Senior Application Security Specialist

Cybage Software

United States

On-site

USD 150,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Cybage Software seeks an accomplished security engineering lead to drive application security programs across cloud-native systems. You will guide engineering teams, shape security strategy, and implement scalable controls in fast-paced environments.

The role demands deep expertise in secure software design, threat modeling, and DevSecOps, with strong focus on AI/ML security and proactive tooling enhancements. 5+ years of related experience is expected.

Qualifications

  • 5 years of relevant experience in Application Security, AppSec engineering, Cloud Security, or Software Engineering
  • Deep expertise in application security, secure software design, and risk management, including frameworks such as OWASP ASVS, OWASP Top 10, and NIST 800‑53
  • Extensive experience conducting complex security assessments and building automated security controls for large engineering environments
  • Strong understanding of modern architectures (cloud-native, microservices, Kubernetes, containers, serverless) and DevSecOps processes
  • Advanced understanding of AI/ML security, including model vulnerability analysis, AI threat modeling, secure LLM integration patterns, and familiarity with NIST AI RMF or OWASP Top 10 for LLMs

Responsibilities

  • Design and implement security architectures and controls for large-scale, cloud-native applications.
  • Conduct in-depth risk assessments, including penetration testing and code reviews.
  • Collaborate with developers and DevOps teams to integrate security at all stages of the software development lifecycle (SDLC).
  • Drive security for AI-powered features by defining secure architectures, assessing AI/ML risks, and implementing advanced testing and controls for AI models, agents, and MCP servers.
  • Identify areas of improvements in security tools and practices, and remediate the identified gap by implementing innovative solutions.
  • Evaluate third‑party security tools and vendor‑provided controls for technical effectiveness, enterprise fit, and alignment with organization’s security architecture and standards.
  • Collaborate with vendors to provide actionable technical feedback, drive product improvements, and ensure controls are implemented and configured appropriately for Bloomberg Industry Group’s environment.
  • Build, improve, and scale security automation, integrating tooling across CI/CD pipelines and cloud platforms.
  • Provide guidance to junior engineers and cross-functional teams on security best practices.
  • Participate in incident response efforts and investigations into security incidents.
  • Stay ahead of the curve by keeping informed of industry trends and emerging threats, applying this knowledge to continually improve security

Skills

Application Security
Cloud Security
Security Architecture
DevSecOps
AI/ML Security
Risk Assessment

Job description

Founded in 1995, Cybage Software Pvt. Ltd., a technology consulting organization is a leader in the hi-tech and outsourced product engineering space. We are a valued partner to technology startups, mid-size companies and Fortune 500 corporations alike. Our solutions are focused on modern technologies, and are enabled by a scientific, data-driven system called the Excel Shore Model of Operational Excellence.

Job Summary:

This role will require you to lead security engineering initiatives, perform advanced risk assessments, and design scalable security controls across critical applications. You will serve as a subject matter expert (SME) in application, guiding engineering teams, influencing security strategy, and driving automation across the SDLC.This role requires deep technical expertise, leadership potential, and the ability to shape long‑term Application Security direction.

Key Responsibilities
  • Design and implement security architectures and controls for large-scale, cloud-native applications.
  • Conduct in-depth risk assessments, including penetration testing and code reviews.
  • Collaborate with developers and DevOps teams to integrate security at all stages of the software development lifecycle (SDLC).
  • Drive security for AI-powered features by defining secure architectures, assessing AI/ML risks, and implementing advanced testing and controls for AI models, agents, and MCP servers.
  • Identify areas of improvements in security tools and practices, and remediate the identified gap by implementing innovative solutions.
  • Evaluate third‑party security tools and vendor‑provided controls for technical effectiveness, enterprise fit, and alignment with organization’s security architecture and standards.
  • Collaborate with vendors to provide actionable technical feedback, drive product improvements, and ensure controls are implemented and configured appropriately for Bloomberg Industry Group’s environment.
  • Build, improve, and scale security automation, integrating tooling across CI/CD pipelines and cloud platforms.
  • Provide guidance to junior engineers and cross-functional teams on security best practices.
  • Participate in incident response efforts and investigations into security incidents.
  • Stay ahead of the curve by keeping informed of industry trends and emerging threats, applying this knowledge to continually improve security
Required Skills & Qualifications
  • 5 years of relevant experience in Application Security, AppSec engineering, Cloud Security, or Software Engineering
  • Deep expertise in application security, secure software design, and risk management, including frameworks such as OWASP ASVS, OWASP Top 10, and NIST 800‑53.
  • Extensive experience conducting complex security assessments and building automated security controls for large engineering environments.
  • Strong understanding of modern architectures (cloud-native, microservices, Kubernetes, containers, serverless) and DevSecOps processes.
  • Advanced understanding of AI/ML security, including model vulnerability analysis, AI threat modeling, secure LLM integration patterns, and familiarity with NIST AI RMF or OWASP Top 10 for LLMs
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Specialist
Senior Application Security Specialist

A-Line Staffing Solutions • Charlotte (NC)

Hybrid
USD 56,000 - 94,000
Senior Application Security Engineer
Senior Application Security Engineer

High Trail • Arlington (VA)

On-site
USD 140,000 - 190,000
Application Security Engineer
Application Security Engineer

RedStream Technology • Charlotte (NC)

On-site
USD 120,000 - 150,000
Application Security Engineer 3
Application Security Engineer 3

Bloomberg BNA • Arlington (TX)

On-site
USD 120,000 - 150,000
Security Engineer
Security Engineer

Wall Street Consulting Services LLC • New York (NY)

On-site
USD 120,000 - 180,000
Application Security Architect – AI / GenAI
Application Security Architect – AI / GenAI

Reuben Cooley Inc. • New York (NY)

On-site
USD 150,000 - 190,000
AI-Application Security Engineer
AI-Application Security Engineer

Stifel Financial Corp. • St. Louis (MO)

On-site
USD 90,000 - 120,000
Application Security Engineer I
Application Security Engineer I

Bloomberg Industry Group • Arlington (VA)

On-site
USD 90,000 - 110,000
Manager Application Security
Manager Application Security

Citizens • Woodbridge Township (NJ)

On-site
USD 133,000 - 190,000
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

Hybrid
USD 100,000 - 130,000