Senior Lead Application Security Engineer
Listed on 2026-08-17
-
IT/Tech
Cybersecurity, Information Security & Data Protection
We are seeking a Senior Lead Application Security Engineer to define and execute Application Security strategy for the Data Center Modernization and Simplification (DCMS) program and to drive innovation through AI-enabled Application Security capabilities. This role is responsible for shaping enterprise-scale App Sec strategy, influencing cross-functional stakeholders, and delivering scalable, automated security outcomes aligned to the Secure Software Development Lifecycle (SSDLC).
Hybrid Roles in Charlotte, NC – 3 days Onsite/2 days Remote
Duration: 12+ months with possibility of longer-term extensions
Pay Rate: $95/hr - $100/hr on W2
No C2C, H1B, 1099, OPT or 3rd PARTY RESUMES
Required:
Experience and Skills
7+ years of Application Security or Information Security Engineering experience at enterprise scale.
Deep expertise in SSDLC controls including threat modeling, secure design, SAST, SCA, DAST, and penetration testing.
Proven ability to define security strategy and deliver outcomes through influence and technical leadership.
Experience securing GenAI and LLM-based applications, including adversarial testing and prompt-injection defenses.
Experience designing AI-driven security automation or decisioning capabilities.
Strong understanding of Dev Sec Ops and CI/CD security integration.
Experience working in highly regulated environments such as financial services.
Relevant security certifications (CISSP, CSSP, CISM, or equivalent).
Key Responsibilities
- Define and lead the Application Security strategy for DCMS in-scope applications using tier-based control models.
- Evaluate existing App Sec control coverage and establish baseline mappings by application tier.
- Identify control gaps and drive remediation and onboarding plans with application teams and stakeholders.
- Partner with Application Security Champions and engineering teams to ensure consistent adoption of required App Sec controls.
- Ensure alignment with enterprise SDLC requirements and defect remediation expectations.
- Identify and deliver AI and GenAI use cases that reduce manual App Sec effort and improve security coverage.
- Design and implement automated threat modeling using code, infrastructure-as-code, and application metadata.
- Develop adversarial testing capabilities for GenAI and LLM-based applications, including prompt injection and abuse scenarios.
- Lead initiatives for AI model scanning, integrity validation, and secure onboarding of models.
- Define protections for AI-specific risks including insecure prompt construction, tool misuse, and secrets exposure.
- Drive modernization of App Sec controls through automation, rationalization, and platform integration.
- Build proofs-of-concept and pilot new security capabilities, scaling successful solutions into production.
- Influence simplification of App Sec processes to improve developer experience while maintaining strong risk controls.
- Provide strategic guidance to senior leadership on Application Security priorities, risks, and investment decisions.
- Influence cross-functional teams without direct authority to achieve enterprise security outcomes.
- Research emerging threats and technologies and translate insights into actionable App Sec strategy.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).