Job#: 3043810
Job Description:
Security Engineer 5 - (Penetration Testing, AI Security & Application Security Strategy)
Location
Job Summary
The organization is seeking a highly experienced Engineer 5 / Senior Lead Application Security Engineer to define and execute Application Security strategy supporting enterprise modernization initiatives, including the Data Center Modernization and Simplification (DCMS) program. This role serves as a senior technical leader responsible for driving enterprise-scale application security strategy, advancing security automation, leading penetration testing initiatives, and delivering innovative AI-enabled security capabilities.
The ideal candidate possesses deep expertise in Application Security, Secure Software Development Lifecycle (SSDLC) controls, offensive security, threat modeling, vulnerability management, and security engineering. This individual will partner with executive leadership, security teams, software engineering organizations, and business stakeholders to deliver scalable, automated, and risk-aligned security outcomes across the enterprise.
This role requires a strategic leader who can influence executive stakeholders, drive modernization initiatives, and shape the future of Application Security through the adoption of emerging technologies including Artificial Intelligence, Large Language Models (LLMs), and advanced security automation.
Key Responsibilities
Application Security Strategy & Leadership
Penetration Testing & Offensive Security
Lead enterprise penetration testing strategies and application security assessment programs.
Perform or oversee:
Application Penetration Testing
Security Architecture Reviews
Red Team Assessments
Threat Modeling Exercises
Vulnerability Research
Security Assessments
Adversarial Security Testing
Evaluate vulnerabilities, identify security weaknesses, and develop remediation strategies.
Research emerging attack techniques, threat actor behaviors, and evolving risk trends.
Provide technical leadership on remediation planning and security risk reduction activities.
Guide development teams on secure design principles and vulnerability mitigation strategies.
Support offensive security initiatives including exploitation analysis, security testing, and application security validation activities.
Application Security Modernization
AI Security & GenAI Application Protection
Identify, evaluate, and implement AI and Generative AI (GenAI) security use cases that improve security effectiveness and reduce manual effort.
Develop adversarial testing methodologies for:
Large Language Models (LLMs)
Generative AI Applications
AI-Powered Services
Design defenses against:
Prompt Injection Attacks
Model Abuse
Tool Misuse
Sensitive Data Exposure
Secrets Leakage
Support AI model scanning, integrity validation, secure onboarding, and governance programs.
Define security controls addressing emerging AI-specific risks.
Lead initiatives involving AI Testing, AI Security Analytics, AI Operationalization, and AI Security Assessment Automation.
Evaluate emerging AI technologies and develop enterprise security strategies for AI adoption.
Secure Software Development Lifecycle (SSDLC)
Lead and mature enterprise SSDLC programs.
Define and implement security requirements throughout the software development lifecycle.
Provide expertise in:
Threat Modeling
Secure Design Reviews
Secure Coding Practices
Static Application Security Testing (SAST)
Software Composition Analysis (SCA)
Dynamic Application Security Testing (DAST)
Penetration Testing
Partner with engineering organizations to improve developer security capabilities and secure coding maturity.
Drive consistent application of security controls across development teams.
Security Automation & DevSecOps
Enterprise Influence & Technical Leadership
Required Qualifications
7+ years of Application Security, Information Security Engineering, or related engineering experience.
Deep expertise in enterprise-scale Application Security programs.
Strong experience with:
Threat Modeling
Secure Design
Secure Coding Practices
SAST
SCA
DAST
Penetration Testing
Demonstrated experience defining and executing enterprise Application Security strategy.
Proven ability to influence technical and business leaders across large organizations.
Strong understanding of vulnerability management, remediation processes, and security governance.
Exceptional communication, leadership, and executive stakeholder management skills.
Preferred Qualifications
Advanced Application Security & Offensive Security
Experience leading enterprise Application Security transformation and modernization initiatives.
Experience supporting Application Security governance, security consulting, remediation planning, and security champion programs.
Strong expertise in:
Application Security Testing
Offensive Security
Vulnerability Research
Exploitation Techniques
Red Team Methodologies
Security Assessments
Experience driving secure-by-design and SSDLC initiatives across large application portfolios.
Experience working directly with developers and application owners to implement security controls and remediation plans.
AI & GenAI Security
Experience securing:
Generative AI Applications
Large Language Models (LLMs)
AI/ML Platforms
Experience conducting adversarial AI testing and prompt injection assessments.
Experience with:
Prompt Engineering
LLM Security
AI Testing
AI Operationalization
AI Security Analytics
AI Security Assessment Automation
Experience building AI-driven security automation capabilities.
DevSecOps & Automation
Strong understanding of:
DevSecOps
CI/CD Security Integration
Security Automation
Infrastructure as Code (IaC)
Platform Automation
Experience integrating security scanning technologies into software delivery pipelines.
Experience developing security tooling integrations and automation frameworks.
Cloud & Modernization Experience
Experience supporting enterprise modernization initiatives, cloud-native architectures, and security transformation programs.
Experience with:
Cloud Security
Cloud Architecture
Platform Engineering
Infrastructure Automation
Google Cloud Platform (GCP)
Azure Environments
Experience working within highly regulated environments such as financial services.
Technical Skills
Application Security
SSDLC
AI Security
DevSecOps & Automation
Preferred Certifications
One or more of the following certifications are highly desired:
Desired Candidate Profile
The ideal candidate is a senior Application Security leader who combines deep penetration testing expertise, offensive security capabilities, and modern AI security knowledge with proven enterprise leadership experience.
Successful candidates will possess expertise in SSDLC controls, application security architecture, offensive security methodologies, vulnerability management, security automation, and emerging AI security risks. They will have experience influencing executive stakeholders, partnering with developers and security champions, driving enterprise modernization efforts, and delivering scalable Application Security outcomes within highly regulated environments
Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.
Everforth Apex uses a virtual recruiter as part of the application process. Click here for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at https://www.apexsystems.com/privacy-policy
Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Everforth Apex team member can provide.
Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.
If you require an accommodation under the Americans with Disabilities Act to participate in an interview with a virtual recruiter or to use our website for a search or application, please contact our Benefits Department at [email protected] or 804-523-8228. Please note that this contact information is strictly to be used for medical ADA accommodations and that no other inquiries will be answered.
UnitedHealthcare creates and publishes the Transparency in Coverage Machine-Readable Files on behalf of Everforth Apex Systems.
Employee Type:
Contract
Location:
Charlotte, NC, US
Job Type:
Date Posted:
July 24, 2026
Pay Range:
$97 - $105 per hour
Similar Jobs