Senior AppSec Engineer: AI-Driven Secure SDLC Lead

Jobtailor

Colorado

On-site

USD 120,000 - 180,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking an experienced Application Security Engineer to lead security across the SDLC for multiple applications and cloud workloads. You will perform AI-assisted and traditional security assessments and drive remediation from discovery to closure, while collaborating with architects, developers, and DevOps teams.

You will apply OWASP Top 10, API Security Top 10, and secure coding principles, build security metrics and dashboards, and mentor teams to foster a security-first culture

Qualifications

  • 5–7 years of hands‑on application security / DevSecOps experience.
  • Strong working understanding of Secure SDLC, DevSecOps, Agile, and Scrum methodologies.
  • Experience with Burp Suite, GitHub Advanced Security, CodeQL, SAST, SCA, secret scanning, dependency analysis, and CI/CD security tooling.
  • Ability to read, analyze, test, and modify production application code in Java and Python.
  • Knowledge of OWASP Top 10, API Security Top 10, authentication/authorization controls, and secure coding principles.
  • Familiarity with cloud security, identity and access management, and modern application architectures.
  • Experience using AI‑assisted development and security tools safely and effectively.
  • Excellent communication, stakeholder management, presentation, and documentation skills.
  • Ability to work independently across multiple applications, teams, portfolios, and technology stacks.
  • Collaborative and influential, able to negotiate priorities and remove blockers across teams.
  • Coaching others and championing a security‑first culture.

Responsibilities

  • Define, implement, and improve security processes across the SDLC.
  • Perform AI-assisted and traditional security assessments of applications, APIs, cloud workloads, repositories, and supporting infrastructure.
  • Manage source code analysis, secret scanning, dependency analysis, and infrastructure review coverage.
  • Triage findings by exploitability, business impact, and severity.
  • Drive remediation from discovery through verified closure, including backlog management, ownership assignment, retesting, and evidence collection.
  • Identify and reduce security debt, dependency vulnerabilities, outdated libraries, and software supply chain risk.
  • Build security metrics, coverage reporting, and executive dashboards.
  • Leverage AI tools for security analysis, threat modeling, code review, and documentation under governance controls.
  • Perform manual validation and security testing using Burp Suite, browser developer tools, API testing platforms, and secure code review methodologies.
  • Apply OWASP Top 10, API Security Top 10, authentication/authorization controls, and secure coding principles.
  • Support remediation through code fixes, configuration changes, and compensating controls.
  • Partner with architects, developers, DevOps engineers, product owners, and business stakeholders to communicate risk, negotiate priorities, and remove blockers.
  • Maintain Agile work items and participate in Scrum ceremonies.
  • Stay current on emerging threats and AI-related security risks.
  • Coach and mentor application teams to build a security-first culture.

Skills

Secure SDLC
DevSecOps
Burp Suite
CodeQL
GitHub Security
SAST
SCA
Secret Scanning
Dependency Analysis
CI/CD Security
Java
Python
Threat Modeling
OWASP Top 10
API Security
Cloud Security
IAM
AI Tools

Education

Bachelor's Degree in Computer Science
Master's Degree in Cybersecurity
Information Systems Certification

Tools

Burp Suite
GitHub Advanced Security
CodeQL
AI-Assisted Dev Tools
API Testing Platforms

Job description

Jobtailor is seeking an experienced Application Security Engineer to lead security across the SDLC for multiple applications and cloud workloads. You will perform AI-assisted and traditional security assessments and drive remediation from discovery to closure, while collaborating with architects, developers, and DevOps teams.

You will apply OWASP Top 10, API Security Top 10, and secure coding principles, build security metrics and dashboards, and mentor teams to foster a security-first culture

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior App Security Engineer: Secure SDLC & AI Risk Lead
Senior App Security Engineer: Secure SDLC & AI Risk Lead

Clear Capital • Reno (NV)

On-site
USD 111,000 - 145,000
Profit-sharing bonus
401(k) with employer match
Comprehensive health insurance
Senior AppSec Engineer: AI-Driven Secure Coding & CI/CD
Senior AppSec Engineer: AI-Driven Secure Coding & CI/CD

AgileEngine • United States

Hybrid
USD 120,000 - 180,000
Flextime
Professional growth
Competitive compensation
+2
Senior AppSec Engineer: Secure SDLC & AI APIs
Senior AppSec Engineer: Secure SDLC & AI APIs

myhrhome • Irving (TX)

On-site
USD 140,000 - 190,000
Senior AI-Driven Application Security Architect
Senior AI-Driven Application Security Architect

Cvent • Tysons (VA)

Hybrid
USD 120,000 - 160,000
Bonus
Competitive benefits
Senior App Security Engineer: AI & Cloud Lead
Senior App Security Engineer: AI & Cloud Lead

Nclusion • Palo Alto (CA)

Hybrid
USD 200,000 - 260,000
401k match
Medical Insurance
Dental Insurance
+4
Senior Application Security Engineer — Secure SDLC & AI
Senior Application Security Engineer — Secure SDLC & AI

Clear Capital | CubiCasa • Reno (NV)

On-site
USD 111,000 - 145,000
Medical, dental, and vision insurance
401(k) with employer match
Paid time off and holidays
+3
Application Security Engineer: DevSecOps & AI Security
Application Security Engineer: DevSecOps & AI Security

Worky • Dallas (TX)

On-site
USD 120,000 - 180,000
Senior AppSec Engineer — AI-Driven SaaS Security Leader
Senior AppSec Engineer — AI-Driven SaaS Security Leader

Savvy Wealth • New York (NY)

On-site
USD 150,000 - 210,000
Equity
Unlimited PTO
Medical/Dental/Vision
+5
Senior AppSec Engineer: Secure SDLC & CI/CD Lead
Senior AppSec Engineer: Secure SDLC & CI/CD Lead

TripleLift • London (KY)

On-site
USD 140,000 - 180,000
Senior App Security Engineer — AI-Driven SDLC Defender
Senior App Security Engineer — AI-Driven SDLC Defender

Sands • Dallas (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000
Remote work as needed
Career development