
Lead Application Security Engineer AI
Overview
As a Lead Application Security Engineer, you will own the application security strategy for DCMS in-scope applications, defining tier-based control models that scale across the portfolio. You will evaluate existing AppSec control coverage, establish baseline mappings, and drive remediation of critical gaps. Reporting to the security leadership, you will collaborate with engineering teams to embed security into the SDLC, focusing on cloud-native environments and AI applications. This role offers the chance to shape security posture for a major financial client, with a 12+ month contract and hybrid work in Charlotte, NC.
What You'll Do8
- 1Define and lead the AppSec strategy for DCMS in-scope applications using tier-based control models.
- 2Evaluate current security control coverage and map them to application tiers, identifying gaps in protection.
- 3Drive remediation of control gaps, prioritizing based on risk and business impact.
- 4Integrate SAST, DAST, and SCA tools into CI/CD pipelines for automated security checks.
- 5Collaborate with development teams to enforce secure coding practices and conduct code reviews.
- 6Monitor and respond to security incidents in AWS and Azure environments.
- 7Develop and maintain security metrics and KPIs to measure AppSec program effectiveness.
- 8Coach and mentor junior security engineers, fostering a security-first culture.
Requirements8
- 15+ years of experience in application security engineering, with 2+ years in a lead role.
- 2Expertise in OWASP Top 10, threat modeling, and secure SDLC methodologies.
- 3Hands-on experience with SAST, DAST, SCA, and RASP tools.
- 4Strong knowledge of cloud platforms AWS and Azure, including security services like CloudTrail and GuardDuty.
- 5Experience with containerization and orchestration technologies like Docker and Kubernetes.
- 6Exposure to AI and machine learning security concepts, including adversarial attacks and model integrity.
- 7Proficiency in at least one programming language (e.g., Python, Java, C#).
- 8Relevant certifications such as CISSP, CSSLP, or AWS Certified Security are a plus.
Salary Insight
Salary not disclosed in listing
Similar open positions
Explore active roles that match your skills and interests.

Motion Recruitment Partners, LLC
VerifiedPrincipal Application Security Engineer
You will own application security for a major financial services firm with over 150 years of market presence, hardening Java and .NET applications across a global portfolio. You will lead security reviews, threat modeling, and code analysis while partnering with DevOps to embed security into CI/CD pipelines. This hybrid role in Charlotte, NC offers direct impact on high-velocity releases and access to cutting-edge cloud infrastructure.

QUANTUM TECHNOLOGIES LLC
VerifiedAWS Cloud Engineer, Application Security
You will own security for applications built and operated on AWS, embedding security across the entire SDLC from design to incident response. You will work with development teams to enforce secure coding and automate security checks in CI/CD pipelines. You will also manage runtime protection and respond to security incidents, collaborating with engineering and operations. This contract role in Dallas, TX offers 6+ months of work with potential extension, focusing on application security in a dynamic cloud environment.
Wells Fargo
VerifiedLead Information Security Engineer, AppSec
As a Lead Information Security Engineer on the Application Security Team, you will own the integration of AppSec controls across enterprise tools and CI/CD pipelines at Wells Fargo. You will design and implement automated, repeatable AppSec processes, drive shift-left security strategies, and enhance reporting for executive visibility. Collaborating with Security Architecture, governance, and control management, you will influence enterprise risk decisions and mentor a team of security engineers. This role offers a chance to shape AppSec at scale in a highly regulated financial environment, with a focus on AI/LLM-enabled tooling and modern DevSecOps practices.
US132 Guidehouse Digital, LLC
VerifiedAI & Data Lead Developer, Cloud & Analytics
You own the technical delivery of data engineering, analytics, and AI-enabled solutions for large-scale data modernization projects in the public sector. Building on 10+ years of experience, you design and operationalize data pipelines, integrate AI capabilities, and guide cross-functional teams in an Agile environment. You work with AWS and Snowflake to drive scalable architectures, partnering with architects and operations leads to ensure production-grade outcomes. This role stands apart by combining hands-on development with strategic leadership, directly shaping federal data modernization initiatives.
greenlight
VerifiedStaff Product Security Engineer, AI & Cloud Security
You will own end-to-end security for consumer products, a digital platform, and an emerging hardware line at Greenlight, a fintech serving 6.5 million family members. You will drive threat modeling, lead penetration testing, manage PSIRT operations, and champion secure AI adoption across the company. Collaborating with architects, product managers, and engineering, you will define security guardrails for AI-powered products and development workflows. This role offers a rare blend of hands-on technical work and strategic influence in a highly regulated financial environment.
The Charles Stark Draper Laboratory, Inc.
VerifiedAI Cyber Principal - Draper
Draper seeks an AI Cyber Principal to lead cyber security and resilience of internal AI models. This role establishes frameworks for AI-driven tools while protecting against AI-specific threats and establishing model governance. The incumbent secures deployments and extends AI capabilities through understanding of AI and cyber security threats.