Senior Information Security Engineer – AI, Application Security

Jobtailor

Washington (District of Columbia)

On-site

USD 150,000 - 210,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Jobtailor in Washington, DC seeks a senior security professional to lead application and AI security efforts. You will own security assessments for AI platforms, apply OWASP Top 10 for LLMs, and design testing for prompt injection and data leakage, ensuring cross-client isolation and governance.

You will embed security into development pipelines, assess API security controls, and communicate risk with leadership.

Qualifications

  • Bachelor’s degree or equivalent years of experience in computing or cybersecurity.
  • 8+ years in application security or related fields with 3+ years in app security.
  • Strong knowledge of OWASP Top 10 and secure coding principles.

Responsibilities

  • Own security assessments of AI platforms and AI-enabled tools.
  • Apply OWASP Top 10 for LLMs and AI governance standards.
  • Design and execute testing for prompt injection and data leakage.
  • Build and report AI security posture metrics in business terms.
  • Assess API security controls, authentication, and gateway policies.
  • Embed security into development pipelines in cloud/hybrid environments.

Skills

OWASP Top 10
Secure Coding Principles
Application Security Testing
Threat Modeling
Secure Code Review
Static Testing
Dynamic Testing
API Security Assessment
Cloud / Hybrid Environments
Communication Skills

Education

Bachelor’s degree in computer science, cybersecurity, or related field

Tools

Azure
SaaS Applications
On-Premises Applications
Automation Tooling
Development Pipelines

Job description

  • Own security assessments of the firm’s AI platforms and AI-enabled tools, including Harvey and Microsoft Copilot
  • Apply the OWASP Top 10 for LLMs and the firm’s AI governance framework as evaluation standards
  • Design and execute testing for prompt injection, jailbreaking, data leakage, and cross-client isolation in retrieval-augmented and agentic AI platforms
  • Produce evidence that one client’s data cannot influence another client’s outputs in support of information barrier and privilege obligations
  • Evaluate and harden API and integration security across AI platforms, automation tooling, and connected data systems
  • Assess authentication, authorization, gateway policies, rate limiting, and anomaly detection for misuse or exfiltration
  • Conduct ongoing security and configuration assessments of Azure, SaaS, and on-premises applications and services
  • Identify misconfigurations, design weaknesses, and development errors
  • Serve as the embedded security partner to the Catalyst Studio and AI and Automation teams
  • Participate in design reviews and ensure security requirements are defined before development begins
  • Build and report application and AI security posture metrics in business terms relevant to legal operations
  • Perform special projects and other assigned duties
Requirements
  • Bachelor’s degree in computer science, cybersecurity, or a related field, or equivalent years of experience
  • Eight years or more of relevant experience in application security, secure software development, or information security, including at least three years focused on application security
  • Strong understanding of the OWASP Top 10 and secure coding principles
  • Familiarity with the OWASP Top 10 for LLMs
  • Hands-on experience with application security testing, including threat modeling, secure code review, and static and dynamic testing
  • Experience managing findings through remediation
  • Working knowledge of the software development lifecycle
  • Experience embedding security into development and deployment pipelines in cloud or hybrid environments
  • Proficiency in at least one programming or scripting language sufficient to review code and build testing tooling
  • Experience designing or assessing API security controls, including authentication, authorization, and gateway policies
  • Working knowledge of AI and LLM security risks, including prompt injection, data leakage, and cross-tenant isolation in retrieval-augmented architectures
  • Experience assessing third-party and SaaS vendor security architectures
  • Detailed technical knowledge of application, operating system, and network security fundamentals
  • Thorough understanding of current security principles, techniques, and protocols
  • Ability to effectively communicate information security issues, risks, and recommendations to technical and non-technical peers and management, including through well-written reports
  • Ability to problem-solve
  • Excellent interpersonal, verbal and written communication skills, including communication in a virtual environment
  • Ability to work calmly and effectively in a high-pressure, deadline-oriented environment
  • Demonstrated ability to use good judgment and take initiative
  • Willingness to be flexible with time and adjust to a changing work environment
  • Ability to build and maintain positive internal and external relationships while maintaining a client service orientation
  • Ability to use sound judgment and discretion with highly confidential information
  • Ability to take direction and accept supervision
  • Demonstrated ability to work independently, organize and prioritize work accurately, be detail-oriented, understand urgency, and use good judgment
  • Ability to work effectively in a team-oriented collaborative environment
Core Competencies

Demonstrates expertise in application security, including OWASP Top 10 and secure coding principles, with a strong focus on AI and LLM security risks. Proficient in embedding security into development pipelines and assessing API security controls while effectively communicating security issues to diverse audiences.

Highest-signal resume keywords
  • Application Security
  • OWASP Top 10
  • AI Security Risks
  • API Security Controls
  • Security Testing
Hard Skills
  • Application Security Testing
  • Secure Software Development
  • Threat Modeling
  • Secure Code Review
  • Static Testing
  • Dynamic Testing
  • Programming Language Proficiency
  • API Security Assessment
  • Security Principles
  • Configuration Assessment
Soft Skills
  • Effective Communication
  • Problem-Solving
  • Interpersonal Skills
  • Team Collaboration
  • Judgment and Initiative
Industry Keywords
  • Information Security
  • Data Leakage
  • Cross-Tenant Isolation
  • Client Service Orientation
  • High-Pressure Environment
Tools & Technologies
  • Azure
  • SaaS Applications
  • On-Premises Applications
  • Automation Tooling
  • Development Pipelines
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Engineer – AI Security
Principal Engineer – AI Security

Jobtailor • Brooklyn Park (MN)

On-site
USD 180,000 - 260,000
Stock options
Lead Engineer – AI Security
Lead Engineer – AI Security

Jobtailor • Brooklyn Park (MN)

On-site
USD 120,000 - 150,000
Principal, AI Security
Principal, AI Security

Jobtailor • Illinois

On-site
USD 180,000 - 260,000
Senior Manager – Product Cybersecurity
Senior Manager – Product Cybersecurity

Jobtailor • Chicago (IL)

On-site
USD 150,000 - 230,000
Senior AI Security Engineer
Senior AI Security Engineer

Jobtailor • Town of Florida (NY)

On-site
USD 120,000 - 180,000
Info Security Architect – AI
Info Security Architect – AI

Jobtailor • Webster (MA)

On-site
USD 140,000 - 190,000
Lead Platform Security Architect – AI, Data
Lead Platform Security Architect – AI, Data

Jobtailor • California (MO)

On-site
USD 140,000 - 200,000
Senior Staff Product Security Engineer – AI
Senior Staff Product Security Engineer – AI

Jobtailor • Illinois

On-site
USD 140,000 - 220,000
Principal AI Security Engineer
Principal AI Security Engineer

Capitolis • Atlanta (GA)

Hybrid
USD 120,000 - 150,000
Senior AI Engineer, Security Infrastructure
Senior AI Engineer, Security Infrastructure

Jobtailor • Pennsylvania

On-site
USD 180,000 - 260,000