Base Salary
$120k - $160k/yr
Responsibilities
- Architect and own AI-first security automation that takes security work from intake through analysis, risk logging, and published findings.
- Define architectures and design patterns for security agents, LLM-integrated workflows, APIs, MCP connectors, and security tooling decisions.
- Drive automated threat modeling using STRIDE, PASTA, LINDDUN, and MITRE ATT&CK, including defensible penetration-testing scoping.
- Define security coverage and assessment criteria for GenAI and AI/ML features using the OWASP LLM Top 10, OWASP AI Testing Guide, and MITRE ATLAS.
- Own the integration and scaling of SAST, DAST, and SCA across CI/CD, including AI-assisted vulnerability triage.
- Perform and lead secure design reviews, code reviews, threat modeling, and penetration testing for complex cloud-native and AI-driven systems.
- Own product security for an assigned product area, including threat modeling, design reviews, risk decisions, security posture, and remediation outcomes.
- Mentor Engineer II and mid-level teammates and communicate security risk to engineering and leadership.
- Support compliance efforts across ISO 27001, SOC 2, and PCI.
Requirements
- 5+ years of hands-on experience in application security or secure software development with demonstrated technical ownership.
- Ability to design and build non-trivial internal tools and automation using Python, JavaScript/TypeScript, or Bash.
- Experience integrating and continuously improving security tooling across CI/CD and the SDLC.
- Strong familiarity with AWS, GCP, or Azure and cloud-native security, including securing applications built with AWS CDK and infrastructure as code.
- Proficiency with tools such as Burp Suite, Checkmarx, Mend, Veracode, Fortify, ZAP, and Wiz, along with sound judgment about manual versus automated testing.
- Deep understanding of the OWASP Top 10, CWE, SANS Top 25, secure coding practices, and web/API vulnerability classes.
- End-to-end production ownership of at least one security tool, automation, or agentic/LLM-integrated workflow relied on by a team.
- Preferred experience includes securing AI/ML pipelines, adversarial ML, prompt injection, agent-misuse risk, DevSecOps, infrastructure-as-code security, or software supply-chain security.
- Preferred certifications include OSWE, OSCP, AWS Security – Specialty, or CISSP.
Benefits
- Competitive benefits package.
- Hybrid work arrangement with 2 days in the office.
- Base salary range of $120,000-$160,000 annually plus bonus.
- Path to grow into staff-level or lead roles.
Tech Stack
Categories
About Cvent
Join #CventNation! www.cvent.com/careers What We Do: Cvent is a global market-leading meetings, events, & hospitality technology provider. Our Mission: To bring people together, power the human connection and transform the meetings & events industry through innovative technology. Who We Are: With 5,500+ employees & 30,000 customers, we're one of the largest event technology companies in the world, & we're always looking for the next generation of Cventers to join #CventNation! Cvent is consistently recognized as a Top Workplace by The Washington Post, Washington Business Journal, & certified as a Great Place to Work in the US, UK, & India, among other regional & international accolades. **Career Fraud Alert: In today's digital-first world, fraudulent job offers and hiring manager impersonations, often via social media or chat/messaging apps, continue to increase. To protect yourself, verify all communications come from a legitimate Cvent email (name@cvent.com) and be cautious of requests for personal information, unsolicited messages, and offers via chat or social media. If you suspect fraud, contact HRHelp@cvent.com immediately and apply for positions directly through our careers site at https://careers.cvent.com. Your safety and security are our priority.
