HighLevel

HighLevel

HighLevel provides an all-in-one sales and marketing platform that agencies can white label and resell, offering tools and resources designed to help businesses consolidate their marketing efforts and achieve their growth objectives.

Internet Software & Services
251-1K
Founded 2018
$60M raised

Description

  • Lead application security initiatives across web, mobile, API, microservices, and cloud-native products.
  • Conduct architecture reviews, threat modeling, secure code reviews, penetration testing, and hands-on security assessments.
  • Identify and remediate risks involving authentication, authorization, tenant isolation, business logic, data protection, and API security.
  • Define security standards, engineering guardrails, secure design patterns, and DevSecOps requirements.
  • Improve CI/CD security testing using SAST, DAST, SCA, secret scanning, container scanning, and Infrastructure as Code scanning.
  • Lead security reviews and adversarial testing for LLM applications, AI agents, RAG systems, machine learning services, and AI integrations.
  • Test AI risks including prompt injection, jailbreaking, data disclosure, insecure tool use, excessive agency, model abuse, and supply-chain threats.
  • Develop repeatable AI security methodologies, playbooks, automation, and test cases using tools such as Garak or PyRIT.
  • Produce security reports with evidence, risk ratings, business impact, and remediation guidance.
  • Collaborate with engineering, product, infrastructure, and AI/ML teams while mentoring engineers and promoting security awareness.

Requirements

  • 8+ years of cybersecurity experience in application security, product security, penetration testing, or security engineering.
  • 1–3 years of AI Security experience involving AI/ML security, adversarial testing, or security-focused AI research.
  • Experience with threat modeling, architecture reviews, secure code reviews, penetration testing, and vulnerability validation.
  • Strong knowledge of web, mobile, API, cloud-native, OWASP, and business-logic security.
  • Knowledge of OAuth 2.0, OIDC, JWT, SAML, and modern access-control models.
  • Hands-on DevSecOps experience with CI/CD security automation, SAST, DAST, SCA, secret scanning, containers, and Infrastructure as Code.
  • Practical experience with Docker, Kubernetes, microservices, and cloud security.
  • Experience securing or assessing LLM applications, RAG systems, AI agents, machine learning models, or AI-enabled products.
  • Familiarity with OWASP LLM guidance, MITRE ATLAS, NIST AI RMF, and AI security threats.
  • Programming or scripting proficiency in Python, Go, JavaScript, Bash, or a similar language; strong written and verbal communication skills.
  • Preferred: SaaS application security leadership, AI red teaming, security automation, security research, open-source or bug bounty contributions, or certifications such as OSCP, OSWE, GWAPT, GIAC, CISSP, or an AI Security credential.

Benefits

  • Remote-first work environment.
  • Equal opportunity employer.
  • Global team spanning 15+ countries.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Professional Services Technical Architect - Security

GitLab 1K-5K Internet Software & Services

GitLab is hiring a Senior Professional Services Technical Architect, Security to design and lead secure enterprise DevSecOps solutions for Professional Services clients across AMER, from pre-sales scoping through implementation and enablement.

Ansible CI/CD DevSecOps GitLab Jenkins SonarQube Terraform
7 hours, 7 minutes ago

Application Security Engineer II - Contract ( 6 months )

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring a remote Application Security Engineer to triage and validate vulnerability submissions for client bug bounty programs, assess severity, and coordinate responses with researchers and customers.

Burp Suite Nmap
5 days, 6 hours ago

Principal Consultant - ICS/OT Cybersecurity

Dragos 251-1K Professional Services

Dragos is seeking a Singapore-based Principal Consultant to lead high-impact OT/ICS cybersecurity engagements and shape long-term security strategies for critical infrastructure organizations across APAC.

Cybersecurity SIEM
6 days, 7 hours ago

Cyber Security Engineer (Application Security)

TherapyNotes 51-250 Health Care Providers & Services

TherapyNotes is seeking a hands-on Cyber Security Engineer to own application security across the SDLC and CI/CD pipeline for its healthcare-regulated behavioral health SaaS platform.

AWS Azure CI/CD Cybersecurity GitHub Actions HIPAA SIEM Terraform
6 days, 8 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers