Manager - Application & AI Security

Prosum

Scottsdale (AZ)

On-site

USD 140,000 - 190,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Prosum is seeking a Manager, Application & AI Security to lead security across internally developed applications, cloud environments, CI/CD pipelines, and enterprise AI usage. The role focuses on secure-by-default practices and technical leadership in AI security and governance.

The candidate will build security guardrails into development and deployment, oversee security testing and AI inventories, and establish controls for AI runtimes and MCPs.

Qualifications

  • 5+ years of experience in application security, DevSecOps, or related field.
  • Experience leading security engineers or technical security teams.
  • Hands-on experience building security controls into CI/CD pipelines and workflows.
  • Proficiency with CI/CD platforms (Azure DevOps, GitHub Actions, GitLab, Jenkins).
  • Strong knowledge of API security (OAuth 2.0, OWASP) and security testing (SAST/DAST/SCA).
  • Experience securing containers and Kubernetes, IaC security, threat modeling, and SBOMs.
  • Practical AI security experience: AI governance, prompt-injection/breakout testing, AI-agent security.
  • Familiarity with NIST AI RMF and ISO/IEC 42001; CISSP/CSSLP/CISM is a plus.

Responsibilities

  • Lead the secure SDLC, incorporating NIST SSDF and ISO/IEC 27001 practices.
  • Define security requirements and perform security reviews for major releases.
  • Build and maintain secure CI/CD pipelines with guardrails.
  • Oversee security testing across SAST, DAST, SCA, secrets, API security.
  • Establish API security practices per OWASP standards.
  • Lead container, Kubernetes, and IaC security scanning.
  • Drive threat modeling and secure-code development practices.
  • Maintain SBOMs and provide secure development training.
  • Collaborate with cloud/infrastructure teams on cloud security guardrails.

Skills

Application security
DevSecOps
AI security
Threat modeling
Security governance

Education

Bachelor's degree in CS or related field

Tools

Azure DevOps
GitHub Actions
GitLab
Jenkins

Job description

Manager, Application & AI Security to lead the security of internally developed applications, cloud application environments, CI/CD pipelines, and enterprise AI usage.

This role will establish and operate secure-by-default practices across the software development lifecycle while serving as a central technical leader for AI security and governance. The ideal candidate brings strong hands-on experience in application security and DevSecOps, along with a practical understanding of emerging AI security risks.

You will build security guardrails into development and deployment processes, oversee application security testing, manage AI and model inventories, assess prompt-injection and jailbreak risks, and establish controls for MCPs and AI-agent runtimes.

This is a highly technical leadership role focused on building scalable security capabilities rather than simply reviewing or documenting controls.

What You'll DoApplication Security & DevSecOps
  • Lead the secure software development lifecycle, incorporating NIST SSDF and ISO/IEC 27001 practices.
  • Establish application security requirements and conduct security reviews for major releases and critical applications.
  • Build and maintain secure CI/CD "golden pipelines," embedding security guardrails directly into development and deployment workflows.
  • Implement pipeline and artifact integrity controls and monitor production pipelines for security risks.
  • Lead application security testing across SAST, DAST, software composition analysis (SCA), secrets detection, API security, and related capabilities.
  • Establish API security practices aligned with OWASP standards, including the OWASP Top 10 and API Security Top 10.
  • Oversee container, Kubernetes, and Infrastructure-as-Code security scanning.
  • Lead application threat modeling and secure-code development practices.
  • Establish and maintain SBOM generation for internally developed applications.
  • Develop and deliver secure development training for engineering teams.
  • Establish application- and PaaS-level cloud security guardrails in partnership with cloud and infrastructure teams.
  • Provide application and cloud security expertise during broader technology and security reviews.
  • Help establish security guardrails for customer-facing platforms, workflows, and contact-center technologies.
AI Security & Governance
  • Serve as the technical owner for enterprise AI security controls and AI usage governance.
  • Establish controls for LLM and AI assistant usage, including public and internally hosted models.
  • Identify and manage risks associated with shadow AI, unauthorized AI tools, and potential data leakage.
  • Maintain an enterprise AI/model inventory, AI bill of materials (AI-BOM), model registry, and approval workflows.
  • Assess AI applications and models for security risks before production use.
  • Conduct prompt-injection and jailbreak testing and lead LLM security red-teaming.
  • Apply relevant AI security practices, including the OWASP Top 10 for LLM Applications and MITRE ATLAS.
  • Establish security controls for MCPs (Model Context Protocol) and AI-agent runtimes, including per-tool authorization, runtime guardrails, and containment.
  • Partner with governance, risk, compliance, data security, identity, infrastructure, and other teams to ensure AI security controls are implemented effectively.
  • Translate emerging AI security risks into practical technical controls and repeatable processes.
Key Initiatives
  • Enterprise AI Governance & Shadow AI: Establish AI usage policies, discovery, risk assessment, and security controls.
  • Secure CI/CD Golden Pipelines: Build DevSecOps guardrails-as-code and automated blocking of critical security findings.
  • Cloud Application Security: Strengthen security controls across cloud tenants, SaaS, and PaaS environments.
  • AI Agent & MCP Security: Develop runtime security capabilities for AI agents and tool integrations, including authorization and containment.
What Success Looks Like

In this role, success will include:

  • AI tools are risk-assessed and governed before approved enterprise use.
  • Shadow AI is identified, assessed, and addressed within established service levels.
  • Production CI/CD pipelines are covered by security guardrails and monitoring.
  • Major application releases receive appropriate security reviews.
  • Critical application security findings are prevented from reaching production.
  • SAST, DAST, SCA, API security, and secrets scanning are automated across applicable development pipelines.
  • AI/model inventories and approval workflows are accurate, current, and operational.
  • Prompt-injection, jailbreak, and AI-agent security risks are regularly assessed.
  • Application and AI security practices are embedded into engineering workflows rather than operating as a separate manual review process.
What We're Looking For
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent professional experience.
  • 5+ years of experience in application security, DevSecOps, software security, or a closely related discipline.
  • Experience leading or mentoring security engineers or technical security teams.
  • Hands-on experience building security controls into CI/CD pipelines and development workflows.
  • Experience with CI/CD platforms such as Azure DevOps, GitHub Actions, GitLab, Jenkins, or similar technologies.
  • Strong experience with application security testing, including SAST, DAST, SCA/open-source security, secrets scanning, and API security.
  • Strong understanding of API security architecture and standards, including OAuth 2.0, OWASP, and related security practices.
  • Experience securing containers, Kubernetes environments, and Infrastructure-as-Code.
  • Experience with threat modeling and software supply-chain security, including SBOMs.
  • Practical experience with AI/LLM security, including AI usage governance, prompt-injection and jailbreak testing, red-teaming, or AI-agent security.
  • Understanding of AI security and governance frameworks such as NIST AI RMF and ISO/IEC 42001.
  • Familiarity with NIST and ISO/IEC 27001 security frameworks and practices.
  • Experience translating complex technical security issues into clear recommendations for technical and non-technical audiences.
  • Strong communication, collaboration, prioritization, and problem-solving skills.
Helpful Experience
  • Familiarity with AI productivity and development tools such as Claude, GitHub Copilot, or similar platforms.
  • Experience securing MCPs or AI-agent architectures.
  • Experience with AI/model registries, AI inventories, or AI-BOM initiatives.
  • Experience with security platforms and tools such as Checkmarx, Veracode, Snyk, or comparable solutions.
  • CISSP or another relevant security certification is preferred. Additional certifications such as CSSLP, CCSP, or CISM are a plus.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Engineer – Secure AI
Principal Engineer – Secure AI

Jobtailor • Brooklyn Park (MN)

On-site
USD 150,000 - 230,000
Senior AI DevSecOps Engineer
Senior AI DevSecOps Engineer

Jobtailor • Kansas

On-site
USD 120,000 - 180,000
Senior Security AI Engineer
Senior Security AI Engineer

Imperial PFS • Kansas City (MO)

On-site
USD 130,000 - 160,000
Senior Security AI Engineer
Senior Security AI Engineer

IPFS Corporation • Kansas City (MO)

On-site
USD 120,000 - 150,000
Senior Lead AI Security Engineer
Senior Lead AI Security Engineer

JPMorgan Chase & Co. • Columbus (OH)

On-site
USD 120,000 - 150,000
Principal AI Security Engineer
Principal AI Security Engineer

Capitolis • Atlanta (GA)

Hybrid
USD 120,000 - 150,000
Engineering, Cybersecurity, Application Security Engineer, Vice President
Engineering, Cybersecurity, Application Security Engineer, Vice President

TPG Careers Page • Fort Worth (TX)

On-site
USD 230,000 - 320,000
Chief Information Security Officer – CISO
Chief Information Security Officer – CISO

Jobtailor • Salt Lake City (UT)

On-site
USD 180,000 - 240,000
Senior AI Security Engineer
Senior AI Security Engineer

Fayette Chamber of Commerce • Atlanta (GA)

On-site
USD 140,000 - 190,000
Lead Application Security Engineer – AI
Lead Application Security Engineer – AI

Talentrix AI • Charlotte (NC)

On-site
USD 150,000 - 230,000