Security Solutions Lead Consultant - AI Application Security
About the Company
World Wide Technology (WWT) strives to make a new world happen by benefiting clients, partners, people, and communities globally. Founded in 1990, WWT combines strategy, deep technical expertise, and world-class partnerships to help organizations design, build, and scale intelligent AI, digital, cybersecurity, cloud, and infrastructure solutions. Through its Advanced Technology Center (ATC), WWT enables clients to test and validate innovative technology before deploying solutions at scale. With over 14,000 team members and 60+ global locations, WWT’s culture is recognized for innovation and trust, making it a great place to work.
About the Team
Solutions Consulting & Engineering (SC&E) is a customer-focused and solutions-led organization delivering end-to-end and emerging solutions to drive satisfaction, profitability, and growth. The team combines business acumen with full-stack technical expertise to develop innovative solutions for clients' most complex challenges.
About the Role
WWT’s Global Security practice is hiring a Lead Consultant in AI application security, a client-facing advisory role. You will work directly with client security organizations—including CISOs, security architects, application security leads, and GRC/risk teams—to assess and strengthen how their security programs address AI adoption across the application portfolio. The role focuses on closing gaps in application security programs as enterprises integrate model APIs, retrieval pipelines, and agent frameworks.
Responsibilities
- Deliver advisory engagements on securing AI-enabled applications, including readiness/maturity assessments, threat modeling workshops, governance reviews, gap analyses, and prioritized remediation roadmaps.
- Advise client security teams on the full attack surface of modern applications, covering established areas (API security, dependencies, secrets, CI/CD) and AI-specific exposures (prompt injection, model/data supply chain compromise, data poisoning, unsafe output handling, agent tool misuse).
- Guide teams in extending existing programs (threat modeling, secure code review, penetration testing, vulnerability management) to cover models, RAG pipelines, vector stores, and agent frameworks.
- Advise on application security program design, including secure SDLC, tooling strategy (SAST, DAST, SCA, ASPM), API security, software supply chain integrity, and secrets/non-human identity hygiene.
- Deliver recommendations and reference patterns for client engineering teams to implement.
- Run workshops and working sessions to align security, engineering, and governance stakeholders.
- Provide detailed guidance for practitioners and clear, defensible summaries for executives and boards.
- Lead delivery workstreams within larger engagements or manage smaller engagements end-to-end, including scope and client expectations.
- Anchor recommendations in frameworks like OWASP (AppSec/LLM Top 10), NIST AI RMF, ISO/IEC 42001, MITRE ATLAS, NIST CSF, and ISO 27001.
- Contribute to practice IP, including assessment methodologies, control catalogs, and workshop kits.
- Support pursuits with scoping input, proposal content, and SOW reviews.
- Publish and present thought leadership (blogs, client briefings, conference talks, internal enablement).
- Mentor consultants building expertise in AI application security.
- Engage with client security organizations and coordinate with engineering, data science, and platform teams.
- Collaborate with WWT peers in cloud security, identity, and infrastructure to provide a unified client perspective.
Requirements
- 7+ years in cybersecurity, with depth in application security and a working grasp of AI’s impact on security (or equivalent expertise in AI security with fluency in AppSec).
- Client-facing consulting or advisory experience; comfortable briefing executives and defending findings under scrutiny.
- Working knowledge of AI-enabled applications, including model APIs, RAG, vector stores, agent frameworks, and MCP-style tool integrations.
- Familiarity with NIST AI RMF, ISO/IEC 42001, OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST CSF, ISO 27001, or CIS Controls.
- Experience advising on secure SDLC, AppSec tooling, and software supply chain security in enterprise environments.
- Strong writing skills; deliverables are the primary product in advisory work.
Nice to Have
- CISSP, CSSLP, CCSP, AIGP, or GIAC certifications.
- Prior work in regulated industries (financial services, healthcare, energy).
Pay
A reasonable estimate of the current base pay range for this position is $137,200 to $171,500 annually. Actual salary will vary based on factors such as location, experience, skill set, performance, licensure, certification, and business needs. Certain positions may also be eligible for variable incentive compensation (e.g., bonuses or commissions).
Benefits
- Health and Wellbeing: Medical, dental, and vision care; onsite health centers (MO & IL); employee assistance program; wellness program.
- Financial Benefits: Competitive pay; profit sharing; 401k plan with company matching; life and disability insurance; flexible spending accounts; tuition reimbursement.
- Paid Time Off: PTO, holidays, parental leave, medical leave, military leave, bereavement, Day of Caring.
- Additional Perks: Family planning benefits; nursing mothers benefits; voluntary legal/supplemental insurance; pet insurance; employee discount program.
For more details, visit wwt.com/us-benefits.