Senior Information Security Engineer – AI, Application Security
Job in
Washington, District of Columbia, 20022, USA
Listed on 2026-09-15
Listing for:
Jobtailor
Full Time
position Listed on 2026-09-15
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
- Own security assessments of the firm’s AI platforms and AI-enabled tools, including Harvey and Microsoft Copilot
- Apply the OWASP Top 10 for LLMs and the firm’s AI governance framework as evaluation standards
- Design and execute testing for prompt injection, jail breaking, data leakage, and cross-client isolation in retrieval-augmented and agentic AI platforms
- Produce evidence that one client’s data cannot influence another client’s outputs in support of information barrier and privilege obligations
- Evaluate and harden API and integration security across AI platforms, automation tooling, and connected data systems
- Assess authentication, authorization, gateway policies, rate limiting, and anomaly detection for misuse or exfiltration
- Conduct ongoing security and configuration assessments of Azure, SaaS, and on-premises applications and services
- Identify misconfigurations, design weaknesses, and development errors
- Serve as the embedded security partner to the Catalyst Studio and AI and Automation teams
- Participate in design reviews and ensure security requirements are defined before development begins
- Build and report application and AI security posture metrics in business terms relevant to legal operations
- Perform special projects and other assigned duties
- Bachelor’s degree in computer science, cybersecurity, or a related field, or equivalent years of experience
- Eight years or more of relevant experience in application security, secure software development, or information security, including at least three years focused on application security
- Strong understanding of the OWASP Top 10 and secure coding principles
- Familiarity with the OWASP Top 10 for LLMs
- Hands-on experience with application security testing, including threat modeling, secure code review, and static and dynamic testing
- Experience managing findings through remediation
- Working knowledge of the software development lifecycle
- Experience embedding security into development and deployment pipelines in cloud or hybrid environments
- Proficiency in at least one programming or scripting language sufficient to review code and build testing tooling
- Experience designing or assessing API security controls, including authentication, authorization, and gateway policies
- Working knowledge of AI and LLM security risks, including prompt injection, data leakage, and cross-tenant isolation in retrieval-augmented architectures
- Experience assessing third-party and SaaS vendor security architectures
- Detailed technical knowledge of application, operating system, and network security fundamentals
- Thorough understanding of current security principles, techniques, and protocols
- Ability to effectively communicate information security issues, risks, and recommendations to technical and non-technical peers and management, including through well-written reports
- Ability to problem-solve
- Excellent interpersonal, verbal and written communication skills, including communication in a virtual environment
- Ability to work calmly and effectively in a high-pressure, deadline-oriented environment
- Demonstrated ability to use good judgment and take initiative
- Willingness to be flexible with time and adjust to a changing work environment
- Ability to build and maintain positive internal and external relationships while maintaining a client service orientation
- Ability to use sound judgment and discretion with highly confidential information
- Ability to take direction and accept supervision
- Demonstrated ability to work independently, organize and prioritize work accurately, be detail-oriented, understand urgency, and use good judgment
- Ability to work effectively in a team-oriented collaborative environment
Demonstrates expertise in application security, including OWASP Top 10 and…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×