Security Engineer - Secure Development
About the role
About the Role
Security Engineer, Secure Development
engineering, platform, infrastructure, and compliance teams
Application & Code Security Governance
- Own and enforce secure development standards for all internally built applications, platforms, automation, and tooling.
- Perform and oversee
manual and automated code reviews
(static, dynamic, dependency, and supply‑chain analysis).
- Establish clear
release gates
requiring security approval before software or AI systems are delivered to customers or promoted internally.
- Define remediation standards and risk acceptance criteria for security findings.
- Conduct secure design reviews and application threat modeling during early development phases to identify and mitigate risk before implementation.
AI & Emerging Technology Security
- Review internally developed
AI models, agents, prompts, integrations, and data pipelines
for security, privacy, and misuse risk.
- Ensure AI systems comply with internal governance, customer contractual obligations, and emerging regulatory expectations.
- Partner with engineering and data teams to implement
secure AI development patterns
DevSecOps Enablement
- Integrate security tooling into CI/CD pipelines (e.g., SAST, DAST, dependency scanning, container scanning, secrets detection).
- Promote “
shift
left
” security practices and reduce late‑stage security blockers through developer enablement.
- Collaborate with DevOps and Platform teams on secure delivery pipelines and runtime controls.
Risk, Compliance & IP Protection
- Protect XTIUM ’s intellectual property by ensuring secure design, code custody, and controlled access to source repositories.
- Support compliance efforts across frameworks such as SOC 2, ISO 27001, and customer‑specific security requirements.
- Produce audit‑ready artifacts including risk assessments, code review records, and security sign‑offs.
Leadership & Collaboration
- Act as the primary
application security escalation point
for engineering and leadership.
- Mentor developers and engineers on secure coding practices and threat modeling.
- Provide executive‑level reporting on application and AI security posture, trends, and risk exposure.
Required Qualifications
- 8+ years of experience in
application security, DevSecOps, or secure software development
.
- Strong hands‑on experience reviewing code in one or more modern languages (e.g., Python, JavaScript/TypeScript, C#, Java, Go).
- Proven experience securing APIs, web applications, microservices, and cloud‑native platforms.
- Experience integrating security controls into CI/CD pipelines and modern DevOps workflows.
- Deep understanding of common vulnerabilities and attack patterns (OWASP Top 10, API security risks, supply chain threats).
- Ability to balance security rigor with delivery velocity in a customer‑facing MSP environment.
Preferred Qualifications
- Experience securing
AI/ML systems
, automation platforms, or data‑driven applications.
- Familiarity with cloud platforms (Azure, AWS) and containerized environments.
- Experience in a
Managed Services Provider (MSP)
or SaaS organization with external customer delivery obligations.
- Knowledge of regulatory and compliance frameworks impacting software and data security.
Key Competencies
- Secure Software Architecture
- Application & API Security
- AI Security & Governance
- DevSecOps Tooling & Automation
Originally posted on Himalayas
Not included in the source posting: benefits.
Skills
Who can apply
The employer didn't state any visa, work authorization, citizenship or clearance requirements in this posting. Confirm with the employer before applying.
Read automatically from the employer's posting text. Always confirm with the employer — requirements can change after a job is published.