Source description
About the role
About the Role We are looking for an experienced and hands-on Sr. Security Engineer to drive application security initiatives across Glance AI's rapidly evolving technology landscape. This role will partner closely with Engineering, Product, Platform, AI/ML, and Infrastructure teams to embed security into every stage of the software development lifecycle. You will serve as a trusted security advisor, helping teams design secure solutions, proactively identify risks, and build resilient systems at massive scale. The ideal candidate combines deep technical expertise with strong architectural thinking and the ability to influence stakeholders across the organization. What Youll Do Security Architecture & Design Partner with engineering and platform teams to design secure and scalable solutions. Conduct architecture and security design reviews for applications, APIs, cloud services, and infrastructure. Identify security gaps, weaknesses, trust boundaries, and exposure points in solution architectures. Develop and maintain security architecture documentation, including data flows, trust models, security controls, and risk assessments. Define security guardrails, standards, and reference architectures for enterprise-wide adoption. Threat Modeling & Risk Assessment Lead threat modeling exercises using methodologies such as STRIDE, PASTA, and ATT&CK-based approaches. Identify realistic attack paths and abuse scenarios across applications, cloud platforms, APIs, and AI systems. Translate security findings into actionable design and engineering recommendations. Drive risk-based decision-making aligned with business objectives. Application Security & Secure SDLC Embed security throughout the Software Development Lifecycle (SDLC). Guide development teams on secure coding practices and security-by-design principles. Review application security findings from SAST, DAST, SCA, penetration testing, and code reviews. Drive remediation efforts and establish secure development standards. Support security requirements for APIs, mobile applications, web applications, and microservices. Perimeter Defense & Security Controls Provide strategic oversight and tuning recommendations for: Web Application Firewalls (WAF) API Gateways Bot Mitigation Platforms DDoS Protection Services CDN Security Controls Ensure effective protection against: OWASP Top 10 threats API attacks Credential abuse Automated bot attacks Layer 7 attacks Vulnerability & Exposure Management Oversee vulnerability management programs across applications, cloud environments, and infrastructure. Lead penetration testing initiatives and coordinate remediation efforts. Drive attack surface reduction programs. Partner with engineering teams to prioritize and address security risks. Incident Response & Security Operations Act as a senior advisor during security incidents. Support containment, investigation, root cause analysis, and remediation activities. Participate in post-incident reviews and strategic improvement initiatives. AI & Emerging Technology Security Design and implement security controls for AI/ML platforms and applications. Evaluate AI-specific risks such as: Prompt Injection Data Leakage Model Abuse Unauthorized Model Access Supply Chain Risks Establish security guardrails aligned with OWASP Top 10 for LLM Applications and emerging AI security standards. Evaluate and integrate AI-powered security tools to improve threat detection and security automation. Cross-Functional Leadership Serve as a trusted security advisor for engineering, product, and platform teams. Drive security awareness and adoption across the organization. Mentor engineers and security practitioners on secure architecture and design practices. Influence security strategy and long-term roadmap development. Must-Have Qualifications Experience 4+ years of experience in Cybersecurity, Application Security/PT. Strong understanding of modern application architectures and distributed systems. Technical Expertise Security Architecture and Secure Design Reviews Threat Modeling (STRIDE, PASTA, ATT&CK) Application Security & Secure SDLC Cloud Security (GCP / AWS) Kubernetes & Container Security API Security Identity & Access Management Security Automation & DevSecOps Vulnerability Management & Penetration Testing AI Security Understanding of AI/ML security concepts and emerging AI threat landscapes. Familiarity with OWASP Top 10 for LLM Applications and AI security frameworks. What Success Looks Like Security is embedded into product and platform design from day one. Threat modeling becomes a standard part of engineering delivery. Security risks are identified and addressed early in the development lifecycle. Cloud and AI platforms operate with strong security guardrails. Engineering teams adopt secure-by-design practices at scale. Security becomes an enabler for innovation rather than a blocker Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
More at Glance