Job Description
To manage application and AI security across enterprise systems and AI-enabled solutions.
1 - Application & AI Security Governance:
- Establish and maintain the Application Security and AI Security program.
- Define security standards, control requirements, and governance processes for applications and AI-enabled solutions.
- Align application and AI security practices with cybersecurity, privacy, data protection, enterprise architecture, and risk management requirements.
- Maintain secure development guidelines for traditional applications, APIs, cloud-native applications, and AI solutions.
2 - Secure Design, Architecture Review & Threat Modeling:
- Conduct threat modelling for business applications, APIs, cloud applications, AI use cases, and AI-enabled workflows.
- Review application and AI solution architectures to identify security design weaknesses.
Assess authentication, authorization, session management, data flows, integration patterns, and trust boundaries.
- Identify risks such as prompt injection, insecure AI integrations, model misuse, excessive agency, data leakage, and unauthorized access to sensitive information.
3 - Secure SDLC & DevSecOps Enablement:
- Embed application and AI security requirements across design, development, testing, release, and production deployment stages.
- Advise development teams on secure software engineering, secure coding, API security, secrets management, dependency management, and DevSecOps practices.
- Define security gates before production deployment for applications and AI solutions.
Promote developer security awareness and practical secure coding practices.
4 - Application Security Testing & Vulnerability Management:
- Manage and review findings from SAST, DAST, API security testing, software composition analysis, container scanning, and manual security reviews.
- Prioritize vulnerabilities based on severity, exploitability, exposure, business criticality, and data sensitivity.
- Coordinate remediation with development, infrastructure, application owners, and cybersecurity teams.
- Track closure of security findings and validate remediation before release or production go-live.
5 - AI Security, Privacy & Data Protection Risk Assessment:
- Assess AI use cases for cybersecurity, privacy, legal, regulatory, and data protection risks.
Review AI-related data flows, training data, input/output handling, access controls, logging, retention, and sensitive data exposure risks.
- Evaluate third-party AI services, internal AI platforms, APIs, plugins, and AI integrations with enterprise systems from cybersecurity perspective
- Define controls for prompt injection, data leakage, model misuse, insecure outputs, unauthorized data access, and AI-assisted software vulnerabilities.
6 - Advisory, Monitoring & Continuous Improvement:
- Monitor emerging application security and AI security threats, vulnerabilities, attack techniques, and industry best practices.
- Provide expert advisory to development, infrastructure, cybersecurity, privacy, and business teams.
- Support secure adoption of AI technologies across the organization while enabling innovation safely.
- Report application and AI security posture, risks, remediation progress, and key metrics to management.
- Continuously improve tools, processes, standards, and security review practices.
Skills
- Communication skills
- Risk based approach.
- Experience with Secure SDLC.
- Experience performing threat modelling.
- Experience securing APIs.
- Experience reviewing source code.
- Exposure to AI/LLM technologies, either through implementation, governance, or security assessments.
- Experience supporting DevSecOps environments.
- Experience assessing application security risks in regulated environments is preferred
- Certified Secure Software Lifecycle Professional (CSSLP) preferred
- GIAC Web Application Penetration Tester (GWAPT) preferred
- CISSP preferred
- Vendor AI security or AI governance certifications (Microsoft, AWS, google, or equivalent)
4+ years of relevant experience
Education
Bachelor's degree in computer science, Software Engineering, Cybersecurity, or related field.