Lead Security Engineer - Penetration Testing & AI Security

HighLevel

United States

Remote

USD 140,000 - 210,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

HighLevel is seeking a Lead Security Engineer – Application Security & AI Security to drive security across our products and platforms. You will lead security reviews, threat modeling, secure SDLC improvements, and vulnerability management for web, mobile, API, and cloud-native services.

You will also perform adversarial testing of LLM apps, AI agents, RAG architectures, and AI integrations, building repeatable security testing playbooks and automation.

Qualifications

  • 8+ years in cybersecurity with hands-on security engineering experience.
  • Experience in threat modeling, architecture reviews, and secure design.
  • Strong knowledge of web, mobile, API, and cloud-native security.
  • Hands-on DevSecOps experience with CI/CD security automation.

Responsibilities

  • Lead Application Security initiatives across web, mobile, API, and cloud-native products.
  • Conduct architecture reviews, threat modeling, secure design and code reviews.
  • Identify weaknesses in authentication, authorization, tenant isolation, and API security.
  • Define security standards, guardrails, and reusable patterns.
  • Improve security testing across CI/CD pipelines (SAST, DAST, SCA, secrets).
  • Drive vulnerability triage and remediation with engineering teams.
  • Develop security automation and provide developer guidance and training.
  • Lead security reviews of LLM apps, AI agents, and AI integrations.
  • Assess AI architectures, data pipelines, prompts, and model APIs.

Skills

Security leadership
Threat modeling
Secure SDLC
Vulnerability management
Security reviews
Communication

Tools

Docker
Kubernetes
Python
Go
JavaScript

Job description

About Us

HighLevel is an AI powered, all-in-one white-label sales & marketing platform that empowers agencies, entrepreneurs, and businesses to elevate their digital presence and drive growth. We are proud to support a global and growing community of over 1 million businesses, comprised of agencies, consultants, and businesses of all sizes and industries. HighLevel empowers users with all the tools needed to capture, nurture, and close new leads into repeat customers. As of mid 2025, HighLevel processes over 4 billion API hits and handles more than 2.5 billion message events every day. Our platform manages over 470 terabytes of data distributed across five databases, operates with a network of over 250 microservices, and supports over 1 million hostnames.



Our People

With over 1,500 team members across 15+ countries, we operate in a global, remote-first environment. We are building more than software; we are building a global community rooted in creativity, collaboration, and impact. We take pride in cultivating a culture where innovation thrives, ideas are celebrated, and people come first, no matter where they call home.



Our Impact

As of mid 2025, our platform powers over 1.5 billion messages, helps generate over 200 million leads, and facilitates over 20 million conversations for the more than 1 million businesses we serve each month. Behind those numbers are real people growing their companies, connecting with customers, and making their mark - and we get to help make that happen.


Learn more about us on our YouTube Channel or Blog Posts



About the Role

We are looking for a Lead Security Engineer – Application Security & AI Security with 8+ years of cybersecurity experience and strong expertise in securing modern applications, APIs, cloud-native services, and AI-enabled systems.


Application Security and AI Security will be the primary focus of this role. You will lead security reviews, threat modeling, application assessments, secure SDLC improvements, and vulnerability management across HighLevel’s products.


You will also serve as an AI Security specialist, assessing and adversarially testing LLM applications, AI agents, RAG implementations, and AI integrations. This is a hands-on, Lead-level individual-contributor role working closely with Engineering, Product, Infrastructure, and AI/ML teams.



What You’ll Be Doing


Application Security, Secure SDLC & DevSecOps


  • Lead Application Security initiatives across web, mobile, API, microservices, and cloud-native products.

  • Conduct architecture reviews, threat modeling, secure design and code reviews, and hands-on security assessments.

  • Identify weaknesses in authentication, authorization, tenant isolation, business logic, data protection, and API security.

  • Define practical security standards, requirements, guardrails, and reusable secure engineering patterns.

  • Improve security testing across CI/CD pipelines using SAST, DAST, SCA, secret scanning, container scanning, and Infrastructure as Code scanning.

  • Drive risk-based vulnerability triage and remediation in partnership with engineering teams.

  • Develop security automation and promote secure coding through developer guidance, documentation, and training.



AI Security Assessment & Adversarial Testing


  • Lead security reviews of LLM applications, AI agents, RAG architectures, machine learning services, and third-party AI integrations.

  • Assess AI architectures, including model APIs, data pipelines, vector stores, prompts, fine-tuning workflows, plugins, and agent tool chains.

  • Conduct adversarial testing for prompt injection, jailbreaking, sensitive-data disclosure, system-prompt leakage, output manipulation, insecure tool use, excessive agency, and model abuse.

  • Evaluate applicable risks involving data poisoning, model inversion, training-data extraction, adversarial evasion, and model exfiltration.

  • Test security controls such as guardrails, input/output filtering, access controls, human approvals, logging, monitoring, and abuse detection.

  • Develop repeatable AI security testing methodologies, playbooks, automation, and test cases using tools such as Garak, PyRIT, or similar frameworks.

  • Assess security and supply-chain risks associated with third-party models, AI platforms, and AI-enabled SaaS products.



Reporting, Collaboration & Leadership


  • Produce clear security reports containing evidence, risk ratings, business impact, and actionable remediation guidance.

  • Communicate security risks effectively to developers, architects, product leaders, and executive stakeholders.

  • Partner with external consultants, researchers, and bug bounty programs for specialized assessments where required.

  • Mentor engineers and help establish a security-conscious engineering culture.

  • Stay current with developments in Application Security, AI Security, and adversarial testing.



What You’ll Bring


  • 8+ years of cybersecurity experience, with deep hands-on expertise in Application Security, product security, penetration testing, or security engineering.

  • Experience conducting threat modeling, architecture reviews, secure code reviews, penetration testing, and vulnerability validation.

  • 1-3 years of AI Security experience, with AI/ML security, adversarial testing of AI systems, or applied AI research with a security focus.

  • Strong knowledge of web, mobile, API, and cloud-native security, including OWASP guidance and business-logic risks.

  • Strong understanding of authentication and authorization technologies, including OAuth 2.0, OIDC, JWT, SAML, and modern access-control models.

  • Hands-on DevSecOps experience with CI/CD security automation, SAST, DAST, SCA, secret scanning, containers, and Infrastructure as Code.

  • Practical knowledge of Docker, Kubernetes, microservices, and cloud security.

  • Demonstrated experience assessing or securing LLM applications, RAG systems, AI agents, machine learning models, or AI-enabled products.

  • Understanding of AI threats such as prompt injection, jailbreaking, data leakage, insecure tool use, excessive agency, model misuse, and AI supply-chain risks.

  • Familiarity with OWASP guidance for LLM applications, MITRE ATLAS, NIST AI RMF, and related AI security practices.

  • Programming or scripting proficiency in Python, Go, JavaScript, Bash, or a similar language.

  • Strong written and verbal communication skills, with the ability to influence technical and non-technical stakeholders.



Preferred Qualifications


  • Experience building or scaling Application Security practices within a SaaS or product-led technology organization.

  • Hands-on experience red teaming LLM applications, RAG systems, AI agents, or AI-enabled products.

  • Experience developing security automation, internal testing tools, or reusable security guardrails.

  • Contributions to security research, open-source projects, bug bounty programs, or responsible vulnerability disclosure.

  • Relevant certifications such as OSCP, OSWE, GWAPT, GIAC, CISSP, or an AI Security credential.



Equal Employment Opportunity Information

The company is an Equal Opportunity Employer. As an employer subject to affirmative action regulations, we invite you to voluntarily provide the following demographic information. This information is used solely for compliance with government record keeping, reporting, and other legal requirements. Providing this information is voluntary and refusal to do so will not affect your application status. This data will be kept separate from your application and will not be used in the hiring decision.


#LI-Remote #LI-SS1

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Engineer, Product Security
Senior Security Engineer, Product Security

United States Digital Space LLC • United States

Remote
USD 140,000 - 190,000
Frontier AI Offensive Security Specialist
Frontier AI Offensive Security Specialist

Hitachi Cyber • United States

On-site
USD 140,000 - 190,000
Frontier AI focus
Specialized AI security training
Mentorship within global cyber team
+1
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent • Virginia (MN)

Hybrid
USD 120,000 - 160,000
Hybrid work model
Competitive benefits package
AI Defense Engineer
AI Defense Engineer

Gravity IT Resources • Cincinnati (OH)

On-site
USD 140,000 - 210,000
Application & AI Security Engineer
Application & AI Security Engineer

Hydrogen Group • United States

On-site
USD 140,000 - 190,000
Lead Security Engineer: AI & App Security
Lead Security Engineer: AI & App Security

HighLevel • United States

Remote
USD 140,000 - 210,000
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent, Inc. • Virginia (MN)

On-site
USD 120,000 - 160,000
Hybrid work model
Competitive benefits
Sr Engineer I, Product Security
Sr Engineer I, Product Security

NextGen Healthcare, Inc. • Atlanta (GA)

On-site
USD 150,000 - 230,000
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Senior Security Engineer, Product Security
Senior Security Engineer, Product Security

GoodLeap, LLC • Northern (KY)

Hybrid
USD 146,000 - 170,000