09 Sep
|
LeadSquared
|
Karnataka
09 Sep
LeadSquared
Karnataka
Job DescriptionLead – AI and Application security NThe RolenWe are looking for an AI and Application Security Engineer with strong hands-on experience in secure SDLC practices, application security testing, red teaming, code review, container/image review, release security testing, SAST, and AI implementation security reviews. The role involves identifying security risks across applications, APIs, AI-enabled features, and cloud-hosted workloads, and partnering with engineering teams to implement scalable, practical, and measurable security improvements. NResponsibilitiesn N Perform application security assessments across web applications, APIs, mobile applications, services, and integrations as part of the secure SDLC. N Conduct release security testing, including manual testing, SAST result validation, vulnerability verification, and security sign-off support before production releases. N Perform secure code reviews and identify vulnerabilities related to authentication, authorization, input validation, session management, insecure dependencies, business logic flaws, and API security. N Conduct container and image security reviews, including dependency, package, secret, configuration, and vulnerability checks before deployment. N Perform AI implementation security reviews for AI-enabled features, LLM integrations, prompt flows, data exposure risks, model misuse scenarios, and security control gaps. N Plan and execute red teaming and adversarial testing activities for applications, APIs, and AI-enabled workflows, including abuse-case testing and AI-driven security testing techniques. N Use tools such as Burp Suite, Nessus, SAST platforms, dependency scanners,
and other application security testing tools to identify, validate, and track vulnerabilities. N Apply OWASP Top 10, OWASP API Security Top 10, STRIDE threat modeling, and secure design principles to assess application and AI implementation risks. N Work closely with engineering, DevOps, product, and security teams to prioritize vulnerabilities, define remediation actions, and verify fixes. N Maintain clear documentation of findings, risk ratings, remediation recommendations, vulnerability status, and release security outcomes. NnRequirementsn N 3–5 years of relevant experience in application security, product security, secure SDLC, DevSecOps, or AI/application security testing. N Bachelor's degree in computer science, information security, engineering, or a related field. N Mandatory hands-on experience with SDLC security testing, release security testing, SAST, secure code reviews, and vulnerability validation. N Mandatory experience with application security testing tools such as Burp Suite and vulnerability assessment tools such as Nessus. N Robust working knowledge of OWASP Top 10, OWASP API Security Top 10, STRIDE threat modeling, secure coding practices, and application risk assessment. N Hands-on experience in red teaming, abuse-case testing, adversarial testing, or offensive security testing for applications, APIs, or AI-enabled systems. N Experience reviewing AIimplementations, including LLM integrations, prompt security, data leakage risks, insecure AI workflows, model misuse scenarios, and AI-specific threat vectors. N Experience with container/image security reviews, dependency scanning, package vulnerability checks, and secrets/configuration review. N
📌 Lead - Ai And Application Security (Karnataka)
🏢 LeadSquared
📍 Karnataka