Arquiteto de Segurança em Desenvolvimento (AppSec) Senior

1 month, 3 weeks ago
Full-time
Senior
Software Development
Harford County Public Library

Harford County Public Library

Access, Information, Service, Anytime, Anywhere

Diversified Consumer Services
51-250
Founded 1945

Description

  • Define and implement security strategies for applications, including systems that integrate LLMs and generative AI components.
  • Collaborate with development, engineering, and product teams to embed security practices early in the software lifecycle.
  • Review architecture, code, and designs to identify vulnerabilities and security issues.
  • Define guardrails and security standards for LLM-based applications, addressing risks such as prompt injection, insecure output handling, data leakage, excessive agent autonomy, and denial-of-wallet abuse.
  • Establish guidelines for the safe use of AI-assisted development tools across engineering teams.
  • Develop and promote security standards and best practices for the development organization.
  • Provide technical guidance and security training to development teams.
  • Use CI/CD validation tools such as SAST, DAST, SCA, and secret scanning.
  • Monitor emerging security threats and continuously update protections, including threats affecting AI systems.
  • Develop creative solutions for complex security problems that balance business needs and risk.
  • Investigate threats in corporate and production environments using security experience and intuition.
  • Participate in incident analysis and response, supporting continuous improvement of security processes and practices.

Requirements

  • Experience with common attack vectors.
  • Experience performing threat modeling.
  • Experience protecting APIs and mobile applications.
  • Knowledge of cloud security fundamentals and basic cloud services in AWS, Azure, or GCP.
  • Ability to work within multidisciplinary teams using agile methodologies.
  • Familiarity with security risks in LLM and generative AI applications, including OWASP Top 10 for LLM Applications and MITRE ATLAS.
  • Ability to read and communicate in English.
  • Strong communication skills with the ability to translate complex problems into accessible language.
  • Ability to work autonomously.
  • Ability to use influence and negotiation to drive teams toward secure architectures and issue remediation.
  • Initiative to seek or request information when needed.
  • Bachelor’s degree completed or in progress in Information Security, Computer Science, Information Systems, Software Engineering, or related fields.
  • Passion for learning and thriving in a dynamic, constantly changing environment.
  • Preferred: incident response experience focused on root-cause analysis.
  • Preferred: experience in regulated financial projects involving Bacen, PCI, SOX, or similar requirements.
  • Preferred: solid programming knowledge.
  • Preferred: hands-on experience with threat modeling and defining controls for production LLM applications such as chatbots, copilots, agents, and RAG.
  • Preferred: experience securing APIs that expose AI models, including direct and indirect prompt injection, structured output validation, and authorization controls for function calling and tool use.
  • Preferred: experience defining policies and controls for enterprise use of generative AI tools, including prevention of data and intellectual property leakage.
  • Preferred: knowledge of emerging AI governance and security frameworks such as NIST AI RMF and ISO/IEC 42001.

Benefits

  • Health and dental insurance.
  • 24/7 virtual hospital access.
  • Meal voucher and/or food voucher.
  • Remote work allowance for remote roles.
  • Flexible working hours.
  • Education benefit with access to books, podcasts, training, and video lessons through internal learning platforms.
  • Wellhub membership.
  • TotalPass membership.
  • Childcare assistance.
  • Profit sharing bonus (PLR).
  • Life insurance.
  • Transportation voucher for onsite roles.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Application Architect (Oracle Fusion Sales) - Mandarin fluency is required

Apex IT 251-1K Internet Software & Services

Apex IT is hiring an Oracle Fusion Sales Application Architect to lead solution delivery for global enterprise clients, with a focus on Taiwan-based stakeholders and customer projects.

15 hours, 1 minute ago

Sr. Application Analyst

Anaplan 1K-5K Internet Software & Services

Anaplan is hiring a Sr. Application Analyst to lead its Finance and Workforce Center of Excellence in building and scaling Finance Applications for planning, forecasting, and reporting.

Agile UX Design
15 hours, 31 minutes ago

DevSecOps

Cato Networks 251-1K Diversified Telecommunication Services

Cato Networks is hiring an Application Security Engineer (DevSecOps) to embed security across its cloud-based software development lifecycle and help R&D teams deliver secure applications at scale.

Agile AWS CI/CD DevSecOps Docker Go Java Kubernetes Microservices Network Security Python Terraform
1 day, 14 hours ago

Technical Architect/Solution Architect (Strong Knowledge in ReactJS)

3Pillar Global 1K-5K Internet Software & Services

3Pillar is hiring an Architect to serve as the primary technical expert for enterprise software solutions, owning high-level design decisions and technical standards across the stack.

Agile AWS Azure C# CI/CD GCP .NET React REST API
1 day, 15 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers