Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Application Security Engineer, AI-Assisted Vulnerability Management

Eclipse Foundation

Application Security Engineer

The Eclipse Foundation is one of the world's largest open source software foundations, with a proven track record of enabling developer-focused open source innovation earned over 19 years. The Foundation is the home of numerous industry-leading projects and collaborations including Adoptium, Software Defined Vehicle, Eclipse IDE, IOT and Jakarta EE. Supported by over 350 members globally, the Foundation has an established international reach and reputation.

The Role

We are looking for an Application Security Engineer to design, build, and operate AI-assisted vulnerability management workflows across Eclipse Foundation open source projects. This role combines application security, security automation, and practical use of large language models to help identify, triage, and remediate vulnerabilities at a scale that would be difficult to achieve manually. This is not a role focused on casually prompting a chatbot. You will build pipelines, integrate AI-assisted analysis into developer and CI/CD workflows, evaluate findings critically, reduce false positives, and collaborate with project maintainers to land real fixes. The goal is to deliver measurable improvements in how the Foundation discovers, prioritizes, and resolves security issues across its project portfolio.

Location and Term Role

This is an initial 12-month fixed-term role, fully remote and open to candidates located in the European Union, Canada, and the United States. Depending on organizational needs, funding, performance, and mutual fit, there may be an opportunity for renewal or transition to an ongoing/permanent position.

Responsibilities
  • Build and integrate AI-assisted security tooling Design and implement pipelines that use large language models, AI-assisted code analysis, and traditional security tools to scan Eclipse projects for vulnerabilities, including code-level flaws, dependency risks, and misconfigurations.
  • Develop scalable triage workflows Create workflows that separate true positives from noise, prioritize findings based on severity and exploitability, and produce actionable reports for project teams.
  • Drive remediation Work with project maintainers to propose fixes, submit pull requests, and validate that vulnerabilities have been properly resolved.
  • Evaluate and improve tooling Benchmark AI-assisted approaches against traditional SAST, DAST, SCA, and dependency-scanning tools. Measure false-positive rates, assess usefulness, and continuously refine prompts, retrieval strategies, evaluation methods, and model or tool selection.
  • Support responsible AI use in security workflows Help define safe and appropriate use of AI tooling, including the handling of sensitive vulnerability information, project source code, disclosure timelines, and data-sharing constraints.
  • Document and share knowledge Produce internal playbooks, technical write-ups, and metrics dashboards so the security team can sustain and extend this work over time.
  • Coordinate with the broader security team Participate in vulnerability disclosure processes, CVE management, and security advisories as needed.
Success in This Role

Success in this role means helping the Eclipse Foundation improve the speed, accuracy, and consistency of vulnerability discovery and remediation. This includes reducing triage time, improving true-positive rates, increasing the number of actionable findings delivered to projects, and helping maintainers land verified fixes. The role requires careful human review of AI-generated findings before they are shared with maintainers. We value accuracy, reproducibility, and respectful collaboration over the volume of reports produced.

Education

A degree in software engineering, computer science, cybersecurity, or a related field is welcome. Equivalent practical experience is also highly valued. Relevant certifications are considered an asset but are not required.

Desired Skills and Experience

We are looking for someone who is curious, pragmatic, and service-oriented. The successful candidate will be comfortable investigating technical issues, asking thoughtful questions, documenting work carefully, and helping others understand and address security risks. This role requires someone who can operate with a high level of trust, communicate calmly during security events, and balance security priorities with the realities of a collaborative, mission-driven open source environment. You should be comfortable working with distributed teams and contributing to a culture where security enables participation, transparency, and resilience. You should also be comfortable communicating with volunteer and professional maintainers in a constructive, respectful, and actionable way

Must-Have Qualifications
  • Strong application security background, including familiarity with common vulnerability classes such as OWASP Top 10 and CWE, secure coding practices, and practical exploitability analysis.
  • Hands-on experience conducting security code reviews, audits, or assessments using SAST, DAST, SCA, dependency scanning, or other code analysis tools.
  • Ability to build and integrate developer-facing tooling using languages such as Python, Java, TypeScript, or similar.
  • Practical experience applying LLMs or AI-assisted tools to code analysis, vulnerability research, developer productivity, or security automation.
  • Ability to evaluate AI-generated findings critically, measure false positives, and design human-in-the-loop review workflows.
  • Familiarity with open source development workflows, including Git, GitHub or GitLab, pull requests, issue tracking, and CI/CD.
  • Strong written communication skills, including the ability to write actionable security findings, advisories, issues, and remediation guidance for maintainers with varying security backgrounds.
Nice-to-Have Qualifications
  • Experience contributing to or maintaining open source projects.
  • Familiarity with the Eclipse Foundation ecosystem, including projects such as Eclipse IDE, Jakarta EE, Adoptium, Eclipse Mosquitto, or Software Defined Vehicle.
  • Experience with tools such as CodeQL, Semgrep, GitHub Advanced Security, osv-scanner, Trivy, Grype, Syft, Dependabot, or similar.
  • Background in prompt engineering, retrieval-augmented generation, or model evaluation for code-related tasks.
  • Experience with vulnerability disclosure and CVE processes.
  • Knowledge of software supply-chain security practices and technologies such as SBOM, Sigstore, SLSA, OSV, or OpenSSF Scorecard.
  • Experience building dashboards, metrics, or reporting workflows for security programs.
Working Style

We are looking for someone who values practical impact over theoretical findings. You should be comfortable working across many projects, dealing with incomplete information, validating results carefully, and communicating findings in ways that help maintainers take action. This role requires good judgment, discretion with sensitive vulnerability information, and the ability to balance security urgency with open source community realities.

Compensation and Benefits

We offer highly competitive compensation along with a comprehensive benefits package. We thank all applicants for their interest; however, only those to be interviewed will be contacted. For more information about Eclipse Foundation, please visit our website at Eclipse respects the dignity and independence of people with disabilities, and is committed to providing accommodation and support to persons with disabilities throughout any recruitment process, once made aware of a need for accommodation. If you require any special accommodation or support during the recruitment process, please indicate in your email to us.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Application Security Engineer, AI-Assisted Vulnerability Management in United States vacancy
  • $170k - $190k

     ...Ironclad is the leading AI contracting platform that transforms...  ...for Contract Lifecycle Management, a Fortune Great Place to...  ...is seeking a skilled Application Security Engineer with a passion for securing...  ...experience in automated vulnerability scanning and penetration testing... 
    Suggested
    Full time
    Contract work
    Work at office

    Ironclad Inc

    San Francisco, CA
    3 days ago
  • $128.4k - $172.3k

     ...Cisco's Enterprise AI team, the core...  ...mission is to build secure, scalable AI...  ...partnering across engineering, security, compliance...  ...and optimize application security tooling,...  ...identify and remediate vulnerabilities. Lead threat...  ..., vulnerability management, and runtime... 
    Suggested
    Full time
    Temporary work
    Local area
    Flexible hours

    Webex Events (formerly Socio)

    Durham, NC
    22 hours ago
  •  ...Application Security Engineer | Location: New York, NY or Charlotte, NC | Contract...  ...identify and remediate vulnerabilities, mature DevSecOps...  ...support secure integrations for AI-enabled applications such...  ...risks. Implement and manage application security tools... 
    Suggested
    Contract work

    Delphi-US

    New York, NY
    1 day ago
  •  ...Job Title: Application Security Engineer (DevSecOps) Location: Onsite 5x/Week...  ...Practical experience with AI-assisted coding and agentic code (...  ...developers and discuss vulnerabilities/weaknesses in code....  ...teams to build a casino management platform Integrate security... 
    Suggested
    Extra income

    RED SKY Consulting

    Plano, TX
    3 days ago
  • About Opal Security: At Opal, we’re building...  ...governance for the AI era—intelligent access management that empowers enterprises...  ...: Most security engineers spend their...  ...We're hiring an Application Security Engineer...  ...Triage and remediate vulnerabilities from every angle -... 
    Suggested

    Opal Security

    San Francisco, CA
    5 days ago
  • $320k - $405k

     ...Application Security Engineer Remote-Friendly (Travel-Required) | San Francisco...  ...interpretable, and steerable AI systems. We want AI to be...  ..., attack surfaces, and vulnerabilities. Develop tooling to scale...  ...coding practices. Manage Anthropic's vulnerability... 
    Work at office
    Remote work
    Visa sponsorship
    Flexible hours
    Shift work

    anthropic

    United States
    2 days ago
  •  ...on building out security from the ground...  ...leading edge of AI in healthcare globally...  ...Senior or Staff Application Security Engineer to join our team...  ..., and vulnerability remediation strategies...  ...Vulnerability Management & Incident Response...  ...manual and tool-assisted) to identify... 
    Hourly pay
    Full time
    Remote work
    Flexible hours

    Abridge

    United States
    2 days ago
  • $20k

     ...AI-Focused Staff Application Security Engineer At ServiceTitan, we are transforming product...  ...embed practical guardrails, manage emerging risks like non-...  ...web applications for vulnerabilities. Simulation & Validation...  ...Contextual Training: Assist in setting up "Just in Time... 
    Minimum wage
    Local area
    Remote work
    Flexible hours

    ServiceTitan

    United States
    1 day ago
  • $20k

     ...transforming product security into a core part of how engineering delivers software....  ...exceptional Staff Application Security Engineer...  ...remediation of vulnerabilities, standardizing secure...  ...it manually. AI Forward: Interest...  ...automated and AI-assisted tools, to support... 
    Minimum wage
    Local area
    Remote work
    Flexible hours
    Shift work

    ServiceTitan

    United States
    4 days ago
  • $210k - $230k

     ...Director, Information Security and build...  ...identify and remediate application vulnerabilities. This individual contributor...  ...and enable our engineers to code safely. Innovate with AI and deliver security...  ...coding and vulnerability management Assist penetration testing... 
    Full time
    Work at office
    Flexible hours

    Upside Services

    New York, NY
    1 day ago
  • $184k - $230k

    Manager, Application Security Engineering Information Security Santa Barbara, California Dallas, Texas San Diego...  ...the mitigation of software vulnerabilities in AppFolio products. Establish and...  ...on experience using LLMs and other AI capabilities, and an understanding... 
    Full time
    Remote work

    AppFolio, Inc

    San Diego, CA
    3 days ago
  • $96k - $146k

     ...U.S. National Security and Defense. For...  ...employees. Applicants that do not meet...  ...a talented engineer to support our...  ...application-level vulnerabilities. This role...  ...signal quality Assist development...  ...Cyberspace Workforce Management requirements...  ...generated by AI will not be... 
    Temporary work
    For contractors
    Work experience placement
    Immediate start
    Remote work
    Flexible hours

    SciTec

    Princeton, NJ
    5 days ago
  • $180k - $247.5k

     ...Secure Every Identity, from AI to Human Identity is the key to unlocking the...  ...talk. Staff Security Engineer - Vulnerability Management, US Public Sector...  ...increasing pace of cloud application adoption, companies are...  ...SP 800-53 and SOC 2. Assist Okta's Public Sector compliance... 
    Permanent employment
    Local area
    Worldwide
    Flexible hours

    Okta, Inc.

    Washington DC
    5 days ago
  • $188k - $275k

     ...Staff Security Engineer, Vulnerability Management Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA...  ...CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers,...  ...remediation-tracking systems across application, infrastructure, and hardware domains... 
    Permanent employment
    Temporary work
    Casual work
    Work at office
    Remote work
    Flexible hours

    CoreWeave

    Sunnyvale, CA
    2 days ago
  •  ...sponsorship of job applicants for employment...  ...as a Senior Manager. The primary...  ...is to utilize engineering expertise to...  ..., and deliver security features of products...  ...testing, vulnerability management and...  ...Engineering, AI, or related discipline...  ..., need assistance with your application... 

    Toyota Deutschland GmbH

    Plano, TX
    4 days ago
  •  ...Senior Application Security Engineer This role has been designed as 'Hybrid' with an expectation...  ...here. We have the flexibility to manage our work and personal needs. We make...  ...release pipelines. Automated AI specific vulnerability scanning into CI/CD to catch insecure... 
    Work at office
    2 days per week

    Hewlett Packard Enterprise

    Durham, NC
    7 days ago
  • $130k - $280k

     ...integrated, privacy-sensitive AI-powered platform that...  ...solutions for video security, access control, air...  ..., and visitor management. We’ve got serious momentum...  ...baked into our applications throughout the software...  ...Partner closely with engineering and product teams to improve... 
    Full time
    Work visa
    Flexible hours
    Shift work

    Verkada

    San Mateo, CA
    2 days ago
  • $166k - $200k

     ...is powered by Lattice OS, an AI-powered operating system...  ...ABOUT THE TEAM The Technical Security (TechSec) team within Anduril...  ...Senior Technical Security Application Engineer, Secured Spaces , is the technical...  .... Reporting to the Senior Manager, Technical Security Systems... 
    Full time
    Contract work
    Work experience placement
    Immediate start

    Navstar

    Costa Mesa, CA
    22 hours ago
  •  ...As Binti's first Principal Security Engineer (Applications focused), reporting to our...  ...potential security vulnerabilities, implement best practices,...  ...automation, including effective AI tools Share Expertise:...  ...Security Incident and Event Management (SIEM) platforms.... 
    Work at office
    Flexible hours

    Binti Inc

    San Francisco, CA
    3 days ago
  • $180k - $200k

     ...Harness is the AI Software Delivery Platform...  ...testing, deployments, application security, reliability, compliance...  ...calls, and helped manage $2.8B in cloud spend...  ...developing partnerships with engineering and product teams to...  ...efforts to discover vulnerabilities, weaknesses, and anti... 
    Local area
    Immediate start
    Remote work
    Shift work

    Harness

    United States
    1 day ago
  •  ...Application Security Engineer UniUni is a late-stage last-mile logistics company moving millions of...  ...authentication, authorization, session management, and API security across our products...  ...Experience hardening LLM-integrated or AI-powered features in production.... 
    Work at office
    Remote work

    UNIUNI

    United States
    3 days ago
  •  ...Job Title: AppSec Engineer Location: Rockville, MD or Tysons, VA...  ...code (java, python, etc.) AI/GenAI JD: Plan, coordinate and implement application security practices in each phase of software...  ...in evaluating security vulnerabilities, security tools,... 
    3 days per week

    Unisys

    Rockville, MD
    4 hours ago
  •  ...Senior Security Engineer – Secure Code Review New...  ...Engineer to join their Application Security...  ...manual and tool-assisted secure code reviews...  ...and triage vulnerabilities in open-source libraries...  ...Use AI-assisted code analysis...  ...Support vulnerability management, risk... 
    Full time

    AGS

    New York, NY
    4 days ago
  • $255k - $285k

     ...Staff Application Security Engineer At Bumble, we're redefining how security scales across global engineering...  ..., and Security leadership to build AI-powered tools, frameworks, and...  ...further information on how we hold and manage your data, please refer to our Privacy... 
    Live in
    Work at office
    Local area

    Bumble

    Austin, TX
    17 days ago
  • Responsible for supporting application security through security testing, vulnerability management, secure design...  ...of dedicated security engineers to protect our products...  ...management processes. Assist in the development,...  ...to learn and grow into AI Security and Security... 

    Bloomberg Industry Group

    Arlington, VA
    1 day ago
  •  ...Senior Application Security Engineer Remote RegScale is a continuous controls...  ...Engineering, Platform and AI, Compliance as Code,...  ...deployed rather than finding vulnerabilities after the fact. RegScale...  ...signals. Own vulnerability management across the platform,... 
    Remote work
    All shifts
    Shift work

    RegScale

    United States
    1 day ago
  • $160k

     ...Application Security Engineer We believe talent deserves a human touch. Your application...  ...for a portfolio of managed service provider companies...  ...utilities such as vulnerability aggregation pipelines, policy...  ...as CSSLP, GWEB, or OSCP AI/LLM security awareness, with... 
    Full time
    Remote work

    New Charter Technologies

    United States
    2 days ago
  • $40 per hour

     ...join our team to help train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity...  ..., including threat analysis, vulnerability assessments, and offensive...  ...incident response, detection engineering, DFIR, malware analysis,... 
    Hourly pay
    Full time
    Part time
    Remote work

    DataAnnotation

    Washington DC
    2 days ago
  •  ...stacks. We are looking for an Application Security Engineer to partner with...  ...findings and reduce repeat vulnerabilities through root-cause fixes....  ...secure coding patterns. AI security testing: Design...  ...generation). Vulnerability management: Own the end-to-end lifecycle... 
    Live in
    Work at office
    Local area
    Remote work
    Night shift

    Centerfield Corporation

    United States
    3 days ago
  •  ...Title: Software and Application Security Engineer Location: Lake Mary...  ...analyzing risk from vulnerabilities and assessing their...  .... Coaching and assisting in administration...  ...delivery process/ Change Management, SLA Compliance,...  ...: Experience with AI security ?... 
    Remote work

    RIT Solutions Inc/ Tech Dev IT/ Texperts Inc/ConceptsIT, Inc...

    United States
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Application Security Engineer, AI-Assisted Vulnerability Management. Be the first to apply!