Principal Application & AI Security Engineer
Listed on 2026-09-13
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security & Data Protection
About Us
We are the independent expert in assurance and risk management. Driven by our purpose, to safeguard life, property, and the environment, we empower our customers and their stakeholders with facts and reliable insights so that critical decisions can be made with confidence.
About UsWe are the independent expert in assurance and risk management. Driven by our purpose, to safeguard life, property, and the environment, we empower our customers and their stakeholders with facts and reliable insights so that critical decisions can be made with confidence. As a trusted voice for many of the world’s most successful organizations, we use our knowledge to advance safety and performance, set industry benchmarks, and inspire and invent solutions to tackle global transformations.
AboutEnergy Systems
We help customers navigate the complex transition to a decarbonized and more sustainable energy future. We do this by assuring that energy systems work safely and effectively, using solutions that are increasingly digital. We also help industries and governments to navigate the many complex, interrelated transitions taking place globally and regionally, in the energy industry.
AboutThe Role
DNV Energy Systems' Platform Services runs the software products and digital platforms our customers depend on, including systems with significant operational importance in enterprise and energy environments. As we evolve toward agentic AI architectures, security must move from after-the-fact review into architecture, development workflows, and runtime operations - engineered into the platform and the delivery pipeline, with evidence that controls are implemented and operating effectively.
This is a builder's role for a senior technical leader who can read and improve code, design reusable controls, model complex threats, conduct authorized security testing, and work directly with engineering teams to ship durable fixes. The goal is not simply to identify vulnerabilities. It is to eliminate recurring vulnerability classes, reduce exposure, and make the secure path the easiest path.
Thisrole is based at our DNV office in Houston, TX or Oakland, CA, presenting a dynamic hybrid schedule where employees will typically spend three (3) days per week working from either a DNV office or client location/site. Further details regarding role-specific requirements will be shared during the interview process. What You'll Do
- Securing application and AI architecture. Design and implement secure patterns across applications, APIs, cloud platforms, and AI-agent systems, with particular emphasis on identity, authorization, tenant isolation, data access, tool use, and runtime guardrails.
- Automating security in engineering workflows. Build and tune risk-based controls so material issues are caught and acted on inside delivery workflows, rather than at manual checkpoints.
- Eliminating recurring vulnerabilities. Find root causes, fix weaknesses at the architecture or platform-pattern level, and make the same class of issue structurally difficult to reintroduce.
The responsibilities below describe how this work shows up day-to-day across architecture, delivery, AI systems, remediation, and engineering.
Build security into delivery and platform engineering- Design and implement scalable controls for software and AI supply chains, including dependency integrity, SCA, SAST, DAST, build provenance, artifact security, secrets protection, container and infrastructure-as-code assurance, and software or AI bills of materials where appropriate.
- Implement platform-level controls: policy as code, authorization enforcement, data-access guardrails, secure defaults, and reusable reference implementations.
- Design AI-assisted security-testing environments, automated attack scenarios, and security-regression suites that prevent resolved issues from silently returning.
- Implement risk-based quality gates with documented exception paths, accountable ownership, and service-level expectations, so material issues block release.
- Review source code, APIs, and application designs for weaknesses in authentication, authorization, session management, input handling, data-access scope, and multi-tenant isolation, including row- and field-level boundaries.
- Conduct authorized application, API, and AI security testing, including targeted manual testing of business logic and trust boundaries that automated tools cannot adequately validate.
- Work alongside engineers to…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).