
Principal Application & AI Security Engineer
Det Norske Veritas (DNV)5 days ago
Houston, TX, USAStaff+
Base Salary
$175k - $225k/yr
Responsibilities
- Design and implement secure patterns for applications, APIs, cloud platforms, AI-agent systems, and software and AI supply chains.
- Build automated security controls covering dependency integrity, SCA, SAST, DAST, build provenance, artifact security, secrets protection, containers, infrastructure as code, and software or AI bills of materials.
- Implement policy-as-code, authorization enforcement, data-access guardrails, secure defaults, reusable reference implementations, risk-based quality gates, and documented exception paths.
- Review source code, APIs, and application designs for authentication, authorization, session management, input handling, data-access, and multi-tenant isolation weaknesses.
- Conduct authorized application, API, and AI security testing, including manual business-logic and trust-boundary testing.
- Work with engineers to remediate root causes, validate fixes, create regression tests, and prevent recurring vulnerability classes.
- Establish vulnerability triage and remediation practices with exploitability analysis, accountable ownership, retesting, closure evidence, and escalation.
- Secure AI agents through least-privilege identities, governed tool and data access, prompt-injection defenses, runtime policies, approval requirements, resource limits, and tamper-resistant auditability.
- Lead high-risk threat modeling and architecture reviews for complex, multi-tenant, cloud-native, event-driven, and AI-enabled systems.
- Develop reusable secure patterns for microservices, APIs, event-driven systems, containers, Kubernetes, cloud services, and agentic AI applications.
- Mentor senior engineers and technical leaders and represent application and AI security in technical, executive, customer, audit, and assurance discussions.
- Serve as the application and AI security technical lead during relevant incidents and support investigation, containment, recovery, remediation validation, and lessons learned.
Requirements
- 8+ years of experience in application security or secure software engineering with responsibility for production software and security controls.
- A degree in computer science, cybersecurity, engineering, or a related field is welcome but not required; equivalent practical experience is fully recognized.
- Deep application and API security expertise in authentication, authorization, session management, data protection, input validation, and multi-tenant isolation.
- Ability to review, write, test, and improve production-quality code in one or more languages used in cloud applications, automation, and security engineering.
- Experience leading source-code reviews, application and API security testing, threat modeling, and architecture reviews for complex systems.
- Experience integrating and tuning security tooling in CI/CD and converting findings into risk-based automated controls.
- Production experience with a major cloud provider such as Azure or AWS, plus understanding of cloud identity, platform services, and the shared-responsibility model.
- Ability to set technical direction, create reusable capabilities across products, and influence senior stakeholders without formal authority.
- Ability to communicate material security risk clearly to engineers, product leaders, executives, customers, and assurance stakeholders.
- Strong written and verbal English communication skills.
- Practical AI-agent security experience and experience applying AI to security testing, code analysis, vulnerability triage, or security automation are preferred.
- Experience securing distributed, event-driven, multi-tenant, or critical enterprise systems is preferred.
- Container, Kubernetes, infrastructure-as-code, software-supply-chain security, incident response, vulnerability investigation, exploit validation, and remediation verification experience are preferred.
- Hands-on depth with Veracode, Burp Suite Professional, or equivalents and familiarity with OWASP application, API, and agentic AI security guidance are preferred.
- OSCP, GIAC GWAPT, GWEB, GCSA, AZ-500, AWS Certified Security - Specialty, CISSP, or CCSP credentials are a plus.
- Pre-employment drug and background screening is required.
Benefits
- Generous paid time off including vacation, sick days, company holidays, and personal days.
- Multiple medical and dental plans, vision benefits, FSA, dependent care and commuter benefits, and a company-seeded HSA.
- Employer-paid therapist-led virtual care through Talkspace.
- 401(k) with company match, company-provided life insurance, and short- and long-term disability benefits.
- Education reimbursement, career advancement opportunities, charitable matched giving, volunteer rewards, and paid volunteer time off.
- Hybrid schedule based in Houston, TX or Oakland, CA, typically working three days per week from a DNV office or client location/site.
- Benefits vary based on position, tenure, location, and employee election.