Manager, Application Security, DevSecOps
KPMG US · Stamford, CT · 1 wk ago
Hybrid$127k/yrFull-time
Responsibilities
- Establish, manage, and maintain AI-specific application security standards, evaluation frameworks, and required security controls/baselines to address risks like data leakage, prompt injection, insecure agent actions, IP exposure, and supply-chain threats
- Own the end-to-end AppSec evaluation process for AI tools and use cases, covering intake, architectural assessments, data flows, risk documentation, and formally accepted exceptions
- Act as the primary liaison between application teams and Information Security to embed AI AppSec requirements into DevSecOps processes and promote secure-by-design practices
- Provide security consulting and subject-matter expertise to development and platform teams on secure AI design, integrations, operational models, and compensating controls
- Present AI AppSec evaluation findings, risk decisions, metrics, dashboards, and recommendations to both technical and executive stakeholders to track tool coverage and control maturity
- Maintain awareness of the emerging AI threat landscape while managing evaluation outcomes, approved tool lists, residual risks, and the consistent adoption of approved security controls
Qualifications
- Minimum six years of recent experience in application security, DevSecOps practices, secure software engineering, and SDLC governance, including CI/CD pipelines and security tooling integration
- Bachelor's degree from an accredited college or university is preferred; minimum of a high school diploma or GED is required; the following preferred certifications: CISSP, CISM, GWAPT, GPEN, CEH, GWEB, or equivalent are preferred
- Strong understanding of application security principles, common security standards and frameworks (such as the OWASP Top 10 and secure coding standards), security controls, and risk management within enterprise environments
- Solid knowledge of AI-related application security risks, including prompt injection, data leakage, IP protection, insecure automation, and third-party AI supply-chain risks
- Experience defining and enforcing security standards, baselines, and evaluation criteria for applications or platforms, with preferred experience with large global multi-culture environments; moderate to expert knowledge of cloud platforms (with a preference for Azure), cloud security architecture, and secure service design
- Strong written and verbal English communication skills, with the ability to clearly articulate risk, evaluation outcomes, and security requirements to both technical and executive audiences