Application Security Engineer
Job Description
Compest Solutions Inc is seeking an Application Security Engineer / AI Security Engineer on a contract basis to strengthen security engineering across applications, cloud services, APIs, and AI or LLM integrations. This onsite role focuses on turning security and privacy risk into practical testing, clear documentation, and actionable remediation guidance for engineering teams.
The work spans security and privacy design reviews, threat modeling, and hands-on assessment, including adversarial testing of AI agents for common failure modes such as prompt injection and unsafe tool behavior. The position is based on-site in the Seattle, Washington and Sunnyvale, California area, with local candidates required.
Responsibilities
- Conduct security and privacy design reviews for applications, APIs, cloud services, engineering proposals, and AI integrations.
- Review system architecture and data flows, including access controls, trust boundaries, and authentication and authorization safeguards.
- Perform threat modeling for critical services and AI agents, documenting attack surfaces, attack scenarios, attack paths, mitigations, and residual risks.
- Lead hands-on security and adversarial testing for AI/LLM agents, including:
- Prompt injection
- Tool misuse
- Excessive agency
- Unauthorized data access
- Permission and access-control issues
- External integrations
- Sensitive-data exposure
- Identify, validate, and document security vulnerabilities, and provide practical remediation recommendations.
- Collaborate with engineering, security, privacy, and third-party teams to drive remediation and validate security controls.
- Develop reusable security assessment artifacts such as methodologies, checklists, threat models, test cases, and reporting templates.
- Support security automation and AI-assisted security workflows when appropriate.
Requirements
- 8+ years of professional experience in security engineering, application security, product security, offensive security, systems architecture, or a related technical security discipline.
- Experience reviewing complex technical designs and identifying security risks in:
- Applications
- APIs
- Cloud services
- Microservices
- Distributed systems
- Strong understanding of threat modeling, vulnerability assessment, and risk modeling.
- Strong understanding of authentication and authorization, least-privilege, and data protection.
- Strong understanding of security architecture.
- Hands-on experience with security testing, vulnerability investigation, penetration testing, adversarial testing, or security-control validation.
- Strong technical communication skills, with the ability to explain security findings to engineering and business stakeholders.
Preferred Qualifications
- Experience assessing AI/LLM applications and autonomous AI agents.
- Knowledge of prompt injection, jailbreaks, unsafe tool use, excessive agency, and AI data-security risks.
- Experience with privacy and security design reviews.
- Experience securing cloud environments.
- Security automation experience using Python, Go, Bash, or similar languages.
- Familiarity with application-security frameworks and industry security practices.
Tech
- Python
- Go
- Bash
Location: Onsite in Seattle, Washington and Sunnyvale, California (local candidates required).
Position type: Contract
Compensation: USD 50 - 55 per hour
Minimum experience: 8 years