LOG IN
SIGN UP
Canary Wharfian - Online Investment Banking & Finance Community.
Sign In
or continue with e-mail and password
Forgot password?
Don't have an account?
Create an account
or continue with e-mail and password
By signing up, you agree to our Terms & Conditions and Privacy Policy.

Application Security Engineer

ExperiencedNo visa sponsorship
Millennium logo

at Millennium

Hedge Funds

Posted 2 days ago

No clicks

**Application Security Engineer: Safeguard Enterprise AI & Software** The Application Security Engineer is a seasoned professional, experienced in AI security and enterprise-wide toolset development. Protecting Millennium's complex environment, this role focuses on AI security guardrails, risk management, and secure coding practices. Key responsibilities include: defining AI security strategies, managing risks, leading consultations, engaging in SDLC, and developing security programs. Quantitative and qualitative expertise includes AI-specific risks, security tools, and hybrid cloud environments. ESSENTIALS: Bachelor's degree, 5+ years' experience, Python/Java proficiency, SCA/SBOM familiarity. Desired certifications: CISSP, CISM. Collaborative, stakeholder-focused, with cloud and infrastructure bekends knows advantage.

Compensation
Not specified

Currency: Not specified

City
Not specified
Country
Not specified

Full Job Description

Application Security Engineer

The successful candidate will be a subject matter expert with direct experience in a wide range of security technologies, tools, and methodologies. The role is suited for an experienced Application Security engineer with proven understanding in enterprise security and AI security and will focus on building toolsets and processes to drive adoption of secure practices across the enterprise. The team fosters a collaborative environment and is building a best-in-class program to partner with the business to protect the Firms information and computer systems. Millennium is a complex and robust technical environment and securing the Firm from external and internal threats is a top priority.

Principal Responsibilities

  • AI Security Strategy: Define and implement security guardrails for Generative AI, LLMs, and Agentic frameworks, ensuring safe enterprise adoption.

  • AI Risk Management: Conduct specialized threat modeling, red teaming, and risk assessments for AI/ML models (e.g., testing for prompt injection, model theft, and data poisoning).

  • Security Consulting: Lead risk management activities, including application risk assessments, design reviews, and mitigation strategies for IT projects.

  • Lifecycle Engagement: Engage throughout the SDLC to identify vulnerabilities, conduct code reviews/penetration testing, and enforce secure coding standards.

  • Program Development: Evangelize AppSec and AI security best practices through developer education, training materials, and outreach.

  • Tooling & Architecture: Design robust security architectures and integrate automated security testing (SAST/DAST/SCA) into CI/CD pipelines.

  • Stakeholder Liaison: Partner with Technology, Trading, Legal, and Compliance to create policies and communicate technical risks to non-technical stakeholders.

Qualifications/Skills Required

  • Bachelor's degree or higher in Computer Science, Computer Engineering, IT Security or related field.

  • 5+ years experience working as an Application Security Engineer, Software Engineer, or similar role.

  • Deep understanding of AI-specific risks (OWASP Top 10 for LLMs) and experience securing applications utilizing LLMs.

  • Experience working with AI models, Agentic frameworks and security risks associated with AI.

  • Experience in working with global teams, collaborating on code and presentations.

  • Demonstrated work experience in hybrid on-premise and Public Cloud environments (AWS/GCP/Azure)

  • Strong understanding of security architectures, secure configuration principles/coding practices, cryptography fundamentals and encryption protocols.

  • Experience with common SCM & CI/CD technologies like GitHub, Jenkins, Artifactory, etc. and integrating Security Scanning and Vulnerability Management into the CI/CD Pipelines

  • Familiarity with static and dynamic security analysis tools, and SCA/SBOM solutions.

  • Hands on experience with Secrets Management & Password Vault technologies such as Delinea Secret Server and/or Hashicorp Vault, etc.

  • Strong experience in secure programming in languages such as Python, Java, C++, C#, or similar.

  • Familiarity with Infrastructure as Code tools (CloudFormation, Terraform, Ansible, etc.)

  • Familiarity with web application security testing tools and methodologies.

  • Knowledge of various security frameworks and standards such as ISO 27001, NIST, OWASP, etc.

  • Knowledge of Linux, OS internals and containers is a plus.

  • Certifications like CISSP, CISM, CompTIA Security+, or CEH are advantageous.

Application Security Engineer

Compensation

Not specified

City: Not specified

Country: Not specified

Millennium logo
Hedge Funds

2 days ago

No clicks

at Millennium

ExperiencedNo visa sponsorship

**Application Security Engineer: Safeguard Enterprise AI & Software** The Application Security Engineer is a seasoned professional, experienced in AI security and enterprise-wide toolset development. Protecting Millennium's complex environment, this role focuses on AI security guardrails, risk management, and secure coding practices. Key responsibilities include: defining AI security strategies, managing risks, leading consultations, engaging in SDLC, and developing security programs. Quantitative and qualitative expertise includes AI-specific risks, security tools, and hybrid cloud environments. ESSENTIALS: Bachelor's degree, 5+ years' experience, Python/Java proficiency, SCA/SBOM familiarity. Desired certifications: CISSP, CISM. Collaborative, stakeholder-focused, with cloud and infrastructure bekends knows advantage.

Full Job Description

Application Security Engineer

The successful candidate will be a subject matter expert with direct experience in a wide range of security technologies, tools, and methodologies. The role is suited for an experienced Application Security engineer with proven understanding in enterprise security and AI security and will focus on building toolsets and processes to drive adoption of secure practices across the enterprise. The team fosters a collaborative environment and is building a best-in-class program to partner with the business to protect the Firms information and computer systems. Millennium is a complex and robust technical environment and securing the Firm from external and internal threats is a top priority.

Principal Responsibilities

  • AI Security Strategy: Define and implement security guardrails for Generative AI, LLMs, and Agentic frameworks, ensuring safe enterprise adoption.

  • AI Risk Management: Conduct specialized threat modeling, red teaming, and risk assessments for AI/ML models (e.g., testing for prompt injection, model theft, and data poisoning).

  • Security Consulting: Lead risk management activities, including application risk assessments, design reviews, and mitigation strategies for IT projects.

  • Lifecycle Engagement: Engage throughout the SDLC to identify vulnerabilities, conduct code reviews/penetration testing, and enforce secure coding standards.

  • Program Development: Evangelize AppSec and AI security best practices through developer education, training materials, and outreach.

  • Tooling & Architecture: Design robust security architectures and integrate automated security testing (SAST/DAST/SCA) into CI/CD pipelines.

  • Stakeholder Liaison: Partner with Technology, Trading, Legal, and Compliance to create policies and communicate technical risks to non-technical stakeholders.

Qualifications/Skills Required

  • Bachelor's degree or higher in Computer Science, Computer Engineering, IT Security or related field.

  • 5+ years experience working as an Application Security Engineer, Software Engineer, or similar role.

  • Deep understanding of AI-specific risks (OWASP Top 10 for LLMs) and experience securing applications utilizing LLMs.

  • Experience working with AI models, Agentic frameworks and security risks associated with AI.

  • Experience in working with global teams, collaborating on code and presentations.

  • Demonstrated work experience in hybrid on-premise and Public Cloud environments (AWS/GCP/Azure)

  • Strong understanding of security architectures, secure configuration principles/coding practices, cryptography fundamentals and encryption protocols.

  • Experience with common SCM & CI/CD technologies like GitHub, Jenkins, Artifactory, etc. and integrating Security Scanning and Vulnerability Management into the CI/CD Pipelines

  • Familiarity with static and dynamic security analysis tools, and SCA/SBOM solutions.

  • Hands on experience with Secrets Management & Password Vault technologies such as Delinea Secret Server and/or Hashicorp Vault, etc.

  • Strong experience in secure programming in languages such as Python, Java, C++, C#, or similar.

  • Familiarity with Infrastructure as Code tools (CloudFormation, Terraform, Ansible, etc.)

  • Familiarity with web application security testing tools and methodologies.

  • Knowledge of various security frameworks and standards such as ISO 27001, NIST, OWASP, etc.

  • Knowledge of Linux, OS internals and containers is a plus.

  • Certifications like CISSP, CISM, CompTIA Security+, or CEH are advantageous.