About this role
Security Engineer 5 – (Penetration Testing, AI Security & Application Security Strategy) Location: Charllotte, NC / Dallas, TX / Minneapolis, MN / Chandler, AZ / Des Moines, IA, Raleigh, NC
Job Summary
The organization is seeking a highly experienced Engineer 5 / Senior Lead Application Security Engineer to define and execute Application Security strategy supporting enterprise modernization initiatives, including the Data Center Modernization and Simplification (DCMS) program. This role serves as a senior technical leader responsible for driving enterprise-scale application security strategy, advancing security automation, leading penetration testing initiatives, and delivering innovative AI-enabled security capabilities. The ideal candidate possesses deep expertise in Application Security, Secure Software Development Lifecycle (SSDLC) controls, offensive security, threat modeling, vulnerability management, and security engineering. This individual will partner with executive leadership, security teams, software engineering organizations, and business stakeholders to deliver scalable, automated, and risk-aligned security outcomes across the enterprise. This role requires a strategic leader who can influence executive stakeholders, drive modernization initiatives, and shape the future of Application Security through the adoption of emerging technologies including Artificial Intelligence, Large Language Models (LLMs), and advanced security automation.
Key Responsibilities
-
Application Security Strategy & Leadership
-
Define and lead enterprise Application Security strategy supporting Data Center Modernization and Simplification (DCMS) initiatives. Establish security control requirements and baseline security coverage models across application portfolios. Assess existing Application Security control coverage and identify gaps requiring remediation. Develop and execute AppSec onboarding and improvement plans across application portfolios. Partner with Application Security Champions, engineering teams, architects, and business stakeholders to drive security control adoption and remediation efforts. Ensure alignment with enterprise Secure Software Development Lifecycle (SSDLC) requirements and remediation expectations. Serve as a trusted advisor to senior leadership on Application Security risks, investments, and strategic priorities. Influence enterprise-wide security initiatives through technical expertise and strategic leadership.
-
Penetration Testing & Offensive Security
-
Lead enterprise penetration testing strategies and application security assessment programs. Perform or oversee: Application Penetration Testing, Security Architecture Reviews, Red Team Assessments, Threat Modeling Exercises, Vulnerability Research, Security Assessments, Adversarial Security Testing. Evaluate vulnerabilities, identify security weaknesses, and develop remediation strategies. Research emerging attack techniques, threat actor behaviors, and evolving risk trends. Provide technical leadership on remediation planning and security risk reduction activities. Guide development teams on secure design principles and vulnerability mitigation strategies. Support offensive security initiatives including exploitation analysis, security testing, and application security validation activities.
-
Application Security Modernization
-
Lead secure-by-design and application security modernization initiatives across the enterprise. Drive adoption of security automation, security tooling, and developer enablement capabilities. Partner with software engineering teams to improve security outcomes while enhancing developer experience. Simplify and optimize Application Security processes while maintaining strong risk controls. Build proofs-of-concept and pilot emerging security capabilities, scaling successful solutions to production environments. Develop long-term strategy for AppSec platform maturity, automation, and operational effectiveness.
-
AI Security & GenAI Application Protection
-
Identify, evaluate, and implement AI and Generative AI (GenAI) security use cases that improve security effectiveness and reduce manual effort. Develop adversarial testing methodologies for Large Language Models (LLMs), Generative AI Applications, and AI-Powered Services. Design defenses against Prompt Injection Attacks, Model Abuse, Tool Misuse, Sensitive Data Exposure, and Secrets Leakage. Support AI model scanning, integrity validation, secure onboarding, and governance programs. Define security controls addressing emerging AI-specific risks. Lead initiatives involving AI Testing, AI Security Analytics, AI Operationalization, and AI Security Assessment Automation. Evaluate emerging AI technologies and develop enterprise security strategies for AI adoption.
-
Secure Software Development Lifecycle (SSDLC)
-
Lead and mature enterprise SSDLC programs. Define and implement security requirements throughout the software development lifecycle. Provide expertise in Threat Modeling, Secure Design Reviews, Secure Coding Practices, SAST, SCA, DAST, Penetration Testing. Partner with engineering organizations to improve developer security capabilities and secure coding maturity. Drive consistent application of security controls across development teams.
-
Security Automation & DevSecOps
-
Drive modernization of Application Security controls through automation and platform integration. Design AI-driven security automation capabilities and intelligent security decisioning solutions. Develop and implement security tooling integrations and automation frameworks. Collaborate with DevSecOps teams to integrate security controls into CI/CD pipelines. Leverage Infrastructure as Code (IaC), platform automation, and security orchestration capabilities where appropriate. Improve security efficiency through automation, continuous validation, and workflow optimization.
-
Enterprise Influence & Technical Leadership
-
Act as a senior advisor to technology leadership on Application Security strategy and enterprise security roadmaps. Influence cross-functional teams without direct authority to achieve enterprise security outcomes. Collaborate with Application Security Champions, engineering organizations, and business stakeholders to drive risk reduction and secure development practices. Translate emerging threats, technologies, and industry trends into actionable security programs. Mentor and develop Application Security engineers and security practitioners. Contribute to enterprise security standards, policies, and best practices. Represent Application Security initiatives with executive leadership and key stakeholders.
-
Required Qualifications
-
7+ years of Application Security, Information Security Engineering, or related engineering experience. Deep expertise in enterprise-scale Application Security programs. Strong experience with: Threat Modeling, Secure Design, Secure Coding Practices, SAST, SCA, DAST, Penetration Testing. Demonstrated experience defining and executing enterprise Application Security strategy. Proven ability to influence technical and business leaders across large organizations. Strong understanding of vulnerability management, remediation processes, and security governance. Exceptional communication, leadership, and executive stakeholder management skills.
-
Preferred Qualifications
-
Advanced Application Security & Offensive Security. Experience leading enterprise Application Security transformation and modernization initiatives. Experience supporting Application Security governance, security consulting, remediation planning, and security champion programs. Strong expertise in: Application Security Testing, Offensive Security, Vulnerability Research, Exploitation Techniques, Red Team Methodologies, Security Assessments. Experience driving secure-by-design and SSDLC initiatives across large application portfolios. Experience working directly with developers and application owners to implement security controls and remediation plans. AI & GenAI Security. Experience securing Generative AI Applications, Large Language Models (LLMs), AI/ML Platforms. Experience conducting adversarial AI testing and prompt injection assessments. Experience with Prompt Engineering, LLM Security, AI Testing, AI Operationalization, AI Security Analytics, AI Security Assessment Automation. Experience building AI-driven security automation capabilities. DevSecOps & Automation. Strong understanding of DevSecOps, CI/CD Security Integration, Security Automation, Infrastructure as Code (IaC), Platform Automation. Experience integrating security scanning technologies into software delivery pipelines. Experience developing security tooling integrations and automation frameworks. Cloud & Modernization. Experience supporting enterprise modernization initiatives, cloud-native architectures, and security transformation programs. Experience with Cloud Security, Cloud Architecture, Platform Engineering, Infrastructure Automation. Google Cloud Platform (GCP), Azure Environments.