Principal Application & AI Security Engineer

DNV Germany Holding GmbH

Houston, Northern (TX, KY)

Hybrid

USD 150,000 - 230,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

DNV Energy Systems' Platform Services in Houston is seeking a Principal Application & AI Security Engineer. You will lead security architecture across software, APIs, cloud platforms, and AI-enabled systems, integrating controls into the delivery pipeline and aligning with enterprise standards.

This role blends hands-on coding with design leadership in a hybrid work model based in Houston or Oakland. As a senior technical leader, you will mentor engineers, run authorized testing, and drive

Qualifications

  • Experience securing architecture across apps, APIs, cloud, and AI agents.
  • Ability to design reusable security controls and run authorized testing.
  • Proven track record eliminating recurring vulnerability classes.

Responsibilities

  • Lead architecture and security patterns for multi-tenant, cloud-native systems.
  • Automate risk-based controls within delivery workflows.
  • Perform authorized security testing of applications, APIs, and AI components.
  • Mentor engineers and coordinate incident response and remediation.

Skills

Secure architecture
Threat modeling
Security testing
AI security

Tools

SCA
SAST
DAST
Kubernetes
CI/CD Security

Job description

DNV Energy Systems' Platform Services is seeking Principal Application & AI Security Engineer.

DNV Energy Systems' Platform Services runs the software products and digital platforms our customers depend on, including systems with significant operational importance in enterprise and energy environments. As we evolve toward agentic AI architectures, security must move from after-the-fact review into architecture, development workflows, and runtime operations - engineered into the platform and the delivery pipeline, with evidence that controls are implemented and operating effectively.

This is a builder's role for a senior technical leader who can read and improve code, design reusable controls, model complex threats, conduct authorized security testing, and work directly with engineering teams to ship durable fixes. The goal is not simply to identify vulnerabilities. It is to eliminate recurring vulnerability classes, reduce exposure, and make the secure path the easiest path.

This role is based at our DNV office in Houston, TX or Oakland, CA, presenting a dynamic hybrid schedule where employees will typically spend three (3) days per week working from either a DNV office or client location/site. Further details regarding role‑specific requirements will be shared during the interview process.

What you’ll do

You’ll be a technical leader within our organization focused on three core priorities:

  • Securing application and AI architecture. Design and implement secure patterns across applications, APIs, cloud platforms, and AI‑agent systems, with particular emphasis on identity, authorization, tenant isolation, data access, tool use, and runtime guardrails.
  • Automating security in engineering workflows. Build and tune risk‑based controls so material issues are caught and acted on inside delivery workflows, rather than at manual checkpoints.
  • Eliminating recurring vulnerabilities. Find root causes, fix weaknesses at the architecture or platform‑pattern level, and make the same class of issue structurally difficult to reintroduce

The responsibilities below describe how this work shows up day‑to‑day across architecture, delivery, AI systems, remediation, and engineering.

Build security into delivery and platform engineering
  • Design and implement scalable controls for software and AI supply chains, including dependency integrity, SCA, SAST, DAST, build provenance, artifact security, secrets protection, container and infrastructure‑as‑code assurance, and software or AI bills of materials where appropriate.
  • Implement platform‑level controls: policy as code, authorization enforcement, data‑access guardrails, secure defaults, and reusable reference implementations.
  • Design AI‑assisted security‑testing environments, automated attack scenarios, and security‑regression suites that prevent resolved issues from silently returning.
  • Implement risk‑based quality gates with documented exception paths, accountable ownership, and service‑level expectations, so material issues block release.
Find, prove, and fix material weaknesses
  • Review source code, APIs, and application designs for weaknesses in authentication, authorization, session management, input handling, data‑access scope, and multi‑tenant isolation, including row‑and‑field‑level boundaries.
  • Conduct authorized application, API, and AI security testing, including targeted manual testing of business logic and trust boundaries that automated tools cannot adequately validate.
  • Work alongside engineers to remediate root causes, validate fixes, create regression tests, and put preventive controls or secure patterns in place.
  • Establish vulnerability triage and remediation practices, including exploitability and exposure analysis, accountable ownership, target dates, exception handling, retesting, closure evidence, and escalation of overdue material risk.
Secure AI agents and AI‑assisted development
  • Establish agent identities and least‑privilege permissions, with clear separation of read, write, execute, approval, and administrative capabilities.
  • Govern model, tool, skill, connector, plug‑in, memory, and data access, including tenant isolation and boundaries between trusted and untrusted context.
  • Validate untrusted inputs and tool outputs, and design defenses against direct and indirect prompt injection, goal manipulation, tool misuse, privilege escalation, sensitive‑data exposure, memory poisoning, unsafe delegation, and cascading failures.
  • Assess multi‑agent workflows to implement approval requirements for consequential or irreversible actions, runtime policy enforcement, rate and resource limits, and tamper‑resistant auditability.
Shape secure architecture at scale
  • Lead high‑risk threat modeling and architecture reviews for complex, multi‑tenant, cloud‑native, event‑driven, and AI‑enabled systems.
  • Develop and demonstrate reusable secure patterns for microservices, APIs, event‑driven systems, containers, Kubernetes, cloud services, and agentic AI applications.
  • Contribute to platform roadmaps and engineering practice so controls are implemented at the most effective layer and reused across products.
  • Provide evidence from implementation, testing, and incidents to help Information Security team continuously improve enterprise standards and assurance expectations.
Support engineering teams and incidents
  • Partner across distributed engineering hubs, including North America and Chennai, to drive adoption of secure patterns and automation at scale.
  • Translate findings into prioritized, actionable engineering work reflecting technical severity, exploitability, customer impact, and delivery context.
  • Mentor senior engineers and technical leaders in secure design, development, threat modeling, and remediation.
  • Serve as the application and AI security technical lead during relevant incidents – coordinating with designated incident lead and Information Security team to support investigation, containment, eradication, recovery, remediation validation, and lessons learned.
  • Represent application and AI security in significant technical, executive, customer, audit, and assurance discussions when needed.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Application & AI Security Engineer
Principal Application & AI Security Engineer

DNV GL, USA • Houston (TX)

Hybrid
USD 140,000 - 190,000
Principal AI & App Security Architect
Principal AI & App Security Architect

DNV Germany Holding GmbH • Houston (TX), Northern (KY)

Hybrid
USD 150,000 - 230,000
Principal AI Security Architect for Secure Platforms
Principal AI Security Architect for Secure Platforms

DNV GL, USA • Houston (TX)

Hybrid
USD 140,000 - 190,000
Senior Security Engineer – AI & Application Security
Senior Security Engineer – AI & Application Security

Identify Security • United States

On-site
USD 140,000 - 210,000
AI-Application Security Engineer
AI-Application Security Engineer

Stifel Financial Corp. • St. Louis (MO)

On-site
USD 90,000 - 120,000
Senior Security AI Engineer
Senior Security AI Engineer

Imperial Funding Corporation • Kansas City (MO)

On-site
USD 130,000 - 190,000
Medical, prescription, dental benefits
Wellness program and EAP
401(k) with company match
+1
Engineering Manager, Application Security
Engineering Manager, Application Security

Qualia • Austin (TX)

On-site
USD 180,000 - 240,000
Medical, Dental & Vision health plans
Competitive salary & equity
Flexible schedules
+3
Senior Security AI Engineer
Senior Security AI Engineer

Imperial PFS • Kansas City (MO)

On-site
USD 130,000 - 160,000
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent • Tysons (VA)

Hybrid
USD 120,000 - 160,000
Bonus
Competitive benefits
Principal Application Security Engineer
Principal Application Security Engineer

Motion Recruitment • Charlotte (NC)

Hybrid
USD 140,000 - 190,000