AppSec Engineer: Secure SDLC & AI Security

Teradata Corporation (SE)

Columbus (OH)

On-site

USD 102,000 - 153,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Healthcare
401(k) retirement plan
Time-off programs

Job summary

Teradata seeks an Application Security Engineer to automate security across the software development lifecycle and collaborate with Product Engineering to push security left. You will analyze code across Java, C/C++, Go, Python, and JavaScript/TypeScript, integrate scanning tools in CI/CD, and guide teams on remediation for OWASP Top Ten risks.

Responsibilities include evaluating supply chain risks, reviewing IaC configurations, and communicating risk to technical and non-technical stakeholders

Qualifications

  • Read and reason about code in Java, C/C++, Go, Python, or JavaScript/TypeScript to identify and address security issues.
  • Integrate SAST, SCA, DAST, IaC, and Container scanning into CI/CD pipelines.
  • Spot manual security processes and build automation to replace them.
  • Write and maintain security automation scripts in Go.
  • Identify and remediate software supply chain risks including malicious or compromised third-party packages, typosquatting, and dependency confusion attacks.
  • Evaluate internal software and third-party products against security requirements.
  • Evaluate new technologies and development practices for AppSec impact.
  • Apply OWASP AI security standards to assess and reduce risk in AI-generated code and agentic workflows outlined in OWASP AI Top Tens.
  • Familiarity with the OWASP AISVS and OWASP Top 10 for LLMs, Agentic Apps, or NHIs as emerging standards for AI security.
  • Translate SAST, SCA, DAST, IaC, container scan, and pentest findings into plain-language summaries for non-security audiences.
  • Work directly with Product Engineering to improve security practices across the Secure SDLC.
  • Deliver developer training on secure coding, security requirements, and AppSec tooling.
  • Guide and mentor software engineers on vulnerability remediation.
  • Serve as the go-to SME for AppSec topics, processes, and tooling.
  • Make sound, well-reasoned security decisions and explain the tradeoffs clearly.

Responsibilities

  • Analyze and triage findings from SAST, SCA, DAST, IaC, and container scanning tools to identify true positives and eliminate noise.
  • Deliver clear, actionable remediation guidance to development teams for AppSec findings across the application portfolio.
  • Perform code reviews and reason about vulnerabilities across Java, C/C++, Go, Python, and JavaScript/TypeScript codebases.
  • Integrate and tune AppSec scanning tools within CI/CD pipelines to shift security left in the SDLC.
  • Assess web applications and APIs for common vulnerability classes including the OWASP Top Ten (2025).
  • Apply OWASP ASVS, AISVS, and SVPS standards to application security assessments and security requirement definitions.
  • Review AI-assisted development workflows and evaluate agentic systems for risks such as prompt injection, excessive permissions, unsafe tool use, and insecure output handling.
  • Investigate software supply chain risks by analyzing open-source dependencies for known vulnerabilities, suspicious packages, and dependency confusion exposures.
  • Write and maintain automation scripts in Go to streamline security processes and tool integrations.
  • Review and assess Infrastructure as Code configurations in Terraform, CloudFormation, Helm, and Ansible for security misconfigurations.
  • Evaluate cloud environments across AWS, Azure, and/or Google Cloud for AppSec risk and misconfigurations.
  • Communicate security findings and risk clearly to both technical and non-technical stakeholders.
  • Support compliance activities related to PCI-DSS and FedRAMP as they intersect with application security.

Skills

Code reading & reasoning
CI/CD security integration
Automation scripting (Go)
Vulnerability remediation guidance
Threat modeling & risk assessment

Education

MS/BS in Electrical Engineering, CS, IT, or related field
Advanced degree preferred

Tools

SAST tools
SCA tools
DAST tools
IaC scanners
Container scanning tools
Terraform
CloudFormation
Helm
Ansible

Job description

Teradata seeks an Application Security Engineer to automate security across the software development lifecycle and collaborate with Product Engineering to push security left. You will analyze code across Java, C/C++, Go, Python, and JavaScript/TypeScript, integrate scanning tools in CI/CD, and guide teams on remediation for OWASP Top Ten risks.

Responsibilities include evaluating supply chain risks, reviewing IaC configurations, and communicating risk to technical and non-technical stakeholders

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer — Secure SDLC & AI Risk
Application Security Engineer — Secure SDLC & AI Risk

Teradata Corporation (SE) • Nashville (TN)

On-site
USD 102,000 - 153,000
AppSec Engineer — Shift-Left Security for AI‑Driven Apps
AppSec Engineer — Shift-Left Security for AI‑Driven Apps

Teradata • California (MO)

Hybrid
USD 120,000 - 190,000
Application Security Engineer — Shift Left & Automate
Application Security Engineer — Shift Left & Automate

Teradata Group • San Diego (CA)

On-site
USD 130,000 - 190,000
AppSec Engineer – Shift-Left & Automate Security
AppSec Engineer – Shift-Left & Automate Security

Teradata Corporation (SE) • Frankfort (KY)

On-site
USD 102,000 - 153,000
Application Security Engineer - Shift Left & Automation
Application Security Engineer - Shift Left & Automation

Teradata Corporation (SE) • Richmond (VA)

On-site
USD 102,000 - 153,000
Flexible work model
Health benefits
401(k) plan
Shift-Left Application Security Engineer
Shift-Left Application Security Engineer

Teradata Corporation (SE) • Jackson (MS)

On-site
USD 102,000 - 153,000
Flexible work options
Competitive benefits
Application Security Engineer
Application Security Engineer

Teradata Group • San Diego (CA)

On-site
USD 130,000 - 190,000
AppSec Architect: Secure SDLC & DevSecOps Lead
AppSec Architect: Secure SDLC & DevSecOps Lead

TechDigital Group • Maryland Heights (MO)

On-site
USD 120,000 - 160,000
AppSec Engineer - AI/SDLC Security & Automation
AppSec Engineer - AI/SDLC Security & Automation

Nelnet, Inc. • Northern (KY)

Hybrid
USD 90,000 - 125,000
Medical insurance
Dental insurance
Vision insurance
+10
Application Security Engineer: DevSecOps & AI Security
Application Security Engineer: DevSecOps & AI Security

Worky • Dallas (TX)

On-site
USD 120,000 - 180,000