Application & AI Security Engineer

MissionSquare

Washington (District of Columbia)

Hybrid

USD 128,000 - 206,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Total rewards
Hybrid schedule
Tuition reimbursement
Career development
Wellness programs
Volunteer program

Job summary

MissionSquare is seeking an Application & AI Security Engineer in the Washington, DC area. The role embeds security across the SDLC, drives automation of security tooling, and secures AI-enabled applications with a security-first mindset.

You will collaborate with developers, architects, and security teams to reduce enterprise risk, apply threat modeling for AI/LLM, and promote secure development practices across multidisciplinary teams.

Qualifications

  • Bachelor's degree or equivalent professional experience.
  • 7+ years in IT, information security, or related discipline.
  • Experience with agile workflows (Scrum/Kanban).
  • Hands-on application security testing experience (Burp Suite).
  • Experience with SAST, SCA, DAST.
  • Experience securing AI/LLM-powered apps; OWASP Top 10 for LLM; MITRE ATLAS.
  • Experience with Claude and GPT models.
  • Knowledge of OWASP, CVSS, MITRE ATT&CK, SDLC.
  • Preferred CISSP or GWAPT.

Responsibilities

  • Collaborate with developers to embed security into design and deployments.
  • Perform security testing and validation of controls across projects.
  • Oversee defensive security practices across applications, including AI-enabled applications.
  • Apply SAST, SCA, DAST tools to identify and remediate risks.
  • Identify vulnerabilities via automated and manual reviews; prioritize fixes.
  • Apply threat modeling to AI/LLM design and development.
  • Assess and secure AI/ML applications; govern AI coding tools.
  • Serve as security escalation point and drive resolution.
  • Build tools to help teams adopt security components.
  • Support shift-left security throughout SDLC.
  • Other duties as assigned.

Skills

Security testing
SAST
SCA
DAST
Threat modeling
AI/LLM security
Java/Python scripting
Code reviews

Education

Bachelor's degree or equivalent

Tools

Burp Suite
OWASP Top 10 for LLM Apps
MITRE ATT&CK
Claude & GPT models
Security tooling (CI/CD)

Job description

Join a great place to work with MissionSquare, a financial services corporation with approximately $79 billion in assets under management and administration and over 600 employees. Founded in 1972, MissionSquare is dedicated to the retirement needs of public sector employees. We focus on delivering results-oriented retirement and retiree health savings plans, education, investment options, personalized guidance, and related services to public sector participants in more than 9,200 plans and nearly 2 million participant accounts. We strive to make the administration of retirement programs as easy and cost-effective as possible. We have an extraordinary talent base and invite you to consider joining MissionSquare.

$128,490.00 - $205,580.00

The Application & AI Security Engineer is a highly technical role responsible for advancing and embedding application and AI security across the software development lifecycle. This role drives automation of application security tooling, strengthens secure coding and design practices, secures AI- and LLM-powered applications, and promotes adherence to secure development principles. The engineer partners with developers, architects, cybersecurity teams, data engineers, stakeholders, and scrum masters to deliver secure, resilient applications. With a security-first mindset, the role continuously assesses application and AI threats, reduces enterprise risk, and supports secure development and deployment practices across multidisciplinary teams.

  • MissionSquare cannot sponsor or hire candidates with H1B, STEM or OPT visas for this role.***
Essential Functions For This Role Include
  • Build relationships with developers, stakeholders, and scrum master to incorporate security principles into engineering design and application deployments.
  • Perform security testing and validation of application security controls across projects, ensuring secure design and implementation.
  • Oversee the implementation of defensive security practices and countermeasures across applications, including AI-enabled applications.
  • Apply SAST, SCA, and DAST tools and methodologies to identify and reduce application security risk.
  • Identify vulnerabilities in code through automated and manual assessments and promote efficient remediation.
  • Apply threat modeling principles to improve design and development practices, including threat modeling for AI/LLM applications.
  • Assess and secure AI/ML and generative AI applications, including model and LLM integration security, prompt injection, and data-leakage risks, and govern the safe use of AI coding assistants in the development lifecycle.
  • Serve as a point of contact for security-based escalations and remain closely involved in resolution activities.
  • Build services and tools that enable developers and engineers to easily adopt and use security components produced by the application security team.
  • Support shift-left initiatives by incorporating security early and throughout the development lifecycle.
  • Performs other duties as assigned
If you have the following skills, we encourage you to apply
  • Bachelor's degree (BA/BS), or equivalent professional experience
  • At least 7+ years of experience in information technology, information security administration, security operations, or a related technical security discipline
  • Experience with agile workflows, including Scrum and Kanban
  • Hands-on experience with application security testing, including Burp Suite
  • Demonstrated experience with SAST, SCA, and DAST tools and methodologies
  • Experience securing AI/LLM-powered applications and familiarity with the OWASP Top 10 for LLM Applications and MITRE ATLAS
  • Experience using Claude and GPT models
  • Familiarity with securing and governing AI-assisted coding tools in the software development lifecycle
  • Ability to write code using Java, Python, Bash, Perl, or PowerShell
  • Understanding of OWASP, CVSS, the MITRE ATT&CK framework, and the software development lifecycle (SDLC)
  • Foundational knowledge of infrastructure and operating systems
  • Preferred certifications: CISSP and/or GIAC Web Application Penetration Tester (GWAPT)
To benefit your career and support your wellbeing, we offer
  • Competitive Total Rewards package, including base pay, incentive programs, benefits, and a 401(k) plan with matching contributions
  • Flexible and hybrid work schedules to support work-life balance
  • Tuition reimbursement to support continued education
  • Professional and career development opportunities, including courses and certifications
  • Comprehensive wellness programs promoting physical, mental, and emotional health
  • Volunteerism initiatives to encourage community engagement
Equal Employment Opportunity

As a company, MissionSquare is an Equal Opportunity Employer. We strive to create an environment that reflects the value and diversity of our employees and fosters respect among them. We believe that talent from diverse backgrounds will further enhance our ability, and mission, to serve those who serve their communities.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, or any other protected classifications under any applicable law.

This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer II
Application Security Engineer II

Abnormal • United States

On-site
USD 130,000 - 187,000
Application Security Engineer II
Application Security Engineer II

Socket.dev • United States

On-site
USD 130,000 - 187,000
Senior Application Security Architect
Senior Application Security Architect

State Street • Princeton (NJ)

Hybrid
USD 120,000 - 203,000
401(k) with company match
Comprehensive health/dental/vision-ins
Paid time off and disability coverage
+1
Senior Application Security Architect
Senior Application Security Architect

State Street • Quincy (MA)

Hybrid
USD 120,000 - 203,000
Senior Application Security Architect
Senior Application Security Architect

State Street • Clifton (NJ)

Hybrid
USD 120,000 - 203,000
401K with company match
Comprehensive benefits program
Paid time off
Senior Application Security Architect
Senior Application Security Architect

State Street • Austin (TX)

Hybrid
USD 120,000 - 203,000
401K match
Medical, dental, vision insurance
Paid time off
+1
Senior Application Security Architect
Senior Application Security Architect

State Street • Berwyn (PA)

On-site
USD 120,000 - 203,000
401K with company match
Comprehensive benefits package
Paid time off
Application Security Engineer II
Application Security Engineer II

Abnormal AI • United States

On-site
USD 130,000 - 187,000
Application Security Engineer
Application Security Engineer

Pantera Capital • Palo Alto (CA)

On-site
USD 100,000 - 258,000
Equity
Medical coverage
401(k)
Director, Application Security Austin, TX
Director, Application Security Austin, TX

Webai • Austin (TX)

On-site
USD 180,000 - 280,000
Competitive salary
Health benefits (medical/dental/vision
401(k) match
+7