Senior AppSec Engineer — AI-Driven Security & CI/CD Leader

Jobot Consulting

New York (NY)

Hybrid

USD 125,000 - 146,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Jobot Consulting seeks an experienced Application Security Engineer to build and scale an enterprise AppSec program. You will own discovery, tooling, CI/CD integration, and collaboration with engineering leaders across business units.

This hybrid role requires three days on site and offers exposure to SAST, SCA, AI-assisted security workflows, and meaningful metrics for leadership. You’ll influence security practices while delivering secure software at velocity.

Qualifications

  • 7+ years of experience in application security, product security, or security engineering.
  • 3+ years of experience supporting complex environments with multiple independent business units, brands, product groups, or engineering organizations.
  • Hands-on experience implementing and operating modern AppSec tools such as Semgrep, Snyk, Checkmarx, Veracode, Apiiro, Ox Security, GitHub Advanced Security, or similar platforms.
  • Code-level proficiency in at least three commonly used programming languages such as Python, JavaScript/TypeScript, Java, C#, or Go, with the ability to review code and effectively validate security findings.
  • Strong scripting and automation skills, ideally in Python or a comparable language.
  • Experience building integrations using REST APIs and working within CI/CD environments such as GitHub Actions, GitLab CI, Jenkins, or Azure DevOps.
  • Demonstrated success influencing engineering teams and driving security adoption without direct authority.
  • Strong understanding of the OWASP Top 10, modern application attack patterns, software supply chain risks, and threat modeling methodologies such as STRIDE or PASTA.

Responsibilities

  • Lead application discovery and inventory efforts across multiple business units, including application ownership mapping, technology stack profiling, and risk tiering.
  • Implement, integrate, and operate modern application security tooling, including SAST, SCA, secrets scanning, container security, and Infrastructure-as-Code scanning.
  • Embed security tooling and controls directly into CI/CD pipelines to make security part of the development lifecycle rather than a separate process.
  • Design and implement AI-assisted triage workflows to help prioritize findings, reduce false positives, and prevent development teams from becoming overwhelmed by security alerts.
  • Establish and evolve secure SDLC standards, threat modeling practices, security requirements, and development gates.
  • Partner closely with engineering and development leaders to create practical AppSec playbooks that improve security while supporting speed of delivery.
  • Help shape the organization’s approach to AI within application security, including evaluating emerging capabilities such as AI-assisted code review, agentic security testing, automated security requirements, and remediation guidance.
  • Develop meaningful metrics and executive-level reporting that connect application security initiatives to measurable reductions in business and technology risk.

Skills

Python
JavaScript/TypeScript
Java
C#
Go
Automation scripting
CI/CD integrations
OWASP Top 10
Threat modeling

Tools

Semgrep
Snyk
Checkmarx
Veracode
Apiiro
Ox Security
GitHub Advanced Security

Job description

Jobot Consulting seeks an experienced Application Security Engineer to build and scale an enterprise AppSec program. You will own discovery, tooling, CI/CD integration, and collaboration with engineering leaders across business units.

This hybrid role requires three days on site and offers exposure to SAST, SCA, AI-assisted security workflows, and meaningful metrics for leadership. You’ll influence security practices while delivering secure software at velocity.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior AppSec Engineer - AI, CI/CD & Secure SDLC
Senior AppSec Engineer - AI, CI/CD & Secure SDLC

Jobot Consulting • Charlotte (NC)

Hybrid
USD 83,000 - 96,000
Senior AppSec Engineer — AI-Driven Security & DevSecOps
Senior AppSec Engineer — AI-Driven Security & DevSecOps

Australia-Employment • New York (NY)

On-site
USD 83,000 - 96,000
Senior AppSec Architect for AI-Driven DevSecOps (Remote)
Senior AppSec Architect for AI-Driven DevSecOps (Remote)

CVS Health • Arizona

Hybrid
USD 175,000 - 335,000
Health benefits
Bonus/equity program
Senior AI-Powered AppSec Engineer
Senior AI-Powered AppSec Engineer

Cvent • Virginia (MN)

Hybrid
USD 120,000 - 160,000
Hybrid work model
Competitive benefits package
Senior AppSec Engineer — Build Secure AI Platforms
Senior AppSec Engineer — Build Secure AI Platforms

Cogent Security • San Francisco (CA)

On-site
USD 100,000 - 300,000
Senior AppSec Architect—AI & DevSecOps Leader
Senior AppSec Architect—AI & DevSecOps Leader

CVS Health • New York (NY)

Hybrid
USD 175,000 - 335,000
Remote: Senior App Security Architect for AI & DevSecOps
Remote: Senior App Security Architect for AI & DevSecOps

CVS Health • Illinois

Hybrid
USD 175,000 - 335,000
Senior AppSec Engineer — AI-Driven SaaS Security Leader
Senior AppSec Engineer — AI-Driven SaaS Security Leader

Savvy Wealth • New York (NY)

On-site
USD 150,000 - 210,000
Equity
Unlimited PTO
Medical/Dental/Vision
+5
AI-Powered AppSec Architect for Secure Code & SDLC
AI-Powered AppSec Architect for Secure Code & SDLC

Information Technology Senior Management Forum • Tempe (AZ)

Hybrid
USD 120,000 - 204,000
Senior AppSec Architect - Remote & AI Security
Senior AppSec Architect - Remote & AI Security

Koitecc Solutions • Northern (KY)

Hybrid
USD 175,000 - 335,000
Medical, dental, vision
Retirement benefits
Paid time off
+1