Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Sr Application Security Engineer - AI-First Development

Las Vegas Sands Corp

Senior Application Security Engineer (AI-First Development)

The primary responsibility of the Senior Application Security Engineer (AI-First Development) is to design, orchestrate, and validate the offensive security tooling and adversary-emulation capabilities used to find, prove, and help remediate exploitable weaknesses across applications, infrastructure, the software supply chain, and AI/ML systems. This role operates within an AI-First SDLC in which AI agents serve as primary producers of offensive tooling, exploit proof-of-concept code, attack automation, and adversary-emulation artifacts, while the engineer provides operational direction, context engineering, human-in-the-loop governance, and final accountability for the safety, authorization, and effectiveness of all offensive security work. All testing is performed strictly within authorized scope and defined rules of engagement.

The Senior Application Security Engineer is an experienced security or software engineer with a strong offensive security and secure-coding background who has adopted modern AI-assisted development tools as a core part of their daily workflow and is prepared to grow into deeper agent orchestration, context engineering, and verification responsibilities. This is a tool-builder-forward role: the emphasis is on engineering high-quality offensive tooling and exploit proof-of-concepts as much as on executing engagements.

All duties are to be performed in accordance with departmental and Las Vegas Sands Corp.'s policies, practices, and procedures. All Las Vegas Sands Corp. Team Members are expected to conduct and carry themselves in a professional manner at all times. Team Members are required to observe the company's standards, work requirements and rules of conduct.

Essential Duties & Responsibilities

  • Offensive Tooling Strategy, Agent Workflow Design, and Orchestration

    • Design, build, and maintain AI agent workflows that produce offensive security tooling, exploit proof-of-concept code, attack automation, and adversary-emulation artifacts from engagement objectives and authorized scope.

    • Decompose engagement objectives and threat scenarios into discrete, verifiable offensive tasks and tooling components that AI agents can execute effectively within defined boundaries and rules of engagement.

    • Select and configure appropriate AI models, agent frameworks, and offensive tooling for each workflow based on blast radius, target sensitivity, operational safety, and cost considerations.

    • Construct and maintain operational context that provides agents with approved attack techniques, target environment details, rules of engagement, and safety constraints needed to produce correct, in-scope, and consistent outputs.

    • Contribute to the offensive toolchain, including reusable testing skills, automation hooks, and project memory files that provide persistent context across agent sessions. Authoring of advanced toolchain components may be developed on the job.

    • Systematically capture attack patterns, technique effectiveness, and findings from each engagement and encode them back into shared context, offensive skills, and agent configurations so that subsequent work becomes more reliable.

    • Participate in collaborative refinement sessions to align on engagement objectives, scope, safety constraints, and context packages before agent execution begins.

    • Establish and maintain rules of engagement, scope boundaries, written authorization, and deconfliction procedures for each engagement, ensuring all offensive activity remains legal, authorized, and safe.

  • Exploit Validation and Findings Assurance

    • Apply human oversight at governance checkpoints appropriate to the risk level of each workflow, including pre-execution review, in-flight observation, and post-execution audit.

    • Review, test, and approve AI-generated offensive tooling, exploit code, and attack automation, ensuring they meet Sands coding standards, operational safety requirements, and rules of engagement before use against any authorized target.

    • Verify that AI-generated exploits and offensive tooling demonstrate genuine, reproducible impact rather than false positives, and reject findings that cannot be reliably validated or that achieve results outside authorized scope.

    • Partner with Cyber Security on Threat and Risk Assessments, vulnerability remediation, AI agent governance, and approved tooling decisions, surfacing offensive findings and exploitability signals that inform their reviews.

    • Support agent observability practices that track engagement activity, finding rates, exploit reproducibility, and coverage across targets and environments.

    • Produce clear, reproducible engagement deliverables, including technical findings reports, executive summaries, attack-path narratives, and prioritized remediation recommendations tailored to both technical and executive stakeholders.

  • Offensive Engineering and Application Exploitation

    • Architect and deliver shared offensive tooling, exploitation frameworks, and reusable testing harnesses spanning web, API, cloud, and binary targets that the security team consumes, using AI-First methodologies as the primary development approach.

    • Define attack methodologies, engagement playbooks, tooling interfaces, and safety controls that serve as foundational context for agent-driven offensive work.

    • Collaborate with cross-functional teams including engineering, QA, Cyber Security, and IT Operations to translate threat scenarios into executable offensive testing workflows.

    • Coordinate with security and engineering teams across global locations to ensure consistency in testing standards, safety controls, and reporting practices.

    • Write, debug, and refactor exploit code, offensive tooling, and attack automation directly when agent outputs require manual intervention or when developing novel exploitation techniques.

    • Ensure delivered offensive tooling meets enterprise standards for reliability, maintainability, operational safety, observability, and responsible use.

    • Design and execute offensive testing of the organization's AI and LLM-based systems and agents, including prompt injection, jailbreaks, tool and MCP abuse, guardrail evasion, and model and training-data extraction, drawing on frameworks such as the OWASP LLM Top 10 and MITRE ATLAS.

  • Continuous Improvement and Mentorship

    • Evaluate emerging AI models, agent frameworks, offensive tooling, and attack techniques to continuously improve testing effectiveness and coverage.

    • Mentor team members on AI-assisted offensive security practices, context engineering techniques, and verification methodologies.

    • Document attack patterns, prompt and context libraries, and lessons learned to build institutional knowledge.

    • Participate in collaborative construction sessions, guiding agent execution in real time and coaching team members on effective offensive tooling and engagement orchestration techniques.

  • Perform job duties in a safe manner.

  • Attend work as scheduled on a consistent and regular basis.

  • Perform other related duties as assigned.

Minimum Qualifications

  • At least 21 years of age.

  • Proof of authorization to work in the United States.

  • Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or a related field, or equivalent professional experience.

  • Must be able to obtain and maintain any certification or license, as required by law or policy.

  • 5+ years of professional software engineering or offensive security experience, including time in senior or lead positions owning the design and delivery of non-trivial security tooling or leading penetration-testing or red-team engagements.

  • Demonstrated daily use, over the past 6 months or more, of at least one modern AI-assisted development tool such as Claude Code, Cursor, GitHub Copilot, or Windsurf, with the ability to speak concretely about effective usage patterns and failure modes.

  • Strong foundational knowledge in at least one major programming or scripting ecosystem (such as Python, Go, C/C++, Rust, or PowerShell) and hands-on experience building offensive security tooling or exploits. Familiarity with additional languages and runtimes is a plus.

  • Experience assessing or exploiting workloads on at least one major cloud platform (Azure, AWS, or GCP). Azure experience is a plus.

  • Hands-on experience conducting offensive security work such as penetration testing, red-team engagements, or application, web, and API exploitation, including familiarity with common offensive tooling (such as Burp Suite, Metasploit, or nmap) and adversary frameworks such as MITRE ATT&CK.

  • Solid working knowledge of Windows and Linux internals

Vacancy posted 14 hours ago
Similar jobs that could be interesting for youBased on the Sr Application Security Engineer - AI-First Development in United States vacancy
  • Role Description The primary responsibility of the Senior Application Security Engineer (AI-First Development) is to design, orchestrate, and validate the offensive security tooling and adversary-emulation capabilities used to find, prove, and help remediate exploitable... 
    Senior
    Full time
    Flexible hours

    Las Vegas Sands Corp.

    Remote
    a month ago
  • $175k - $215k

     ...giving organizations secure, governed access to all...  ...enterprises power AI and analytics without...  ...the roleAs our Senior Application Security Engineer, you'll be the technical...  ...earlier in the development lifecycle, and create...  ...party dependencies, and first-party code — automating... 
    Senior
    Local area
    Flexible hours
    Shift work

    Starburst Data

    Boston, MA
    14 hours ago
  •  ...are looking for a Senior Application Security Engineer to architect and build automated...  ...the SDLC, engineering AI-enabled secure code scanning...  ...remediation guidance to development teams — operating with full...  ...and AI/ML, and our people-first culture has earned us multiple... 
    Senior
    Full time
    Local area
    Remote work
    Flexible hours

    AgileEngine

    Remote
    22 days ago
  •  ...platform protects email, data, applications, and networks with...  ...BarracudaAs a Senior Application Security Engineer, you’ll help shape the future...  ...SCA, Secrets Scanning, etc.)AI security controls and LLM risk...  ...onEmbed security across the development lifecycle, moving from pen-... 
    Senior
    Worldwide
    Flexible hours

    Barracuda

    Alpharetta, GA
    3 days ago
  • OverviewHow you’ll Make an ImpactThe Security Engineer plays a critical role in...  ...of Epsilon’s software applications by embedding security into the development lifecycle and advancing AI-enabled engineering...  ...establish a proactive, security-first development culture that prioritizes... 
    Suggested
    Temporary work
    Freelance
    Work at office
    Local area
    Flexible hours

    Publicis Media

    Boston, MA
    3 days ago
  • $130k - $218k

     ...are unable to consider applications from candidates based...  ...decentralized application development platform, an...  ...our users as safe and secure as possible. We are...  ...Application Security Engineer to join our rapidly growing...  ...includes the development of AI tooling for... 
    Senior
    Contract work
    Remote work
    Worldwide
    Shift work

    ConsenSys

    United States
    3 days ago
  •  ...cyber safety for the first digital generations,...  ...them grow, manage and secure their digital and financial...  ...talent who see AI as a teammate – leveraging...  ...Role: As a Senior Application Security Engineer, you will help...  ...strengthen and scale secure development practices across Gen’... 
    Senior
    Full time
    Flexible hours

    MoneyLion

    Remote
    26 days ago
  •  ...among the leaders in areas like application development and AI/ML, and our people-first culture has earned us multiple Best...  ...and AI-enabled SDLC secure code scanning. You will facilitate...  ...role requires 5+ years of software engineering experience with strong Python depth... 
    Local area
    Remote work
    Flexible hours
    Shift work

    AgileEngine

    United States
    14 hours ago
  • Join to apply for the Mid Level Application Security Engineer role at Jobright.ai 3 days ago Be among the first 25 applicants Join to apply for the Mid Level Application...  ...are integrated throughout the application development process. Responsibilities: Collaborate with... 
    Part time
    Work at office
    Remote work
    Relocation

    jobright.com

    Chicago, IL
    1 day ago
  •  ...revenue back into research and development, ensuring our employees...  ...; one that is human-first and accelerated by AI to create meaningful and...  ...environment. As a Senior Application Engineer specializing in Salesforce...  ...Salesforce data models, security, and governor limits •... 
    Senior
    Full time
    Work experience placement
    Work at office
    Remote work
    Flexible hours

    PointClickCare

    Remote
    20 days ago
  • $93.6k - $157.56k

     ...someone experienced with securing a wide variety of applications, you are looking for an opportunity...  ...an Application Security Engineer at Esri, you will fill a...  ...with the application development, DevSecOps, and...  ...workflows using various AI tools US citizenship and... 
    Senior

    ESRI

    Redlands, CA
    1 day ago
  •  ...on-call availabilityThe Senior Application Security Engineer is a deeply technical, hands-on...  ...Security function at CBIZ. As the first dedicated hire in this domain,...  ...architect and advisor to development, engineering, platform, and AI teams.Operating within a matrix... 
    Senior

    CBIZ

    Independence, OH
    2 days ago
  • $111k - $144.4k

     ...Enterprise Information Security /Full-Time /RemoteThe Sr. Application Security Engineer is responsible for validating...  ...repeatable secure development practices to reduce the...  ...business metrics.Lead AI security initiatives, including...  ...this pursuit since our first order in 2001.Clear... 
    Senior
    Full time
    Temporary work
    Work experience placement
    Remote work

    Clear Capital

    Reno, NV
    3 days ago
  •  ...TexasMission Control - Information Security /Employee / Full-Time /On...  ...agent-centric software development. As the leader in AI code review and...  ...platform, and infrastructure engineering teams so that our...  ...architectureExtensive experience with application and cloud architectures,... 
    Full time
    Relocation

    SonarSource

    Austin, TX
    11 hours ago
  • $165k - $248k

     ...Category Engineering Hire Type Employee Job ID 168...  ...pervasive intelligence. From AI and cloud...  ...streamline rule deck development, regression testing, and...  ...accuracy to help enable first-pass silicon success...  ...Synopsys considers all applicants for employment without... 
    Senior
    Remote work
    Worldwide

    Synopsys Inc

    Sunnyvale, CA
    a month ago
  • $140k - $200k

     ...Senior Application Security Engineer New York, New York; Miami, Florida; Remote (USA) Gemini is...  ...judgment into every team. Gemini is AI-first and AppSec builds the tools to make...  ...escalations, etc.) ~ Some background in development or scripting experience (Python,... 
    Senior
    Work at office
    Remote work
    Flexible hours

    Gemini, Inc.

    Miami, FL
    3 days ago
  • $100k - $135k

     ...(DSN) is seeking a full-time Sr. Application Security Engineer to join our team in Chicago, IL...  ...embedded throughout the software development lifecycle (SDLC). • Perform AI-assisted and traditional...  ...application teams to build a security-first culture. Requirements... 
    Senior
    Full time
    Casual work
    Remote work

    Diversified Services Network

    United States
    22 hours ago
  •  ...Senior Application Security Engineer American Fork, Utah, United States LVT is...  ...security solutions to deliver AI-driven, actionable...  ...secure. Since pioneering our first mobile, solar-powered units...  ...every layer of our Software Development Lifecycle (SDLC). This isn'... 
    Senior
    Full time
    Work at office
    Flexible hours

    LVT Corp

    American Fork, UT
    14 hours ago
  •  ...As a Sr. Application Security Engineer at vCluster Labs, you are the architect of trust...  ...stakeholders. Feature Development : Everyone at the...  ...novel problems related to AI and multi-tenant infrastructure...  ...such as Khosla Ventures (first investor in OpenAI, GitLab... 
    Senior
    Remote work
    Flexible hours
    Shift work

    vCluster

    Canada, KY
    1 day ago
  • $120k

     ...Posting Title: Senior Application Security Engineer ---- Hiring Department:...  ...security throughout the software development lifecycle across Dell...  ...security architecture AI, Robotics, and Biomedical Systems...  ...to submit your resume the first time you apply, then you... 
    Senior
    For contractors
    Work at office
    Immediate start

    University of Texas at Austin

    Austin, TX
    1 day ago
  •  ...that helps us do that better. AI is core to how we operate:...  ...even before COVID!), we welcome applicants from almost anywhere. Our...  ...seeking a Senior Application Security Engineer to join our Security Engineering...  ...every month! We take off the “First Friday” every month to focus... 
    Senior
    Work at office
    Immediate start
    Remote work
    Work from home
    Weekend work

    Monarch Money

    United States
    1 day ago
  • $150k - $173k

     ...Application Security Engineer III Founded in 2012, EasyPost is a YC unicorn whose mission is to make...  ...EasyPost solves this problem with the first developer-friendly REST API for shipping...  ...security into the fabric of our development lifecycle. Your efforts will help drive... 
    Senior
    Work experience placement
    Remote work
    Work from home
    Flexible hours
    Shift work

    EasyPost

    United States
    1 day ago
  • $160k - $200k

     ...Senior Product Security Engineer UTA seeks a Senior Product...  ...into the design, development, and operation of our...  ...controls across our applications and services, safeguarding...  ..., data-driven tools, AI-enabled business...  ...best-in-class, client-first approach is innovative... 
    Senior

    United Talent

    Beverly Hills, CA
    2 days ago
  •  ...organization in the technology and security sector, is seeking a passionate and skilled Application Security Automation Engineer to join their dynamic team...  ...Security Operations and Development teams. The ideal candidate...  ...libraries, utilizing AI-driven automation to... 

    Experis

    New York, NY
    1 day ago
  •  ...Technology oversees the effective development, delivery, and operation...  ...Business Integration, and Application Development & Maintenance...  ...Health is seeking a Sr. Application Test Engineer to lead end‑to‑end testing...  ...standard testing tools and AI‑assisted capabilities to improve... 
    Senior
    Full time
    Temporary work
    Local area
    Immediate start

    Cardinal Health

    Dublin, OH
    3 days ago
  • $82k - $118k

     ...Application Security Engineer Guild Mortgage Company, closing loans and opening doors since 1960. As a mortgage...  ...of our applications, including AI-enabled applications and services. Working within established secure development standards, they perform code reviews, run... 
    Minimum wage
    Work at office
    Local area
    Remote work
    Work from home
    Monday to Friday
    Shift work

    Guild Mortgage

    United States
    4 days ago
  •  ...human-operated fintech into AI-native financial...  ...Your Challenge As a Senior Application Security Engineer, you’ll be a hands-on technical...  ...’s applications, APIs, and development processes. You’ll help engineering...  ...A pragmatic, engineering-first mindset with a passion for... 
    Senior
    Full time
    Local area

    Unlimint

    Remote
    27 days ago
  • $157k - $216k

     ...next generation of our Application Security capability, a continuous, AI-augmented, layered defense...  ...built for a SaaS engineering organization where AI agents...  ...audit background. ~Development background, hands-on...  ...senior IC team. ~Remote-first, high autonomy,... 
    Senior
    Full time
    Remote work

    AlphaSense

    Remote
    a month ago
  •  ...BioRender is seeking a Senior Application Security Engineer to join our Security team – an engineer first, who contributes directly to...  ...quickly and safely. You'll work AI-natively, using AI coding...  ...review, triage, and tooling development. ~Secure AI-integrated product... 
    Senior
    Full time
    Remote work

    BioRender Inc.

    Remote
    a month ago
  •  ...We are looking for a Senior Application Security Engineer to break Counterpart...  ...leak and close them. ~Use AI as a force multiplier for finding...  ...-off policy. ~Remote-first culture that supports collaboration...  ..., mentorship, professional development funding, and regular... 
    Senior
    Full time
    Work at office
    Remote work
    Flexible hours

    Clover Health

    Remote
    28 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Sr Application Security Engineer - AI-First Development. Be the first to apply!