Lancesoft logo

Application Security AI Engineer

Lancesoft

  • Canton, OH
  • 30+ days ago
  • Remote
  • $70

Highlights

In addition to triage and code scan vulnerability management, the engineer will provide hands-on engineering support to test, evaluate, and help implement AI-assisted security tooling (including frontier-model-based capabilities) and strengthen software supply chain security, including safeguarding developer IDEs, plugins/extensions, and developer workflows from malicious code and compromise. Job Duties:Provide unified application security triage coverage across SCA, SAST, and DAST findings, including validation of critical and high-risk vulnerabilities, false positive analysis, exploitability assessment, remediation guidance, and escalation support for findings that may impact production, internet-facing, or business-critical applications.

Numbers & Facts

LocationCanton, OH (
Remote
)
IndustryStaffing/Employment Agencies
Salary$70
Company Size2,000 to 2,499 employees
Year Founded2000
Websitehttp://www.lancesoft.com/

Description

Job Title: Application Security AI Engineer
Work Location: Remote –USA
Pay: $70 –90/ hour
 
Must have: 3 plus years Code scanning experience, 3 plus years open source scanning, and 3 plus years dynamic and static scanning
 
The Application Security AI Engineer will augment the Application Security team by providing unified triage coverage across SCA/SAST/DAST findings, threat intelligence escalations, and PatchNow Critical events.
In addition to triage and code scan vulnerability management, the engineer will provide hands-on engineering support to test, evaluate, and help implement AI-assisted security tooling (including frontier-model-based capabilities) and strengthen software supply chain security, including safeguarding developer IDEs, plugins/extensions, and developer workflows from malicious code and compromise.
 
Job Duties:
  • Provide unified application security triage coverage across SCA, SAST, and DAST findings, including validation of critical and high-risk vulnerabilities, false positive analysis, exploitability assessment, remediation guidance, and escalation support for findings that may impact production, internet-facing, or business-critical applications.
  • Rapidly assess and coordinate responses for threat intelligence escalations and PatchNow Critical events, including scope analysis, owner routing, mitigation guidance, tracking, and closure verification.
  • Monitor and analyze newly disclosed and novel vulnerabilities, including faster-moving disclosures influenced by frontier-model-enabled research, and produce actionable briefs that drive remediation plans.
  • Engineer, test, and implement application security tooling that leverages frontier models or AI-enabled capabilities for vulnerability identification, code reasoning, triage acceleration, remediation recommendations, and analyst workflow automation while preserving human review, auditability, and secure use controls.
  • Support company processes for evaluating and onboarding new AI capabilities, including technical proof-of-value execution, security testing, control validation, data handling review, model output evaluation, success metrics, and documentation needed for internal governance and approval pathways.
  • Strengthen software supply chain security by helping secure open-source dependency selection, package intake, SBOM and component visibility, malicious package detection, dependency health assessment, and policy enforcement across developer, pipeline, and artifact management workflows.
  • Assess and improve developer IDE security, plugins/extensions, and developer workflows, including package managers, code-assist tools, and CI integrations, against malicious code, compromised extensions, and unsafe configurations.
 
Qualifications:
  • Strong experience triaging SCA/SAST/DAST findings and managing high-severity escalations (threat intel and critical patch events) through remediation and closure.
  • Engineering experience with scripting, automation, APIs, CI/CD workflows, developer tooling, or security platform integrations.
  • Practical familiarity with AI-enabled security tools, frontier models, coding assistants, prompt and tool orchestration, model evaluation, or AI governance processes.
  • Experience securing the software supply chain and developer tooling (IDEs, plugins/extensions, package managers, CI/CD integrations) against compromise and malicious code.
  • Ability to translate technical vulnerability findings into clear remediation guidance, risk summaries, and prioritization recommendations for development and security stakeholders.

About Company

We are a $125 Million, NMSDC-certified Minority & Woman owned Workforce Solutions Company headquartered in the DC metro area with presence across US with global presence - Canada, Mexico, India, UK, Malaysia, Indonasia, Hongkong, Singapore, UAE. We are specialized in providing Workforce Solutions, SOW project delivery, Engineering Solutions, Creative Services. We currently support 100+ Fortune companies globally and across multiple industry segments. We are currently supporting several massive programs across industry segment nationally/globally (Intel, Ally, AMD, QUALCOMM, Morgan Stanley, Kraft/ Mondelez, MNP, Amdocs, Dell, SanDisk, Medtronic, Becton Dickinson, GE, Lockheed Martin, UTC, L-3 Communications, Caterpillar, BMW, Mercedes Benz, National Grid, Dominion, Energy Future Holdings, PSEG, 3M, Fidelity, Aetna, Humana, Johnson & Johnson, Pfizer, Merck etc). 

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender, identity, national origin, disability, or protected veteran status.

Similar Jobs