This role focuses on leading and enforcing secure development practices across a broad technology stack, including Java, React, Node.js, Python (Django, FastAPI), JavaScript, HTML, and C++. You will be responsible for conducting thorough manual and automated code reviews, establishing security release gates, and defining remediation standards to ensure robust application security. Early involvement in secure design reviews and threat modeling will be essential to mitigate risks before implementation. Additionally, you will oversee the security of AI models, integrations, and data pipelines, addressing risks such as prompt injection and data leakage, while ensuring compliance with internal policies and emerging regulations.
Key Responsibilities
- Own and enforce secure development standards for all internally built applications, platforms, automation, and tooling.
- Perform and oversee manual and automated code reviews, including static, dynamic, dependency, and supply chain analyses tailored to specific languages and frameworks.
- Establish security release gates requiring approval before software or AI systems are delivered or promoted internally.
- Define remediation standards and risk acceptance criteria for security findings.
- Conduct secure design reviews and application threat modeling during early development phases.
- Review AI models, agents, prompts, integrations, and data pipelines for security, privacy, and misuse risks.
- Perform AI-based security analysis to identify and mitigate prompt injection vulnerabilities and AI-driven data leakage risks.
- Evaluate AI integrations for exposure of sensitive data and enforce controls to prevent unauthorized data exfiltration.
- Ensure AI systems comply with internal governance, customer contractual obligations, and regulatory expectations.
- Collaborate with engineering and data teams to implement secure AI development patterns, including data protection, access controls, and auditability.
- Integrate security tooling into CI/CD pipelines such as Jenkins and GitHub Enterprise, including SAST, DAST, dependency scanning, container scanning, and secrets detection.
- Promote shift-left security practices and reduce late-stage security blockers through developer enablement.
- Work closely with DevOps and Platform teams on secure delivery pipelines and runtime controls.
- Secure data persistence and messaging layers including RabbitMQ, Kafka, Cassandra, MongoDB, and Snowflake by ensuring encryption, access control, and secure configuration.
- Protect intellectual property by ensuring secure design, code custody, and controlled access to source repositories.
- Support compliance efforts across frameworks such as SOC 2, ISO 27001, and customer-specific security requirements.
- Produce audit-ready artifacts including risk assessments, code review records, and security sign-offs.
- Serve as the primary application security escalation point for engineering and leadership.
- Mentor developers and engineers on secure coding practices and threat modeling across multiple languages and frameworks.
- Provide executive-level reporting on application and AI security posture, trends, and risk exposure.
Required Qualifications
- Minimum of 8 years’ experience in application security, DevSecOps, or secure software development.
- Strong hands-on experience reviewing code in one or more modern languages such as Java, JavaScript/TypeScript, Python, or C++.
- Proven expertise securing APIs, web applications, microservices, and cloud-native platforms on Azure and AWS.
- Experience integrating security controls into CI/CD pipelines and modern DevOps workflows, specifically with Jenkins and GitHub Enterprise.
- Deep understanding of common vulnerabilities and attack patterns including OWASP Top 10, API security risks, and supply chain threats.
- Demonstrated experience with AI security analysis, including identifying prompt injection vectors and detecting AI-based data leakage.
- Experience securing data storage and messaging technologies such as RabbitMQ, Kafka, Cassandra, MongoDB, and Snowflake.
- Ability to balance rigorous security requirements with delivery velocity in a customer-facing Managed Services Provider (MSP) environment.
Preferred Qualifications
- Experience securing AI/ML systems, automation platforms, or data-driven applications.
- Familiarity with containerized environments and orchestration.
- Background in a Managed Services Provider (MSP) or SaaS organization with external customer delivery obligations.
- Knowledge of regulatory and compliance frameworks impacting software and data security.
- Hands-on experience with Django and FastAPI frameworks.
- Practical experience with AI security tooling, red teaming large language models, or implementing guardrails against prompt-based attacks and data exfiltration.
Key Competencies
- Secure Software Architecture
- Application and API Security
- AI Security and Governance
- AI Threat Modeling including Prompt Injection and Data Leakage
- DevSecOps Tooling and Automation
- Cross-Functional Leadership
XTIUM is committed to equal opportunity employment, fostering a diverse and inclusive workplace.