Engineer - Penn Tester
Listed on 2026-07-27
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Security Engineer 5
Location:
Charlotte, NC / Dallas, TX / Minneapolis, MN / Chandler, AZ / Des Moines, IA / Raleigh, NC
The organization is seeking a highly experienced Engineer 5 / Senior Lead Application Security Engineer to define and execute Application Security strategy supporting enterprise modernization initiatives, including the Data Center Modernization and Simplification (DCMS) program. This role serves as a senior technical leader responsible for driving enterprise-scale application security strategy, advancing security automation, leading penetration testing initiatives, and delivering innovative AI-enabled security capabilities.
The ideal candidate possesses deep expertise in Application Security, Secure Software Development Lifecycle (SSDLC) controls, offensive security, threat modeling, vulnerability management, and security engineering. This individual will partner with executive leadership, security teams, software engineering organizations, and business stakeholders to deliver scalable, automated, and risk-aligned security outcomes across the enterprise.
This role requires a strategic leader who can influence executive stakeholders, drive modernization initiatives, and shape the future of Application Security through the adoption of emerging technologies including Artificial Intelligence, Large Language Models (LLMs), and advanced security automation.
Key Responsibilities
Application Security Strategy & Leadership- Define and lead enterprise Application Security strategy supporting Data Center Modernization and Simplification (DCMS) initiatives.
- Establish security control requirements and baseline security coverage models across application portfolios.
- Assess existing Application Security control coverage and identify gaps requiring remediation.
- Develop and execute App Sec onboarding and improvement plans across application portfolios.
- Partner with Application Security Champions, engineering teams, architects, and business stakeholders to drive security control adoption and remediation efforts.
- Ensure alignment with enterprise Secure Software Development Lifecycle (SSDLC) requirements and remediation expectations.
- Serve as a trusted advisor to senior leadership on Application Security risks, investments, and strategic priorities.
- Influence enterprise-wide security initiatives through technical expertise and strategic leadership.
- Lead enterprise penetration testing strategies and application security assessment programs.
- Perform or oversee:
Application Penetration Testing, Security Architecture Reviews, Red Team Assessments, Threat Modeling Exercises, Vulnerability Research, Security Assessments, Adversarial Security Testing. - Evaluate vulnerabilities, identify security weaknesses, and develop remediation strategies.
- Research emerging attack techniques, threat actor behaviors, and evolving risk trends.
- Provide technical leadership on remediation planning and security risk reduction activities.
- Guide development teams on secure design principles and vulnerability mitigation strategies.
- Support offensive security initiatives including exploitation analysis, security testing, and application security validation activities.
- Lead secure-by-design and application security modernization initiatives across the enterprise.
- Drive adoption of security automation, security tooling, and developer enablement capabilities.
- Partner with software engineering teams to improve security outcomes while enhancing developer experience.
- Simplify and optimize Application Security processes while maintaining strong risk controls.
- Build proofs-of-concept and pilot emerging security capabilities, scaling successful solutions to production environments.
- Develop long-term strategy for App Sec platform maturity, automation, and operational effectiveness.
- Identify, evaluate, and implement AI and Generative AI (GenAI) security use cases that improve security effectiveness and reduce manual effort.
- Develop adversarial testing methodologies for:
Large Language Models (LLMs), Generative AI Applications, AI-Powered Services. - Design defenses against:
Prompt Injection Attacks, Model Abuse, Tool Misuse, Sensitive Data Exposure, Secrets Leakage. - Support AI model scanning, integrity validation, secure onboarding, and governance programs.
- Define security controls addressing emerging AI-specific risks.
- Lead initiatives involving AI Testing, AI Security Analytics, AI Operationalization, and AI Security Assessment Automation.
- Evaluate emerging AI technologies and develop enterprise security strategies for AI adoption.
- Lead and mature enterprise SSDLC programs.
- Define and implement security requirements throughout the software development lifecycle.
- Provide expertise in:
Threat Modeling, Secure Design Reviews, Secure Coding Practices, Static Application Security Testing (SAST), Software Composition Analysis (SCA),…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).