Application Security Engineer - Threat & Vulnerability Management (AI Focus)
NTT DATA
NTT DATA
Join NTT DATA as an Application Security Engineer specializing in Threat and Vulnerability Management with a focus on AI. This role is crucial for embedding security into the core of our AI application development.
You will drive secure-by-design principles across AI applications, agentic AI solutions, code, and CI/CD pipelines. Your expertise will ensure AI agents and applications are developed, tested, and deployed with robust security measures.
Ideal candidates possess a strong background in Application Security, SAST, DAST, SCA, vulnerability management, threat modeling, Secure SDLC, DevSecOps, and CI/CD security. A solid understanding of emerging security risks in LLMs, Generative AI, and Agentic AI is also key.
Take ownership of application vulnerability management for AI applications, agents, APIs, and services, ensuring secure development lifecycles.
Identify, assess, and prioritize vulnerabilities, establishing clear SLAs and remediation processes for AI workloads.
Integrate SAST, DAST, and SCA tools into CI/CD pipelines, defining security quality gates and automating checks.
Lead threat modeling for AI applications and LLM-powered solutions, assessing against frameworks like OWASP Top 10 for LLMs.
Mitigate AI-specific attack scenarios such as prompt injection, excessive agency, and sensitive data disclosure.
Build and maintain AI/ML Software Bill of Materials (SBOM) capabilities, managing risks across the AI/ML software supply chain.
Establish and enforce Secure SDLC guardrails, embedding security controls throughout the development and deployment phases.
A minimum of 7 years of hands-on experience in Application Security and Vulnerability Management is required.
Demonstrated experience (5+ years) with SAST, DAST, and SCA tools, including analyzing findings and triaging vulnerabilities.
Possess a strong understanding and 5+ years of experience in Secure SDLC, DevSecOps, and CI/CD security integration.
3-5 years of experience integrating automated security testing into development and deployment pipelines.
Proficiency in identifying application security vulnerabilities and common attack techniques.
Experience conducting threat modeling for enterprise applications and distributed systems.
Solid knowledge of LLM, Generative AI, and Agentic AI security risks, including common attack vectors.
Familiarity with AI/ML supply-chain security and SBOM practices is essential.
Exceptional communication and collaboration skills are needed to work effectively across various engineering and security teams.
NTT DATA
IT Consulting