Senior Security Engineer – AI & Application Security

Identify Security

United States

On-site

USD 140,000 - 210,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Identify Security in the United States is seeking a senior security engineer to help secure AI-enabled platforms where application security, identity, APIs, cloud, and autonomous systems intersect. This is not a traditional AppSec role and focuses on capabilities to govern AI actions and permissions.

You will collaborate across security, engineering, product, identity, and AI teams to design practical controls for AI agents, runtime authorization, and fine-grained access policies.

Qualifications

  • 8+ years of experience across security engineering, application security, product security, platform security, or similar disciplines.
  • Strong hands-on web application and API security experience.
  • AppSec and/or DevSecOps engineering experience.
  • Deep understanding of OAuth 2.x, OIDC, token-based authorization, delegated access, and service identities.
  • Experience designing fine-grained authorization and least-privilege models.
  • Strong knowledge of APIs and distributed application architectures.
  • Experience with cloud-native environments and service-to-service security.
  • Experience with API gateways, WAFs, edge security, or similar controls.
  • Experience securing complex, consumer-facing or high-availability applications.
  • Exposure to AI-enabled, automation-heavy, or autonomous systems.
  • Ability to conceive deterministic security controls for non-deterministic AI behavior.

Responsibilities

  • Designing security controls for AI agents and autonomous workflows.
  • Establishing runtime authorization and least-privilege boundaries.
  • Securing non-human identities, workloads, service accounts, and AI agents.
  • Designing delegated authorization using OAuth, OIDC, tokens, and short-lived credentials.
  • Maintaining attribution across users, agents, services, APIs, and actions.
  • Reviewing complex application and distributed-system architectures.
  • Securing high-volume consumer-facing digital and transaction environments.
  • Building secure patterns for APIs and backend services.
  • Applying strong AppSec and DevSecOps principles.
  • Working with API gateways, WAFs, edge controls, and bot mitigation.
  • Securing cloud-native, containerized, and service-to-service environments.
  • Defining policy enforcement points before sensitive or high-impact actions occur.
  • Implementing human-in-the-loop controls where automation should not have full autonomy.
  • Designing logging, telemetry, and auditability for AI-enabled systems.
  • Helping detect excessive, unintended, or potentially unsafe agent behavior.
  • Turning new AI security risks into practical engineering patterns that can be reused across the organization.

Skills

Security engineering
Web API security
OAuth/OIDC
Least-privilege
Runtime security
API gateways/WAFs
Cloud-native security
AppSec/DevSecOps
AI security
Distributed architectures

Job description

Engagement: Contract with potential Contract-to-Direct Hire

Duration: 6–12 months + with potential extension

Help Secure What AI Is Allowed to Do

AI is moving beyond generating content.

It is starting to take action.

That creates a very different security problem.

We are looking for a senior security engineer to help secure AI-enabled digital platforms where application security, identity, APIs, cloud, and autonomous systems intersect.

This is not a traditional AppSec role.

You will help answer questions like:

  • What is an AI agent allowed to access?
  • What authority is it operating under?
  • How do we prevent it from taking actions outside its intended scope?
  • Where should security policy stop or require approval before an action occurs?
  • How do we create these controls without slowing down product and engineering teams?

If you enjoy emerging security problems but have the engineering fundamentals to actually build the controls, this is worth a conversation.

What You’ll Do

You will work across security, engineering, product, identity, platform, and AI teams to help build practical security controls for next-generation digital experiences.

Your work may include:
  • Designing security controls for AI agents and autonomous workflows
  • Establishing runtime authorization and least-privilege boundaries
  • Securing non-human identities, workloads, service accounts, and AI agents
  • Designing delegated authorization using OAuth, OIDC, tokens, and short-lived credentials
  • Maintaining attribution across users, agents, services, APIs, and actions
  • Reviewing complex application and distributed-system architectures
  • Securing high-volume consumer-facing digital and transaction environments
  • Building secure patterns for APIs and backend services
  • Applying strong AppSec and DevSecOps principles
  • Working with API gateways, WAFs, edge controls, and bot mitigation
  • Securing cloud-native, containerized, and service-to-service environments
  • Defining policy enforcement points before sensitive or high-impact actions occur
  • Implementing human-in-the-loop controls where automation should not have full autonomy
  • Designing logging, telemetry, and auditability for AI-enabled systems
  • Helping detect excessive, unintended, or potentially unsafe agent behavior
  • Turning new AI security risks into practical engineering patterns that can be reused across the organization
What We’re Looking For

We are not expecting someone who has spent 10 years doing “agentic AI security.”

That talent market does not exist yet.

We are looking for someone with strong security engineering fundamentals who can apply them to a new problem.

You will likely have:
  • 8+ years of experience across security engineering, application security, product security, platform security, or similar disciplines
  • Strong hands-on web application and API security experience
  • AppSec and/or DevSecOps engineering experience
  • Deep understanding of OAuth 2.x, OIDC, token-based authorization, delegated access, and service identities
  • Experience designing fine-grained authorization and least-privilege models
  • Strong knowledge of APIs and distributed application architectures
  • Experience with cloud-native environments and service-to-service security
  • Experience with API gateways, WAFs, edge security, or similar controls
  • Experience securing complex, consumer-facing or high-availability applications
  • Exposure to AI-enabled, automation-heavy, or autonomous systems
  • The ability to think through how deterministic security controls can govern non-deterministic AI behavior
Experience That Will Get Our Attention

You may stand out if you have worked with:

  • Agentic AI or AI orchestration platforms
  • MCP or agent runtime security
  • Non-Human Identity / workload identity
  • Policy-as-code
  • Runtime authorization or policy enforcement
  • API abuse prevention
  • Fraud or transaction security
  • Cloud-native security
  • Secure API design patterns such as scoped execution, rollback, idempotency, rate limiting, or preview/apply
The Person We Want

We are looking for a builder, not just a reviewer.

Someone who can walk into an architecture discussion, understand how the system really works, identify where trust can break, and help engineers build a better control.

You should be comfortable crossing traditional security boundaries.

One day the problem may be OAuth delegation.

The next may be API authorization.

Then AI agent permissions.

Then application architecture or runtime controls.

You do not need to know everything.

You do need to be technically curious, capable of going deep, and comfortable solving security problems where the playbook is still being written.

If you have spent your career securing complex applications and platforms and are now thinking seriously about how identity, authorization, APIs, and security controls need to evolve when AI systems can take action, we would like to talk with you.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer - AI Focus
Senior Security Engineer - AI Focus

Euna Solutions • Atlanta (GA)

On-site
USD 140,000 - 210,000
AI-Application Security Engineer
AI-Application Security Engineer

Stifel Financial Corp. • St. Louis (MO)

On-site
USD 90,000 - 120,000
Sr. AI Security Engineer
Sr. AI Security Engineer

McCarthy Holdings, Inc. • Phoenix (AZ), Dallas (TX)

On-site
USD 120,000 - 160,000
Senior Security AI Engineer
Senior Security AI Engineer

Imperial PFS • Kansas City (MO)

On-site
USD 130,000 - 160,000
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent • Tysons (VA)

Hybrid
USD 120,000 - 160,000
Bonus
Competitive benefits
Senior Security AI Engineer
Senior Security AI Engineer

Imperial Funding Corporation • Kansas City (MO)

On-site
USD 130,000 - 190,000
Medical, prescription, dental benefits
Wellness program and EAP
401(k) with company match
+1
Engineering Manager, Application Security
Engineering Manager, Application Security

Qualia • Austin (TX)

On-site
USD 180,000 - 240,000
Medical, Dental & Vision health plans
Competitive salary & equity
Flexible schedules
+3
Application Security Engineer
Application Security Engineer

Gravity IT Resources • Miami (FL)

On-site
USD 165,000 - 248,000
Senior Security Engineer - AI
Senior Security Engineer - AI

7AI • Boston (MA)

On-site
USD 100,000 - 140,000
AI Security Engineer
AI Security Engineer

Synergy Business Consulting, Inc. • Fort Lauderdale (FL)

Hybrid
USD 110,000 - 150,000
Housing 30 days
Relocation package
Flights