–integrated AI evaluation harness that scans source code for security flaws across apps and infrastructure. This hands-on IC role blends AppSec, DevSecOps, AI engineering, and secure SDLC governance.

You will lead integration with pipeline tooling, create AI-assisted review methods, maintain benchmarks and regression tests, govern vendor AI models, and ensure compliance with

Qualifications

  • Bachelor’s degree in CS, cybersecurity, software engineering, IT, or related field.
  • 10+ years in application security, secure software engineering, DevSecOps, security architecture, or related roles.
  • Deep expertise in secure code review, vulnerability detection, threat modeling, exploitability analysis, and secure SDLC practices.
  • Experience with vulnerability and penetration test readouts/walkthroughs with stakeholders.
  • Hands-on experience with SAST, SCA, DAST, secrets scanning, API security testing, container security, IaC scanning, and developer workflow integrations.
  • Experience integrating security capabilities into SDLC pipeline tooling (Jenkins, GitHub Actions, GitHub Enterprise, Atlassian).
  • Practical experience using LLMs or AI models for code review, software engineering, vulnerability research, security analysis, or developer productivity use cases.
  • Understanding of prompt engineering, RAG, model evaluation, AI guardrails, human-in-the-loop review, prompt/model versioning, and vendor/open-source model trade-offs.
  • Experience designing or maintaining evaluation harnesses, benchmark suites, regression tests, validation pipelines, and test orchestration workflows.
  • Strong understanding of OWASP, CWE, CVSS, NIST SSDF, AI security risks, regulated source-code handling, auditability, and vendor/model governance.

Responsibilities

  • Architect the CI/CD-integrated AI secure-code evaluation harness as a hands-on IC for source code repositories and Secure SDLC lifecycles.
  • Integrate evaluation workflows with pipeline tooling and AppSec reporting platforms.
  • Design AI-assisted secure code review methods that complement SAST, SCA, DAST, secrets scanning, IaC scanning, threat modeling, security testing, and manual assessments.
  • Maintain benchmarks, golden test cases, prompt/model versions, retrieval configurations, scoring criteria, and regression tests for AI-generated findings.
  • Govern approved vendor and frontier AI models, including selection, routing, fallback patterns, accuracy, explainability, cost, and data-protection trade-offs.
  • Define safeguards for proprietary production code, including access controls, approved model endpoints, minimization, retention limits, secure logging, and evidence handling.
  • Route validated findings into developer workflows with actionable remediation guidance and feedback loops to reduce false positives and improve adoption.
  • Define metrics and control evidence aligned to internal governance processes, financial services authorities, and cyber security frameworks (NIST SSDF, NIST CSF 2.0, NYDFS, FINRA, SOX ITGC, FFIEC, GLBA).

Skills

AppSec
DevSecOps
Threat modelling
Vulnerability detection
SAST
SCA
DAST
AI for code review
Prompt engineering
Model governance
CI/CD tooling
Jenkins
GitHub Actions
GitHub Enterprise

Education

Bachelor’s degree in Computer Science or related field

Tools

Jenkins
GitHub Actions
GitHub Enterprise
Atlassian tools

Job description

The Information Technology Senior Management Forum seeks an Application Security Architect to design and operate a CI/CD–integrated AI evaluation harness that scans source code for security flaws across apps and infrastructure. This hands-on IC role blends AppSec, DevSecOps, AI engineering, and secure SDLC governance.

You will lead integration with pipeline tooling, create AI-assisted review methods, maintain benchmarks and regression tests, govern vendor AI models, and ensure compliance with

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI-Driven Application Security Architect
AI-Driven Application Security Architect

Edward Jones • St. Louis (MO)

Hybrid
USD 150,000 - 230,000
Medical and prescription drug coverage
Dental coverage
Vision coverage
+2
AI-Driven AppSec Architect: Secure SDLC & DevSecOps
AI-Driven AppSec Architect: Secure SDLC & DevSecOps

Edward Jones • Tempe (AZ)

Hybrid
USD 150,000 - 190,000
Medical benefits
Dental & vision
401k plan
+1
AI-Powered AppSec Director: Architect Secure SDLC
AI-Powered AppSec Director: Architect Secure SDLC

Zeta Global Corp. • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 210,000
Unlimited PTO
Excellent medical, dental, and vision
Employee Equity
+3
Senior AI-Driven Application Security Architect
Senior AI-Driven Application Security Architect

Cvent • Tysons (VA)

Hybrid
USD 120,000 - 160,000
Bonus
Competitive benefits
Senior AppSec Engineer: AI-Driven Secure Coding & CI/CD
Senior AppSec Engineer: AI-Driven Secure Coding & CI/CD

AgileEngine • United States

Hybrid
USD 120,000 - 180,000
Flextime
Professional growth
Competitive compensation
+2
Lead AI-Sec at Scale: AppSec Manager
Lead AI-Sec at Scale: AppSec Manager

United States Digital Space LLC • United States

Hybrid
USD 210,000 - 270,000
Remote-friendly Europe role
25 days annual leave
Referral scheme
+2
AI-Application Security Engineer
AI-Application Security Engineer

Stifel Financial Corp. • St. Louis (MO)

On-site
USD 90,000 - 120,000
Senior AppSec Engineer — AI-Driven Security in SDLC (Remote)
Senior AppSec Engineer — AI-Driven Security in SDLC (Remote)

AgileEngine, LLC • Brazil (IN)

On-site
USD 120,000 - 160,000
GenAI-Savvy App Security Architect | Cloud & DevSecOps
GenAI-Savvy App Security Architect | Cloud & DevSecOps

New York Technology Partners • New York (NY), Jersey City (NJ)

Hybrid
USD 180,000 - 240,000
Senior AI-Driven AppSec Engineer
Senior AI-Driven AppSec Engineer

Cvent, Inc. • Tysons (VA)

Hybrid
USD 120,000 - 160,000