Application Security Engineer - DevSecOps & Red Team

Jobright.ai

San Francisco (CA)

On-site

USD 140,000 - 200,000

Full time

23 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Writer Corporation seeks an Application Security Engineer to secure its AI and AGI applications by embedding security into development pipelines, performing pen tests, and collaborating with cross-functional teams to safeguard AI solutions.

The role emphasizes automation of security testing, secure deployment practices, and threat modeling across cloud-native architectures, while enabling proactive remediation and architecture reviews.

Qualifications

  • 8+ years in application security with hands-on testing.
  • 5+ years conducting penetration tests and security assessments.
  • Proven record of finding and exploiting critical vulnerabilities.
  • Deep experience integrating security into DevOps workflows and CI/CD pipelines.
  • Strong programming skills for exploit development and security automation.
  • Expertise in web application and API security, including cloud-native architectures.
  • Proficient with penetration testing tools (e.g., Burp Suite, OWASP ZAP, custom scripts).
  • Skilled in SAST, DAST, and SCA tools.
  • Strong understanding of application-layer attack techniques and exploitation.
  • Experience with supply chain security and build pipeline hardening.
  • Demonstrated ability to translate red team findings into concrete defensive measures.

Responsibilities

  • Embed security in the build pipeline — Own pre-deployment application security, including automated vulnerability scanning, container scanning, and custom security gates in CI/CD
  • Conduct advanced application penetration testing — Perform comprehensive testing on AI applications, APIs, and model endpoints, simulating adversarial attacks to validate controls
  • Automate security testing at scale — Develop scripts, tools, and frameworks for continuous security assessment, including SAST, DAST, and SCA integration
  • Lead application-layer red team exercises — Plan and execute engagements that mimic sophisticated adversary techniques targeting AI systems
  • Hunt and validate vulnerabilities — Discover, reproduce, and chain vulnerabilities into realistic attack paths, providing actionable remediation guidance
  • Advise on security architecture — Review designs for weaknesses, create secure patterns, and identify systemic issues across applications
  • Collaborate across boundaries — Partner with Cloud/Infrastructure on deployment/runtime security, AI Security on threat modeling, and Detection & Response on defensive validation

Skills

AppSec expertise
Penetration testing
DevSecOps automation
CI/CD integration
Vulnerability discovery
SAST tools
DAST tools
API security
Exploit development
Security architecture
Purple team operations
Collaboration

Tools

Burp Suite
OWASP ZAP
custom scripts

Job description

Writer Corporation seeks an Application Security Engineer to secure its AI and AGI applications by embedding security into development pipelines, performing pen tests, and collaborating with cross-functional teams to safeguard AI solutions.

The role emphasizes automation of security testing, secure deployment practices, and threat modeling across cloud-native architectures, while enabling proactive remediation and architecture reviews.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer — DevSecOps & AI
Application Security Engineer — DevSecOps & AI

FSAStore.com • United States

On-site
USD 75,000 - 95,000
Medical, Dental, Vision
401K with company match
Flexible PTO
+2
Application Security Engineer - Shift Left & Secure AI Apps
Application Security Engineer - Shift Left & Secure AI Apps

Teradata Corporation (SE) • Salem (OR)

On-site
USD 102,000 - 153,000
401(k) retirement plan
Benefits package
App Security Engineer - AI-Driven DevSecOps
App Security Engineer - AI-Driven DevSecOps

GameChanger • United States

Remote
USD 110,000 - 170,000
Remote US work
Unlimited vacation
Tech stipend
+5
Principal Application Security Engineer: AI & DevSecOps Leader
Principal Application Security Engineer: AI & DevSecOps Leader

Relha LLC • Brooklyn Park (MN)

Hybrid
USD 168,000 - 303,000
Health benefits
401(k) plan
Paid time off
AI Security Red Team Engineer: Assess, Build, Defend AI
AI Security Red Team Engineer: Assess, Build, Defend AI

Check Point Software Technologies • Washington

On-site
USD 135,000 - 195,000
AI Security Engineer — Red Team & Automation
AI Security Engineer — Red Team & Automation

Check Point Software • Washington

On-site
USD 120,000 - 180,000
App Security Engineer - Secure DevOps & Threat Modeling
App Security Engineer - Secure DevOps & Threat Modeling

Figure • United States

On-site
USD 120,000 - 155,000
Medical, dental, vision coverage
Company 401(k) and commuter benefits
Paid holidays and PTO
Application Security Engineer: DevSecOps & AI Security
Application Security Engineer: DevSecOps & AI Security

Worky • Dallas (TX)

On-site
USD 120,000 - 180,000
Application Security Engineer II — AI & Cloud Security
Application Security Engineer II — AI & Cloud Security

Abnormalsecurity • United States

On-site
USD 130,000 - 187,000
Bonus potential
Equity
Benefits package
Application Security Engineer - SDLC & AI Security
Application Security Engineer - SDLC & AI Security

Jobtailor • San Francisco (CA)

On-site
USD 140,000 - 180,000