Senior AI & AppSec CyberSecurity Engineer
Job Description
Own secure adoption of AI and applications across the organization, from governance and threat modeling to AppSec execution and team mentorship.
Responsibilities
- Provide security oversight for AI tools, platforms, and AI-powered applications used across Sweetwater
- Evaluate new vendors and AI models prior to adoption, including supply chain risk review
- Assess adversarial robustness while managing data handling and intellectual property considerations
- Lead Application Security (AppSec) across the software development lifecycle, including secure code review, threat modeling, and security testing
- Leverage automated tooling to improve efficiency and coverage for AppSec activities
- Develop and maintain AI and AppSec security standards and documentation to support audit and regulatory compliance needs
- Partner with software teams to establish and enforce secure coding standards and testing practices, including code review and validation standards
- Support Sweetwater’s risk exception process by performing security reviews of policy exceptions and unusual use cases with relevant stakeholders
- Identify, triage, and remediate AI governance and application security risks within established service levels
- Mentor junior security engineers, providing technical guidance and supporting their professional growth
- Stay current with emerging AI security threats and secure coding practices, updating security frameworks and documentation accordingly
Requirements
- Bachelor’s degree in Computer Science, Information Security, or related field, or equivalent professional experience
- 6+ years of cybersecurity experience, including:
- At least 1 year focused on AI/ML security or governance
- 3 years focused on application security
- Demonstrated experience in AI/LLM application security, including:
- Prompt injection defense
- Model risk assessment
- Generative AI governance frameworks
- Experience evaluating and governing AI coding agents and AI code assist platforms for both professional development and citizen development environments
- Expertise advising on SAST/DAST/SCA scanning practices within CI/CD pipelines
- Solid understanding of user-developed, low-code/no-code, and shadow IT governance frameworks, including:
- Tiered risk models
- Automated policy enforcement
- Strong communication and documentation skills, including translating security concepts for technical and non-technical audiences
- Hands-on experience reviewing code and conducting security assessments in real-world development environments
- Preferred: CSSLP (Certified Secure Software Lifecycle Professional) or GSSP (GIAC Secure Software Programmer)
Technologies
- AI tools and AI-powered applications
- AI/ML and AI/LLM application security
- Prompt injection defense
- Model risk assessment
- Generative AI governance frameworks
- AI coding agents and AI code assist platforms
- SAST, DAST, SCA
- CI/CD pipelines
Ideal team-player traits
- WOWs The Customer with passion for customer and colleague experiences
- Gets Things Done with strong work ethic and task urgency
- Obsesses over the Details
- Drives Continuous Improvement focused on effective and efficient ways to get better
- Develops the Future through personal and professional growth and bringing colleagues along
Relocation requirement
- Relocation to Sweetwater’s campus in Fort Wayne, IN is required
Location: Fort Wayne, IN (onsite)