Senior Lead Application Security Engineer

Motion Recruitment

Charlotte (NC)

Hybrid

USD 131,000 - 138,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Motion Recruitment seeks a Senior Lead Application Security Engineer to define and execute the SSDLC-aligned AppSec strategy for the DCMS program, shaping enterprise-scale security while driving automated, AI-enabled protections. The role involves cross-functional influence and delivering scalable security outcomes in a hybrid Charlotte, NC setting.

You will lead threat modeling, secure design, SAST/DAST/SCA, and penetration testing, with a focus on GenAI/LLM security, CI/CD integration, and

Qualifications

  • 7+ years of Application Security or Information Security Engineering experience at enterprise scale.
  • Expertise in SSDLC controls (threat modeling, secure design, SAST, SCA, DAST, pen testing).
  • Experience securing GenAI/LLM apps, adversarial testing and prompt-injection defenses.

Responsibilities

  • Define and lead the AppSec strategy for DCMS; tier-based control models.
  • Evaluate control coverage and baselines by application tier.
  • Identify gaps and drive remediation and onboarding with teams.
  • Partner with AppSec Champions and engineers to ensure adoption of controls.
  • Align with SDLC requirements and defect remediation expectations.
  • Deliver AI and GenAI use cases to reduce manual AppSec effort.
  • Design automated threat modeling using code and metadata.
  • Develop adversarial testing for GenAI/LLM apps; tool integrations.
  • Lead AI model scanning, integrity validation, and secure onboarding of models.
  • Define protections for AI-specific risks including prompt construction and secrets exposure.
  • Drive modernization of AppSec controls through automation.
  • Build proofs-of-concept and scale successful solutions to production.
  • Influence simplification of AppSec processes for better developer experience.
  • Provide strategic guidance on AppSec priorities and investments.
  • Influence cross-functional teams without direct authority.
  • Research emerging threats and translate insights into strategy.

Skills

Threat modeling
SAST
DAST
SCA
Penetration testing
GenAI security
LLM security
DevSecOps
CI/CD security
Regulatory compliance
CISSP
CSSP
CISM

Education

Security certifications: CISSP, CSSP, CISM

Job description

We are seeking a Senior Lead Application Security Engineer to define and execute Application Security strategy for the Data Center Modernization and Simplification (DCMS) program and to drive innovation through AI-enabled Application Security capabilities. This role is responsible for shaping enterprise-scale AppSec strategy, influencing cross-functional stakeholders, and delivering scalable, automated security outcomes aligned to the Secure Software Development Lifecycle (SSDLC).

Hybrid Roles in Charlotte, NC – 3 days Onsite/2 days Remote

Duration: 12+ months with possibility of longer-term extensions

Pay Rate: $95/hr - $100/hr on W2

No C2C, H1B, 1099, OPT or 3rd PARTY RESUMES

Required: Experience and Skills

7+ years of Application Security or Information Security Engineering experience at enterprise scale.

Deep expertise in SSDLC controls including threat modeling, secure design, SAST, SCA, DAST, and penetration testing.

Proven ability to define security strategy and deliver outcomes through influence and technical leadership.

Experience securing GenAI and LLM-based applications, including adversarial testing and prompt-injection defenses.

Experience designing AI-driven security automation or decisioning capabilities.

Strong understanding of DevSecOps and CI/CD security integration.

Experience working in highly regulated environments such as financial services.

Relevant security certifications (CISSP, CSSP, CISM, or equivalent).

Key Responsibilities

  • Define and lead the Application Security strategy for DCMS in-scope applications using tier-based control models.
  • Evaluate existing AppSec control coverage and establish baseline mappings by application tier.
  • Identify control gaps and drive remediation and onboarding plans with application teams and stakeholders.
  • Partner with Application Security Champions and engineering teams to ensure consistent adoption of required AppSec controls.
  • Ensure alignment with enterprise SDLC requirements and defect remediation expectations.
  • Identify and deliver AI and GenAI use cases that reduce manual AppSec effort and improve security coverage.
  • Design and implement automated threat modeling using code, infrastructure-as-code, and application metadata.
  • Develop adversarial testing capabilities for GenAI and LLM-based applications, including prompt injection and abuse scenarios.
  • Lead initiatives for AI model scanning, integrity validation, and secure onboarding of models.
  • Define protections for AI-specific risks including insecure prompt construction, tool misuse, and secrets exposure.
  • Drive modernization of AppSec controls through automation, rationalization, and platform integration.
  • Build proofs-of-concept and pilot new security capabilities, scaling successful solutions into production.
  • Influence simplification of AppSec processes to improve developer experience while maintaining strong risk controls.
  • Provide strategic guidance to senior leadership on Application Security priorities, risks, and investment decisions.
  • Influence cross-functional teams without direct authority to achieve enterprise security outcomes.
  • Research emerging threats and technologies and translate insights into actionable AppSec strategy.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Lead Application Security Engineer (AppSec SME)
Senior Lead Application Security Engineer (AppSec SME)

Motion Recruitment • Charlotte (NC)

Hybrid
USD 140,000 - 190,000
Principal Application Security Engineer
Principal Application Security Engineer

Motion Recruitment • Charlotte (NC)

Hybrid
USD 140,000 - 190,000
Lead Application Security Engineer with AI
Lead Application Security Engineer with AI

Brilliant Infotech Inc. • Charlotte (NC)

Hybrid
USD 140,000 - 210,000
Hybrid Senior Lead AppSec Architect for GenAI & AI Security
Hybrid Senior Lead AppSec Architect for GenAI & AI Security

Motion Recruitment • Charlotte (NC)

Hybrid
USD 131,000 - 138,000
Senior AppSec Strategist: GenAI, SSDLC & DevSecOps
Senior AppSec Strategist: GenAI, SSDLC & DevSecOps

Motion Recruitment • Charlotte (NC)

Hybrid
USD 140,000 - 190,000
Senior AI-Driven AppSec Architect
Senior AI-Driven AppSec Architect

Motion Recruitment • Charlotte (NC)

Hybrid
USD 140,000 - 190,000
Application Security Engineer
Application Security Engineer

IPolarity • Hanover Township (NJ)

On-site
USD 68,000 - 97,000
Application Security Engineer
Application Security Engineer

IPolarity LLC • Whippany (NJ)

On-site
USD 146,136,000 - 197,713,000
Senior Cybersecurity/Application Security Engineer - 846
Senior Cybersecurity/Application Security Engineer - 846

DSM-H Consulting • Chicago (IL)

On-site
USD 120,000 - 180,000
Senior AI Security Engineer – Applications (Hybrid)
Senior AI Security Engineer – Applications (Hybrid)

Brilliant Infotech Inc. • Charlotte (NC)

Hybrid
USD 140,000 - 210,000