Application Security Engineer, AI & Automation
Job Description
Skill is seeking a remote contract Senior Application Security Engineer focused on AI-driven automation for SCA/SAST/DAST triage and software supply chain security. This role centers on building, testing, and refining AI-enabled security tooling that leverages frontier LLMs to identify vulnerabilities, reason about code, accelerate triage, and automate remediation, all while aligning secure developer workflows across a distributed organization. The position offers a remote schedule with an hourly rate of USD 90β92 and requires a minimum of three years of hands-on experience in the field.
Responsibilities
- AI & Automation Engineering: Develop, test, and optimize application security tooling that uses frontier LLMs for vulnerability identification, code reasoning, triage acceleration, and automated remediation.
- Modern Triage & Incident Response: Provide unified triage coverage across SCA, SAST, and DAST findings. Lead rapid assessment and routing of threat intelligence escalations and critical patch events (PatchNow).
- Software Supply Chain Defense: Strengthen open-source dependency selection, package intake, and SBOM visibility. Build guardrails to detect malicious packages and enforce security policies across developer pipelines.
- Secure Developer Workflows: Assess and secure developer environments, including IDEs, plugins/extensions, package managers, and AI coding assistants against malicious code and unsafe configurations.
- AI Governance Support: Assist with technical proofs-of-value, data handling reviews, and model output evaluations required to safely onboard new AI capabilities across the enterprise.
Requirements
- Experience: 3+ years of hands-on Application Security experience with deep familiarity across the vulnerability lifecycle (SCA, SAST, DAST, and manual verification).
- Automation Mindset: Strong engineering fundamentals with scripting languages (Python, Go), APIs, CI/CD pipelines (GitHub Actions, GitLab CI), and developer tool integrations.
- AI Curiosity: Practical familiarity or hands-on experimentation with frontier models (LLMs), AI coding assistants (Copilot), prompt engineering, or AI orchestration frameworks.
- Supply Chain Knowledge: Experience securing software supply chains, package managers, and third-party dependencies against modern attack vectors.
- Communication: Ability to translate complex vulnerabilities into clear, actionable remediation guidance for software engineering teams.
Technologies
- Python
- Go
- GitHub Actions
- GitLab CI
- Copilot
Bonus Points
- Contributions to open-source security tools or AI/LLM security projects (eg, OWASP Top 10 for LLMs).
- Experience building custom integrations or LLM agents to automate security analyst workflows.