State Street logo
State StreetPosted 1 week ago
EXPIRED

Application Security Engineer - Agentic AI Security Engineer, AVP

HybridBengaluru, Karnataka, India or Hyderabad, Telangana, India

Full TimeSenior LevelEnterprise

Job Summary

Define and execute the Agentic AI Security Scanning strategy by integrating AI-powered code analysis and vulnerability discovery into DevSecOps programs. Design, deploy, and support an enterprise AI Harness platform leveraging frontier models to automate security testing and developer enablement. Partner with Software Engineering, Cloud, and Security teams to integrate AI-based capabilities into CI/CD pipelines and workflows. Develop AI agents that identify vulnerabilities, analyze code quality, and recommend remediation actions while establishing governance controls for responsible AI use. Deliver dashboards demonstrating security coverage, platform effectiveness, and remediation outcomes. Establish operational standards and support audits by providing evidence of AI governance and security controls.

Required Qualifications

  • Application Security (AppSec)
  • DevSecOps
  • Secure Software Development Lifecycle (SSDLC)
  • Artificial Intelligence (AI)
  • Large Language Model (LLM) technologies
  • hands-on experience implementing AI-driven security solutions
  • integrating AI agents into software development workflows
  • applying advanced code analysis techniques to identify and remediate security vulnerabilities
  • designing, implementing, and supporting the organization's Agentic AI Harness platform
  • enhance application security testing
  • vulnerability discovery
  • remediation guidance
  • developer enablement
  • deep technical expertise
  • strong security mindset
  • passion for applying emerging AI technologies to modernize and scale application security capabilities across the enterprise
  • Help define and execute the organization's Agentic AI Security Scanning strategy
  • integrating AI-powered code analysis, vulnerability discovery, and remediation capabilities into the broader Application Security and DevSecOps programs
  • Design, deploy, and support an enterprise AI Harness platform leveraging frontier models, agents, and orchestration frameworks
  • automate security testing activities
  • Partner with Software Engineering, Cloud Engineering, DevOps, Platform Engineering, and Security teams
  • integrate AI-based security capabilities into CI/CD pipelines and developer workflows
  • Evaluate, onboard, and operationalize emerging AI security technologies and platforms supporting secure software delivery
  • Develop AI agents capable of identifying security vulnerabilities
  • analyzing code quality
  • validating findings
  • reducing false positives
  • recommending remediation actions
  • Build and maintain secure integrations with source code repositories, CI/CD platforms, vulnerability management systems, and security tooling
  • Leverage AI models to perform code review
  • threat modeling
  • secure design assessments
  • security control validation across diverse technology stacks
  • Develop prompts, workflows, orchestration logic, guardrails, and governance controls
  • ensure accurate, secure, and responsible use of AI within application security processes
  • Collaborate with development teams to triage, prioritize, and remediate vulnerabilities identified through AI-assisted security assessments
  • Deliver dashboards, metrics, reports, and executive-level summaries demonstrating security coverage, vulnerability trends, AI platform effectiveness, and remediation outcomes
  • Establish operational procedures, standards, governance, and best practices for AI-enabled application security capabilities
  • Support audits, regulatory reviews, and risk management activities by providing evidence of AI governance, security controls, and operational processes
  • Continuously evaluate advancements in Generative AI, Agentic AI, LLMs, SLMs, and secure coding technologies
  • improve organizational security capabilities
  • Provide technical leadership
  • support strategic initiatives related to AI-driven application security transformation
  • Strong software development background
  • Java
  • .NET
  • Python
  • Go
  • JavaScript
  • Node.js
  • similar platforms
  • Generative AI technologies
  • LLMs
  • SLMs
  • Retrieval Augmented Generation (RAG)
  • AI agents
  • prompt engineering
  • model orchestration frameworks
  • frontier AI models such as GPT, Claude, Gemini, Llama, Mistral, DeepSeek, or similar technologies
  • Hands-on experience building AI-powered applications
  • agentic workflows
  • automation frameworks
  • developer productivity solutions
  • Application Security disciplines including SAST, DAST, SCA, Container Security, API Security, Supply Chain Security, and Secure SDLC practices
  • Strong understanding of software vulnerabilities including OWASP Top 10, API Security Top 10, CWE, CVSS, and secure coding principles
  • Experience with cloud-native technologies and platforms including Azure, AWS, Kubernetes, and Infrastructure as Code (IaC)
  • Familiarity with AI security concepts including prompt injection, model manipulation, data leakage, LLM security risks, and AI governance frameworks
  • Experience evaluating AI-generated findings
  • conducting root cause analysis
  • developing automated remediation workflows
  • Knowledge of software supply chain security concepts including SBOMs, open-source risk management, and dependency analysis
  • Current information security certifications such as CISSP, CSSLP, Security+, GWAPT, GSEC, or equivalent
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field
  • 10 to 15 years of relevant experience
  • Experience implementing or operating application security tools and DevSecOps platforms
  • Experience designing, developing, or operationalizing AI, machine learning, LLM, or automation-based solutions
  • Experience integrating AI technologies into enterprise software development or cybersecurity workflows
  • Experience partnering with development teams to influence adoption of secure coding practices, security tooling, and modern engineering solutions
  • Familiarity with AI governance, responsible AI practices, model risk management, and enterprise AI controls
  • Security+, CISSP, CSSLP, or equivalent security certification
  • Experience with Agile, Scrum, and modern software engineering methodologies
  • Hybrid: Expected to work from base office location 4 days in a week
  • Standard business hours with flexibility to support global stakeholders across multiple time zones

Desired Qualifications

  • Excellent verbal and written communication skills with the ability to collaborate across technical, operational, and executive audiences
  • Experience implementing or operating application security tools and DevSecOps platforms
  • Experience designing, developing, or operationalizing AI, machine learning, LLM, or automation-based solutions
  • Experience integrating AI technologies into enterprise software development or cybersecurity workflows
  • Experience partnering with development teams to influence adoption of secure coding practices, security tooling, and modern engineering solutions
  • Familiarity with AI governance, responsible AI practices, model risk management, and enterprise AI controls
  • Security+, CISSP, CSSLP, or equivalent security certification preferred
  • Experience with Agile, Scrum, and modern software engineering methodologies

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Find similar roles