19 Aug
|
LeadSquared
|
Bengaluru
19 Aug
LeadSquared
Bengaluru
Lead – AI and Application security The Role
We are looking for an AI and Application Security Engineer with solid hands-on experience in secure SDLC practices, application security testing, red teaming, code review, container/image review, release security testing, SAST, and AI implementation security reviews. The role involves identifying security risks across applications, APIs, AI-enabled features, and cloud-hosted workloads, and partnering with engineering teams to implement scalable, practical, and measurable security improvements.
Responsibilities
- Perform application security assessments across web applications, APIs, mobile applications, services, and integrations as part of the secure SDLC.
- Conduct release security testing, including manual testing, SAST result validation, vulnerability verification, and security sign-off support before production releases.
- Perform secure code reviews and identify vulnerabilities related to authentication, authorization, input validation, session management, insecure dependencies, business logic flaws, and API security.
- Conduct container and image security reviews, including dependency, package, secret, configuration, and vulnerability checks before deployment.
- Perform AI implementation security reviews for AI-enabled features, LLM integrations, prompt flows, data exposure risks, model misuse scenarios, and security control gaps.
- Plan and execute red teaming and adversarial testing activities for applications, APIs, and AI-enabled workflows, including abuse-case testing and AI-driven security testing techniques.
- Use tools such as Burp Suite, Nessus, SAST platforms, dependency scanners,
and other application security testing tools to identify, validate, and track vulnerabilities.
- Apply OWASP Top 10, OWASP API Security Top 10, STRIDE threat modeling, and secure design principles to assess application and AI implementation risks.
- Work closely with engineering, DevOps, product, and security teams to prioritize vulnerabilities, define remediation actions, and verify fixes.
- Maintain clear documentation of findings, risk ratings, remediation recommendations, vulnerability status, and release security outcomes.
Requirements
- 3–5 years of relevant experience in application security, product security, secure SDLC, DevSecOps, or AI/application security testing.
- Bachelor’s degree in computer science, information security, engineering, or a related field.
- Mandatory hands-on experience with SDLC security testing, release security testing, SAST, secure code reviews, and vulnerability validation.
- Mandatory experience with application security testing tools such as Burp Suite and vulnerability assessment tools such as Nessus.
- Strong working knowledge of OWASP Top 10, OWASP API Security Top 10, STRIDE threat modeling, secure coding practices, and application risk assessment.
- Hands-on experience in red teaming, abuse-case testing, adversarial testing, or offensive security testing for applications, APIs, or AI-enabled systems.
- Experience reviewing AI implementations, including LLM integrations, prompt security, data leakage risks, insecure AI workflows, model misuse scenarios, and AI-specific threat vectors.
- Experience with container/image security reviews, dependency scanning, package vulnerability checks, and secrets/configuration review.
📌 Lead - AI and Application Security (Bengaluru)
🏢 LeadSquared
📍 Bengaluru