Manager - Application & AI Security
Indexed description
Manager, Application & AI Security
Location: Scottsdale, AZ (hybrid)
About the Role
We are seeking a Manager, Application & AI Security to lead the security of internally developed applications, cloud application environments, CI/CD pipelines, and enterprise AI usage.
This role will establish and operate secure-by-default practices across the software development lifecycle while serving as a central technical leader for AI security and governance. The ideal candidate brings strong hands-on experience in application security and DevSecOps, along with a practical understanding of emerging AI security risks.
You will build security guardrails into development and deployment processes, oversee application security testing, manage AI and model inventories, assess prompt-injection and jailbreak risks, and establish controls for MCPs and AI-agent runtimes.
This is a highly technical leadership role focused on building scalable security capabilities rather than simply reviewing or documenting controls.
What You'll DoApplication Security & DevSecOps
- Lead the secure software development lifecycle, incorporating NIST SSDF and ISO/IEC 27001 practices.
- Establish application security requirements and conduct security reviews for major releases and critical applications.
- Build and maintain secure CI/CD "golden pipelines," embedding security guardrails directly into development and deployment workflows.
- Implement pipeline and artifact integrity controls and monitor production pipelines for security risks.
- Lead application security testing across SAST, DAST, software composition analysis (SCA), secrets detection, API security, and related capabilities.
- Establish API security practices aligned with OWASP standards, including the OWASP Top 10 and API Security Top 10.
- Oversee container, Kubernetes, and Infrastructure-as-Code security scanning.
- Lead application threat modeling and secure-code development practices.
- Establish and maintain SBOM generation for internally developed applications.
- Develop and deliver secure development training for engineering teams.
- Establish application- and PaaS-level cloud security guardrails in partnership with cloud and infrastructure teams.
- Provide application and cloud security expertise during broader technology and security reviews.
- Help establish security guardrails for customer-facing platforms, workflows, and contact-center technologies.
AI Security & Governance
- Serve as the technical owner for enterprise AI security controls and AI usage governance.
- Establish controls for LLM and AI assistant usage, including public and internally hosted models.
- Identify and manage risks associated with shadow AI, unauthorized AI tools, and potential data leakage.
- Maintain an enterprise AI/model inventory, AI bill of materials (AI-BOM), model registry, and approval workflows.
- Assess AI applications and models for security risks before production use.
- Conduct prompt-injection and jailbreak testing and lead LLM security red-teaming.
- Apply relevant AI security practices, including the OWASP Top 10 for LLM Applications and MITRE ATLAS.
- Establish security controls for MCPs (Model Context Protocol) and AI-agent runtimes, including per-tool authorization, runtime guardrails, and containment.
- Partner with governance, risk, compliance, data security, identity, infrastructure, and other teams to ensure AI security controls are implemented effectively.
- Translate emerging AI security risks into practical technical controls and repeatable processes.
Key Initiatives
- Enterprise AI Governance & Shadow AI: Establish AI usage policies, discovery, risk assessment, and security controls.
- Secure CI/CD Golden Pipelines: Build DevSecOps guardrails-as-code and automated blocking of critical security findings.
- Cloud Application Security: Strengthen security controls across cloud tenants, SaaS, and PaaS environments.
- AI Agent & MCP Security: Develop runtime security capabilities for AI agents and tool integrations, including authorization and containment.
What Success Looks Like
In this role, success will include:
- AI tools are risk-assessed and governed before approved enterprise use.
- Shadow AI is identified, assessed, and addressed within established service levels.
- Production CI/CD pipelines are covered by security guardrails and monitoring.
- Major application releases receive appropriate security reviews.
- Critical application security findings are prevented from reaching production.
- SAST, DAST, SCA, API security, and secrets scanning are automated across applicable development pipelines.
- AI/model inventories and approval workflows are accurate, current, and operational.
- Prompt-injection, jailbreak, and AI-agent security risks are regularly assessed.
- Application and AI security practices are embedded into engineering workflows rather than operating as a separate manual review process.
What We're Looking For
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent professional experience.
- 5+ years of experience in application security, DevSecOps, software security, or a closely related discipline.
- Experience leading or mentoring security engineers or technical security teams.
- Hands-on experience building security controls into CI/CD pipelines and development workflows.
- Experience with CI/CD platforms such as Azure DevOps, GitHub Actions, GitLab, Jenkins, or similar technologies.
- Strong experience with application security testing, including SAST, DAST, SCA/open-source security, secrets scanning, and API security.
- Strong understanding of API security architecture and standards, including OAuth 2.0, OWASP, and related security practices.
- Experience securing containers, Kubernetes environments, and Infrastructure-as-Code.
- Experience with threat modeling and software supply-chain security, including SBOMs.
- Practical experience with AI/LLM security, including AI usage governance, prompt-injection and jailbreak testing, red-teaming, or AI-agent security.
- Understanding of AI security and governance frameworks such as NIST AI RMF and ISO/IEC 42001.
- Familiarity with NIST and ISO/IEC 27001 security frameworks and practices.
- Experience translating complex technical security issues into clear recommendations for technical and non-technical audiences.
- Strong communication, collaboration, prioritization, and problem-solving skills.
Helpful Experience
- Familiarity with AI productivity and development tools such as Claude, GitHub Copilot, or similar platforms.
- Experience securing MCPs or AI-agent architectures.
- Experience with AI/model registries, AI inventories, or AI-BOM initiatives.
- Experience with security platforms and tools such as Checkmarx, Veracode, Snyk, or comparable solutions.
- CISSP or another relevant security certification is preferred. Additional certifications such as CSSLP, CCSP, or CISM are a plus.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search