Application Security Engineer, AI & Automation [SK-12281]
About the role
Aquent is partnering with a leading financial industry innovator dedicated to securing its vast software ecosystem and pioneering the future of digital security. This organization integrates cutting-edge AI and automation into its security operations, creating a dynamic environment where innovation drives impact. They are redefining how security is managed by embracing intelligent, automated solutions that protect critical assets and foster a secure development landscape.
This role offers the opportunity to shape the future of software defense by engineering next-generation AI-driven security automation. You will transform how vulnerabilities are identified, triaged, and remediated, moving beyond manual processes to build sophisticated, LLM-powered security workflows. Your work will intersect traditional Application Security, Software Supply Chain Security, and Frontier AI, enabling you to evaluate, implement, and secure AI-assisted developer tooling.
Responsibilities
- Test, implement, and optimize application security tooling that leverages frontier LLMs for vulnerability identification, code reasoning, triage acceleration, and automated remediation.
- Provide unified triage coverage across SCA, SAST, and DAST findings.
- Lead the rapid assessment and routing of threat intelligence escalations and critical patch events.
- Strengthen open-source dependency selection, package intake, and SBOM visibility.
- Build guardrails to detect malicious packages and enforce security policies across developer pipelines.
- Assess and secure developer environments, including IDEs, plugins/extensions, package managers, and AI coding assistants against malicious code and unsafe configurations.
- Help execute technical proofs-of-value, data handling reviews, and model output evaluations required to safely onboard new AI capabilities across the enterprise.
Requirements
- 3+ years of hands-on experience in Application Security, with deep familiarity across the vulnerability lifecycle (SCA, SAST, DAST, and manual verification).
- Strong engineering fundamentals with scripting languages (e.g., Python, Go), APIs, CI/CD pipelines (e.g., GitHub Actions, GitLab CI), and developer tool integrations.
- Practical familiarity or hands-on experimentation with frontier models (LLMs), AI coding assistants (e.g., Copilot), prompt engineering, or AI orchestration frameworks.
- Experience securing software supply chains, package managers, and third-party dependencies against modern attack vectors.
- Ability to translate complex cryptographic or technical vulnerabilities into clear, actionable remediation guidance for software engineering teams.
Preferred Skills
- Contributions to open-source security tools or AI/LLM security projects (e.g., OWASP Top 10 for LLMs).
- Experience building custom integrations or LLM agents to automate security analyst workflows.
Benefits
- Health benefit contributions.
- Retirement plans with match.
- Flexible spending accounts.