Hybrid Application Security Engineer

Posted 3 months ago

Apply now

About the role

  • Application Security Engineer for Billigence, focusing on security throughout engineering lifecycle and unique challenges of LLM and Gen AI workloads.

Responsibilities

  • Acquire a complete understanding of the Technology system and application landscape and assess it from a cybersecurity perspective.
  • Provide cybersecurity leadership in Agile environments across the broader Digital teams.
  • Design, create, embed, and own cybersecurity best practice processes into the SDLC of all Digital development teams.
  • Plan, research, and design robust security application architectures and patterns for all projects.
  • Proactively identify, prioritize, and manage security vulnerabilities across our codebases, from the front-end to the back-end infrastructure.
  • Embed security checks and scanning tools (SAST, DAST, etc.) directly into our CI/CD pipelines to catch and mitigate security flaws early and at scale.
  • Focus on the unique security challenges of LLMs and Gen AI, including prompt injection, model data poisoning, and the security of model serving infrastructure.
  • Organize ad-hoc and periodic vulnerability scans, risk analysis, and security assessments, and interpret the results for product teams.
  • Research security standards, security systems, and authentication protocols and educate the developers around their use.
  • Work closely with the Group Cyber Security and business teams to implement and maintain corporate security policies, standards, and procedures from an applications perspective.
  • Respond immediately to security-related incidents, manage any escalations and communications to the Senior Leadership team, and provide a thorough post-event analysis.
  • Work with the teams to identify, select, and implement technical security controls.
  • Oversee security awareness programs and educational efforts, particularly around developer training and awareness.

Requirements

  • Must have a strong background in both application and cloud security.
  • Proven experience in an Application Security Engineer or similar security role.
  • Deep understanding of common web application and cloud vulnerabilities (e.g., OWASP Top 10) and hands-on experience with various security testing tools and methodologies.
  • Experience with cloud security in GCP, including Identity and Access Management (IAM), network security, and data protection.
  • Strong analytical skills with a proactive approach to identifying and resolving complex security threats.
  • Excellent communication and interpersonal skills, with the ability to influence and collaborate with diverse engineering teams.

Benefits

  • Hybrid model, 2 days per week in the Sydney office

Job title

Application Security Engineer

Job type

Experience level

Mid levelSenior

Salary

Not specified

Degree requirement

No Education Requirement

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job