Senior Lead Application Security Engineer (AppSec SME)
Location: Charlotte, NC
Work Model: Hybrid
Duration: 12 Months
Job Overview
We are seeking a Senior Lead Application Security Engineer / AppSec SME to define and execute Application Security strategy for a large-scale Data Center Modernization and Simplification (DCMS) program.
This is a senior-level role for an experienced Application Security professional who can combine enterprise AppSec strategy, SSDLC expertise, DevSecOps, security automation, and emerging AI/GenAI security capabilities.
The ideal candidate will have strong technical depth as well as the ability to influence application teams, engineering leaders, security stakeholders, and senior leadership without direct authority.
Key Responsibilities
Application Security Strategy
- Define and lead Application Security strategy for applications within the DCMS program.
- Develop and implement tier-based AppSec control models.
- Assess existing security control coverage and establish application-level baselines.
- Identify AppSec control gaps and drive remediation and onboarding plans.
- Partner with Application Security Champions and engineering teams to implement required security controls.
- Ensure alignment with enterprise SSDLC requirements and defect remediation standards.
- Provide strategic guidance to leadership on AppSec priorities, risks, and investments.
AI & GenAI Security
- Identify and implement AI/GenAI use cases that improve Application Security efficiency and coverage.
- Design automated threat modeling using application code, infrastructure-as-code, and application metadata.
- Develop adversarial testing capabilities for GenAI and LLM-based applications.
- Evaluate and defend against risks such as prompt injection, model abuse, insecure prompts, tool misuse, and secrets exposure.
- Support AI model scanning, integrity validation, and secure model onboarding.
- Develop AI-driven security automation and decisioning capabilities.
- Modernize Application Security controls through automation, rationalization, and platform integration.
- Develop proofs of concept and pilot emerging security technologies.
- Scale successful security solutions into production environments.
- Improve developer experience by simplifying AppSec processes while maintaining strong security and risk controls.
- Integrate security capabilities into DevSecOps and CI/CD pipelines.
Leadership & Influence
- Act as a senior Application Security subject matter expert.
- Influence cross-functional engineering and security teams without direct authority.
- Partner with application owners, developers, security champions, and senior leadership.
- Research emerging Application Security threats and technologies.
- Translate emerging security risks into actionable enterprise security strategies.
Required Qualifications
- 7+ years of Application Security or Information Security Engineering experience at enterprise scale.
- Strong expertise in Secure Software Development Lifecycle (SSDLC) practices.
- Hands-on expertise with:
- Threat Modeling
- Secure Design
- SAST
- SCA
- DAST
- Penetration Testing
- Demonstrated ability to define and execute Application Security strategy.
- Strong experience providing technical leadership and influencing cross-functional teams.
- Strong understanding of DevSecOps and CI/CD security integration.
- Experience working in complex enterprise environments.
Preferred Qualifications
- Experience securing Generative AI and LLM-based applications.
- Experience with prompt injection and adversarial AI testing.
- Experience developing AI-driven security automation or decisioning solutions.
- Experience with automated threat modeling.Experience with AI model scanning, validation, and secure model onboarding.
- Experience working within financial services or other highly regulated environments.
- Relevant certifications such as CISSP, CISM, CSSP, or equivalent.
Ideal Candidate Profile
The ideal candidate is a senior-level Application Security strategist and technical leader, rather than someone focused solely on vulnerability scanning or security operations.
Candidates with a combination of the following will be highly valued:
Enterprise AppSec + SSDLC + Threat Modeling + DevSecOps + Security Automation + GenAI/LLM Security + Strategic Leadership