Application Security Engineer for Billigence, focusing on security throughout engineering lifecycle and unique challenges of LLM and Gen AI workloads.
Responsibilities
Acquire a complete understanding of the Technology system and application landscape and assess it from a cybersecurity perspective.
Provide cybersecurity leadership in Agile environments across the broader Digital teams.
Design, create, embed, and own cybersecurity best practice processes into the SDLC of all Digital development teams.
Plan, research, and design robust security application architectures and patterns for all projects.
Proactively identify, prioritize, and manage security vulnerabilities across our codebases, from the front-end to the back-end infrastructure.
Embed security checks and scanning tools (SAST, DAST, etc.) directly into our CI/CD pipelines to catch and mitigate security flaws early and at scale.
Focus on the unique security challenges of LLMs and Gen AI, including prompt injection, model data poisoning, and the security of model serving infrastructure.
Organize ad-hoc and periodic vulnerability scans, risk analysis, and security assessments, and interpret the results for product teams.
Research security standards, security systems, and authentication protocols and educate the developers around their use.
Work closely with the Group Cyber Security and business teams to implement and maintain corporate security policies, standards, and procedures from an applications perspective.
Respond immediately to security-related incidents, manage any escalations and communications to the Senior Leadership team, and provide a thorough post-event analysis.
Work with the teams to identify, select, and implement technical security controls.
Oversee security awareness programs and educational efforts, particularly around developer training and awareness.
Requirements
Must have a strong background in both application and cloud security.
Proven experience in an Application Security Engineer or similar security role.
Deep understanding of common web application and cloud vulnerabilities (e.g., OWASP Top 10) and hands-on experience with various security testing tools and methodologies.
Experience with cloud security in GCP, including Identity and Access Management (IAM), network security, and data protection.
Strong analytical skills with a proactive approach to identifying and resolving complex security threats.
Excellent communication and interpersonal skills, with the ability to influence and collaborate with diverse engineering teams.
Benefits
Hybrid model, 2 days per week in the Sydney office
Sounding and Security Watch responsible for Navy asset security at NSF Diego Garcia. Conducting checks and ensuring safety during designated watch hours with strong situational awareness.
Sales Enablement Manager creating technical content for Upwind Security. Collaborating across teams to translate cloud security concepts into clear narratives for engineers and security leaders.
Security Engineer designing and implementing security measures to protect Snap Inc.'s infrastructure. Collaborating across teams while focusing on threat detection and response strategies.
IT Security & Compliance Head at Lonza leading security strategy and managing global risk. Collaboration with senior leadership to enhance information security across Capsules & Health Ingredients business.
Senior Security Manager leading security for Sanofi meetings and events across North America. Ensuring compliance with global meeting policies and managing event security operations in high - stake environments.
Security Officer maintaining safety protocols at Aloft New Orleans. Responsible for patrolling, monitoring security systems, and assisting guests with safety - related concerns.
Security Detection Specialist responsible for detecting cybersecurity incidents using advanced security technologies. Analyzing data feeds and leveraging security tools for incident detection and reporting.
Senior Incident Response Engineer at Walmart focusing on security threat campaigns to enhance detection and response capabilities. Collaborating with SOC and engineering teams to improve security posture.
Head of Infrastructure & Security at Kinatico, a RegTech leader, focused on cloud infrastructure and security governance. Leading a technically deep team of cloud engineers and security specialists in a hybrid environment.
Security Shift Manager overseeing security operations at WarHorse Gaming Omaha. Responsible for team safety, compliance with regulations, and staffing in the security department.