Back to search
Prosum Linkedin · Posted 3d ago

Manager - Application & AI Security

Scottsdale, Arizona, United States

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Manager, Application & AI Security

Location: Scottsdale, AZ (hybrid)

About the Role

We are seeking a Manager, Application & AI Security to lead the security of internally developed applications, cloud application environments, CI/CD pipelines, and enterprise AI usage.

This role will establish and operate secure-by-default practices across the software development lifecycle while serving as a central technical leader for AI security and governance. The ideal candidate brings strong hands-on experience in application security and DevSecOps, along with a practical understanding of emerging AI security risks.

You will build security guardrails into development and deployment processes, oversee application security testing, manage AI and model inventories, assess prompt-injection and jailbreak risks, and establish controls for MCPs and AI-agent runtimes.

This is a highly technical leadership role focused on building scalable security capabilities rather than simply reviewing or documenting controls.

What You'll DoApplication Security & DevSecOps

  • Lead the secure software development lifecycle, incorporating NIST SSDF and ISO/IEC 27001 practices.
  • Establish application security requirements and conduct security reviews for major releases and critical applications.
  • Build and maintain secure CI/CD "golden pipelines," embedding security guardrails directly into development and deployment workflows.
  • Implement pipeline and artifact integrity controls and monitor production pipelines for security risks.
  • Lead application security testing across SAST, DAST, software composition analysis (SCA), secrets detection, API security, and related capabilities.
  • Establish API security practices aligned with OWASP standards, including the OWASP Top 10 and API Security Top 10.
  • Oversee container, Kubernetes, and Infrastructure-as-Code security scanning.
  • Lead application threat modeling and secure-code development practices.
  • Establish and maintain SBOM generation for internally developed applications.
  • Develop and deliver secure development training for engineering teams.
  • Establish application- and PaaS-level cloud security guardrails in partnership with cloud and infrastructure teams.
  • Provide application and cloud security expertise during broader technology and security reviews.
  • Help establish security guardrails for customer-facing platforms, workflows, and contact-center technologies.

AI Security & Governance

  • Serve as the technical owner for enterprise AI security controls and AI usage governance.
  • Establish controls for LLM and AI assistant usage, including public and internally hosted models.
  • Identify and manage risks associated with shadow AI, unauthorized AI tools, and potential data leakage.
  • Maintain an enterprise AI/model inventory, AI bill of materials (AI-BOM), model registry, and approval workflows.
  • Assess AI applications and models for security risks before production use.
  • Conduct prompt-injection and jailbreak testing and lead LLM security red-teaming.
  • Apply relevant AI security practices, including the OWASP Top 10 for LLM Applications and MITRE ATLAS.
  • Establish security controls for MCPs (Model Context Protocol) and AI-agent runtimes, including per-tool authorization, runtime guardrails, and containment.
  • Partner with governance, risk, compliance, data security, identity, infrastructure, and other teams to ensure AI security controls are implemented effectively.
  • Translate emerging AI security risks into practical technical controls and repeatable processes.

Key Initiatives

  • Enterprise AI Governance & Shadow AI: Establish AI usage policies, discovery, risk assessment, and security controls.
  • Secure CI/CD Golden Pipelines: Build DevSecOps guardrails-as-code and automated blocking of critical security findings.
  • Cloud Application Security: Strengthen security controls across cloud tenants, SaaS, and PaaS environments.
  • AI Agent & MCP Security: Develop runtime security capabilities for AI agents and tool integrations, including authorization and containment.

What Success Looks Like

In this role, success will include:

  • AI tools are risk-assessed and governed before approved enterprise use.
  • Shadow AI is identified, assessed, and addressed within established service levels.
  • Production CI/CD pipelines are covered by security guardrails and monitoring.
  • Major application releases receive appropriate security reviews.
  • Critical application security findings are prevented from reaching production.
  • SAST, DAST, SCA, API security, and secrets scanning are automated across applicable development pipelines.
  • AI/model inventories and approval workflows are accurate, current, and operational.
  • Prompt-injection, jailbreak, and AI-agent security risks are regularly assessed.
  • Application and AI security practices are embedded into engineering workflows rather than operating as a separate manual review process.

What We're Looking For

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent professional experience.
  • 5+ years of experience in application security, DevSecOps, software security, or a closely related discipline.
  • Experience leading or mentoring security engineers or technical security teams.
  • Hands-on experience building security controls into CI/CD pipelines and development workflows.
  • Experience with CI/CD platforms such as Azure DevOps, GitHub Actions, GitLab, Jenkins, or similar technologies.
  • Strong experience with application security testing, including SAST, DAST, SCA/open-source security, secrets scanning, and API security.
  • Strong understanding of API security architecture and standards, including OAuth 2.0, OWASP, and related security practices.
  • Experience securing containers, Kubernetes environments, and Infrastructure-as-Code.
  • Experience with threat modeling and software supply-chain security, including SBOMs.
  • Practical experience with AI/LLM security, including AI usage governance, prompt-injection and jailbreak testing, red-teaming, or AI-agent security.
  • Understanding of AI security and governance frameworks such as NIST AI RMF and ISO/IEC 42001.
  • Familiarity with NIST and ISO/IEC 27001 security frameworks and practices.
  • Experience translating complex technical security issues into clear recommendations for technical and non-technical audiences.
  • Strong communication, collaboration, prioritization, and problem-solving skills.

Helpful Experience

  • Familiarity with AI productivity and development tools such as Claude, GitHub Copilot, or similar platforms.
  • Experience securing MCPs or AI-agent architectures.
  • Experience with AI/model registries, AI inventories, or AI-BOM initiatives.
  • Experience with security platforms and tools such as Checkmarx, Veracode, Snyk, or comparable solutions.
  • CISSP or another relevant security certification is preferred. Additional certifications such as CSSLP, CCSP, or CISM are a plus.
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search