The Application Security Lead Engineer is a senior role focused on leading application security engineering across cloud-native, microservices-based environments. This position centers on designing and advancing scalable security controls, integrating security throughout DevSecOps practices, and strengthening security outcomes for critical applications. The role also brings deep focus to AI/ML security in support of modern application and platform security needs.
• AppSec engineering — target L9 (Exp), must-have • Cloud Security — target L9 (Exp), must-have • OWASP ASVS — target L8 (Adv), must-have • NIST 800 53 — target L8 (Adv), must-have • microservices — target L8 (Adv), must-have • DevSecOps — target L8 (Adv), must-have • Kubernetes — target L8 (Adv), must-have • AI/ML security — target L9 (Exp), must-have • Working AI leverage — observed and scored, never assumed • 6–0 years of relevant experience From the hiring team: Job Summary: This role will require you to lead security engineering initiatives, perform advanced risk assessments, and design scalable security controls across critical applications. You will serve as a subject matter expert (SME) in application, guiding engineering teams, influencing security strategy, and driving automation across the SDLC. This role requires deep technical expertise, leadership potential, and the ability to shape long term Application Security direction. Key Responsibilities • Design and implement security architectures and controls for large-scale, cloud-native applications. • Conduct in-depth risk assessments, including penetration testing and code reviews. • Collaborate with developers and DevOps teams to integrate security at all stages of the software development lifecycle (SDLC). • Drive security for AI-powered features by defining secure architectures, assessing AI/ML risks, and implementing advanced testing and controls for AI models, agents, and MCP servers. • Identify areas of improvements in security tools and practices, and remediate the identified gap by implementing innovative solutions. • Evaluate third party security tools and vendor provided controls for technical effectiveness, enterprise fit, and alignment with organization’s security architecture and standards. • Collaborate with vendors to provide actionable technical feedback, drive product improvements, and ensure controls are implemented and configured appropriately for Bloomberg Industry Group’s environment. • Build, improve, and scale security automation, integrating tooling across CI/CD pipelines and cloud platforms. • Provide guidance to junior engineers and cross-functional teams on security best practices. • Participate in incident response efforts and investigations into security incidents. • Stay ahead of the curve by keeping informed of industry trends and emerging threats, applying this knowledge to continually improve security Required Skills & Qualifications • 6 years of relevant experience in Application Security, AppSec engineering, Cloud Security, or Software Engineering • Deep expertise in application security, secure software design, and risk management, including frameworks such as OWASP ASVS, OWASP Top 10, and NIST 800 53. • Extensive experience conducting complex security assessments and building automated security controls for large engineering environments. • Proficiency in multiple programming languages (e.g., Python, Java, JavaScript) and hands-on experience with SAST, DAST, SCA, IaC, container, and cloud security tools. • Strong understanding of modern architectures (cloud-native, microservices, Kubernetes, containers, serverless) and DevSecOps processes. • Advanced understanding of AI/ML security, including model vulnerability analysis, AI threat modeling, secure LLM integration patterns, and familiarity with NIST AI RMF or OWASP Top 10 for LLMs
Lead application security engineering initiatives across cloud-native applications and platforms. Design and implement scalable security controls aligned to microservices, Kubernetes, and DevSecOps environments. Conduct deep security assessments and use recognized frameworks such as OWASP ASVS and NIST 800 53 to inform security architecture, control design, and risk reduction. Partner with engineering teams to embed security throughout software delivery and strengthen security practices for AI/ML-enabled systems.
Techies4tech.ai is the hiring organization.
This role offers the opportunity to lead senior-level application security engineering work with broad influence on architecture, controls, and secure delivery practices. The scope spans cloud security, modern application environments, and AI/ML security, creating meaningful impact across current and emerging security priorities. It is a strong fit for someone who wants to shape security direction through hands-on technical leadership in a complex engineering context.
Techies4Tech validates your skills through real coding samples and interviews. Apply now to stand out to hiring teams.
Log In & Apply