Outstanding long-term contract opportunity! A well-known Financial Services Company is looking for a Principal Application Security Engineer in Charlotte, NC (Hybrid).
Work with the brightest minds at one of the largest financial institutions in the world. This is a long-term contract opportunity that includes a competitive benefit package! Our client has been around for over 150 years and is continuously innovating in today's digital age. If you want to work for a company that is not only a household name, but also truly cares about satisfying customers' financial needs and helping people succeed financially.
Contract Duration: 12 Months + extensions, desire to convert
We are seeking a Senior Lead (P5) Application Security Engineer to define and execute Application Security strategy for the Data Center Modernization and Simplification (DCMS) program and to drive innovation through AI-enabled Application Security capabilities. This role is responsible for shaping enterprise-scale AppSec strategy, influencing cross-functional stakeholders, and delivering scalable, automated security outcomes aligned to the Secure Software Development Lifecycle (SSDLC).
Required Skills & Experience
- 7+ years of Engineering experience, or equivalent demonstrated through one or a combination of the following: work or consulting experience, training, military experience, education.
- 7+ years of Application Security or Information Security Engineering experience at enterprise scale.
- Deep expertise in SSDLC controls including threat modeling, secure design, SAST, SCA, DAST, and penetration testing.
- Proven ability to define security strategy and deliver outcomes through influence and technical leadership.
- Experience securing GenAI and LLM-based applications, including adversarial testing and prompt-injection defenses.
- Experience designing AI-driven security automation or decisioning capabilities.
- Strong understanding of DevSecOps and CI/CD security integration.
- Experience working in highly regulated environments such as financial services.
- Relevant security certifications (CISSP, CSSP, CISM, or equivalent).
What You Will Be Doing
- Consult as an expert to develop or influence initiatives and resources for highly complex business and technical needs across Engineering.
- Consult on the strategy and resolution of highly complex and unique challenges requiring in-depth evaluation across multiple areas, delivering solutions that are long-term, large-scale and require vision, creativity, innovation, and advanced analytical and inductive thinking.
- Provide expertise to client senior leadership on innovative Engineering business solutions.
- Strategically engage with client personnel.
DCMS Application Security Strategy
- Define and lead the Application Security strategy for DCMS in-scope applications using tier-based control models.
- Evaluate existing AppSec control coverage and establish baseline mappings by application tier.
- Identify control gaps and drive remediation and onboarding plans with application teams and stakeholders.
- Partner with Application Security Champions and engineering teams to ensure consistent adoption of required AppSec controls.
- Ensure alignment with enterprise SDLC requirements and defect remediation expectations.
AI Innovation for Application Security
- Identify and deliver AI and GenAI use cases that reduce manual AppSec effort and improve security coverage.
- Design and implement automated threat modeling using code, infrastructure-as-code, and application metadata.
- Develop adversarial testing capabilities for GenAI and LLM-based applications, including prompt injection and abuse scenarios.
- Lead initiatives for AI model scanning, integrity validation, and secure onboarding of models.
- Define protections for AI-specific risks including insecure prompt construction, tool misuse, and secrets exposure.
AppSec Modernization and Automation
- Drive modernization of AppSec controls through automation, rationalization, and platform integration.
- Build proofs-of-concept and pilot new security capabilities, scaling successful solutions into production.
- Influence simplification of AppSec processes to improve developer experience while maintaining strong risk controls.
Senior Lead Influence and Leadership
- Provide strategic guidance to senior leadership on Application Security priorities, risks, and investment decisions.
- Influence cross-functional teams without direct authority to achieve enterprise security outcomes.
- Research emerging threats and technologies and translate insights into actionable AppSec strategy.