Job Description Senior Application Security Engineer - Threat Modeling & AI Security Locations: Charlotte, NC (Brevard), Irving/Las Colinas, TX, or Chandler, AZ Schedule: Hybrid (3 Days Onsite / 2 Days Remote) Duration: Contract Overview We are seeking a Senior Application Security Engineer to lead enterprise threat modeling initiatives and help build AI-driven security automation solutions. This role will focus on identifying application security risks, automating threat modeling processes, and partnering with engineering teams to implement secure-by-design practices across the organization. Key Responsibilities Lead application threat modeling efforts using OWASP methodologies and best practices.
Analyze and decompose application architectures to identify security risks and mitigation strategies. Design and implement AI/LLM-powered security automation solutions. Partner with development and architecture teams to improve application security posture.
Integrate security controls into CI/CD pipelines and engineering workflows. Track, assess, and remediate application security vulnerabilities. Develop reusable security standards, reference architectures, and threat modeling frameworks.
Required Qualifications 7+ years of Application Security Engineering experience. 2+ years of hands-on Threat Modeling experience. Experience building AI/LLM-based security solutions for enterprise environments.
Strong understanding of secure application architecture, API security, authentication, and authorization. Experience with cloud security (AWS, Azure, or GCP). Strong communication, collaboration, and problem-solving skills.
Experience with Jira, GitHub, and security automation initiatives. Preferred Qualifications Experience with secure coding, DevSecOps, SAST, DAST, SCA, container security, and software supply chain security. Background in software engineering or application architecture.
Experience securing AI-enabled applications and GenAI solutions. Python development experience. Certifications such as CISSP, CSSLP, CCSP, GIAC GWEB, or GIAC GWAPT.
Key Skills Application Security Threat Modeling AI Security GenAI Security Automation Cloud Security API Security DevSecOps Python OWASP Risk Mitigation Secure Architecture Jira GitHub