Senior Engineer, Application Security
About the role
Cvent is seeking a senior, builder-minded Application Security Engineer to architect and own AI-first security automation. This role will own product security for the teams it partners with, driving their threat modeling, design reviews, and risk decisions end to end.
Responsibilities
- Architect and own AI-first security automation — design agentic systems and skills that take security work from intake through analysis to logged risk and published findings, with minimal manual handoff.
- Lead the development of security agents and AI tooling — define the architecture for LLM-integrated workflows via APIs and MCP connectors, set patterns for tool/function design, and decide build-vs-buy across the toolchain.
- Drive AI-assisted threat modeling at scale — benchmark custom solutions against off-the-shelf agents, embed methodologies into automation, and make pentest scoping decisions defensible and repeatable.
- Set the standard for AI feature security — define coverage models and assessment criteria for GenAI and AI/ML features, applying the OWASP LLM Top 10, OWASP AI Testing Guide, and MITRE ATLAS to real product risk.
- Own integration and scaling of SAST, DAST, and SCA across CI/CD, including AI-assisted triage layers that cut noise and accelerate remediation.
- Perform and lead deep secure design reviews, code reviews, threat modeling, and penetration testing for complex and high-risk systems, including cloud-native and AI-driven architectures.
- Own product security for an assigned product area or portfolio — serve as the accountable security partner for those teams, drive their threat modeling, design reviews, and risk decisions end to end, and own the security posture and remediation outcomes for that scope.
- Mentor Engineer II and mid-level teammates, review their automation and findings, and grow the team's AI and AppSec capability.
- Communicate risk clearly to both engineering and leadership audiences, and support compliance efforts across ISO 27001, SOC 2, and PCI.
Requirements
- 5+ years of hands-on experience in application security or secure software development, with demonstrated technical ownership.
- Strong scripting/programming skills — the ability to design and build non-trivial internal tools and automation in Python, JavaScript/TypeScript, or Bash.
- Proven experience integrating security tooling into CI/CD and the SDLC, and improving it over time.
- Strong familiarity with cloud platforms (AWS preferred; GCP or Azure acceptable) and cloud-native security, including securing applications built with AWS CDK / IaC.
- Proficiency with security testing and cloud security tools (e.g., Burp Suite, Checkmarx, Mend, Veracode, Fortify, ZAP, Wiz).
- Deep understanding of the OWASP Top 10, CWE, SANS Top 25, secure coding practices, and web/API vulnerability classes.
- Demonstrated end-to-end ownership of at least one security tool, automation, or agentic/LLM-integrated workflow that is used in production or relied on by a team — designed, shipped, and depended on by others.
Qualifications
- Bachelor's degree in Computer Science, Information Systems, or a related field.
- Experience with AI and machine learning concepts and technologies.
- Experience with security testing frameworks and tools.
- Experience with cloud platforms and security best practices.
- Experience with security tooling and automation.
Skills
- Strong problem-solving and analytical skills.
- Excellent communication and interpersonal skills.
- Ability to work independently and as part of a team.
- Experience with agile methodologies and DevSecOps.
Benefits
We offer a competitive benefits package, including health insurance, retirement plans, and paid time off. We are also committed to providing a safe and inclusive workplace for all employees.
Pay
The estimated base salary range for new hires into this role is $120,000 - $160,000 annually + bonus depending on factors such as job-related knowledge, relevant experience, and location. We also offer a comprehensive benefits package, details of which can be found here.
Schedule
This role is hybrid, with 2 days in the office per week.