Connect with a cause that needs you!

Senior Application Security Engineer

Remote
Full-time
16th August 2026
Listed today

Salary 

Competitive, depending on experience

Location

Brazil (remote)

Summary of the role

The Senior Application Security Engineer leads the security of what Lhasa builds. As AI-assisted development accelerates the volume and pace of code reaching production, the security of Lhasa’s products cannot rely on end-stage review. This role owns the guardrail architecture, secure development standards, and automated pipeline controls that make security an intrinsic property of how Lhasa writes software and works with solution teams to make those standards effective in practice.

At senior level, this means moving beyond executing assessments to owning the frameworks that govern secure development at scale. You will make independent technical judgements on product security risk, lead application security programmes across Lhasa’s product portfolio, and define how AI-specific threats – prompt injection, agentic system risk, AI-generated code vulnerabilities are addressed in Lhasa’s development process.

You will also provide mentorship across IT and Software Development to develop application security capabilities and strengthens security engineering across IT and Software Development and act as the product security authority within the Enablement function.

Where decisions require architectural authority or carry material strategic risk, you will engage the Lead Security Engineer

You will report to the Lead Security Engineer.

Main Responsibilities

Guardrail Architecture and Secure Development Standards
  • Own and evolve the architecture of Lhasa’s security guardrail files (.md and equivalent): their structure, scope, versioning, update cadence and integration with the development toolchain.
  • Define the security requirements that AI engineers must follow when prompting AI to write code, covering data handling, authentication, injection prevention, and AI-specific vulnerability patterns.
  • Establish and continuously improve Lhasa’s secure-by-design principles for software development, ensuring they are practical, accessible, and current.
  • Treat guardrail recalibration as a standing responsibility: as AI coding tooling, threat patterns, and product architecture evolve, guardrails must keep pace.
  • Lead within the Engineers teams to drive adoption of guardrails across solution teams, resolving ambiguity and handling exceptions with clear rationale.
Application Security Leadership
  • Lead application security assessments across Lhasa’s product portfolio including threat modelling, SAST/DAST analysis and secure code review.
  • Own the design and optimization of Lhasa’s security pipeline architecture: automated gate configuration, exception handling, and coverage reporting.
  • Assess the security implications of AI and ML features in Lhasa’s products, providing expert guidance on prompt handling, data pipeline security, and model input/output risk.
  • Lead the orchestration of external penetration testing for Lhasa’s products, managing scope definition, findings review, and remediation tracking.
  • Define Lhasa’s technical response to novel application security threats – particularly those arising from AI-generated code and agentic systems, updating guardrails and pipeline controls accordingly.
Standards, Compliance, and Member Assurance
  • Own Lhasa’s product compliance with OWASP Top 10, NIST, ISO 27001, and relevant sector security standards.
  • Lead the assessment and implementation of AI-specific regulatory obligations (EU AI Act, ISO 42001) as they apply to Lhasa’s software products and development practices.
  • Produce and maintain product security assurance materials for Lhasa’s members, ensuring they accurately reflect current security controls.
  • Define Lhasa’s approach to security testing evidence and documentation for regulated workflows and audit purposes.
  • Contribute to cross-functional certification activities (ISO 27001, ISO 42001) as they relate to product security.
Enablement and Developer Capability
  • Act as the senior product security authority advising solution teams on the most complex security questions and architectural trade-offs.
  • Support AI engineers and developers in understanding and applying security guardrails, the goal is to make compliance the path of least resistance, not a barrier.
  • Lead security threat modelling sessions with solution teams at the start of significant product initiatives, setting the standard for how product risk is identified early.
  • Build product security competence across development teams over time, raising the baseline and reducing dependency on the InfoSec function for routine decisions.
  • Mentorship: actively develops application security capability and strengthens security engineering practices across IT and Software Development, contributing to the continuous improvement of product security competence across the organisation.
AI Adoption and Ways of Working
  • Use AI tools to scale product security coverage: automated scanning, AI-assisted threat modelling, test case generation, and vulnerability pattern detection at the pace AI development demands.
  • Stay at the leading edge of AI coding tool vulnerability patterns and incorporate new knowledge into guardrail documentation rapidly.
  • Orchestrate external AI security specialists for novel threat areas (prompt injection in agentic systems, model security) where in-house expertise needs to be supplemented.
  • Model AI-first working practices for the Application Security Engineer and for the broader development community.

Skills and Knowledge

Professional Experience
  • Extensive experience in information security, with a strong focus on application or product security.
  • Proven experience owning secure development frameworks, guardrail standards, or DevSecOps programmes.
  • Demonstrated experience embedding security into CI/CD pipelines and automating security gate controls.
  • Experience leading application security assessments including threat modelling, SAST/DAST, and penetration testing orchestration.
  • Background in or sustained close working experience with software development teams.
  • Track record of working autonomously on complex product security challenges and delivering outcomes across multiple teams.
Knowledge and Frameworks
  • Advanced knowledge of application security including OWASP Top 10 and equivalent frameworks.
  • Deep understanding of AI-generated code vulnerability patterns and how to address them at a framework and pipeline level.
  • Strong knowledge of AI-specific attack vectors: prompt injection, data poisoning, model manipulation, and agentic system risk.
  • Expert familiarity with CI/CD tooling and the mechanics of security gate implementation (SAST, DAST, dependency scanning, secrets detection).
  • Working knowledge of ISO 27001, NIST and ISO 42001 as they apply to software products.
Behaviours and Ways of Working
  • Outcome ownership: accountable for the security of Lhasa solutions, including the quality and currency of the guardrail framework.
  • Proactivity: anticipates security risks in new product directions and AI tooling changes before they materialise in production.
  • Influence without authority: achieves secure development outcomes through the quality of standards and the trust of delivery teams, not through mandate.
  • Communication: translates security requirements into practical, actionable guidance for AI engineers and AI Quality engineers at different levels of technical depth.
  • Adaptability: rapidly recalibrates guardrails and controls as AI development tooling and threat patterns evolve.
Desired
  • CISSP, CEH, or equivalent professional certification.
  • Experience with secure AI system design or formal AI security assessment frameworks.
  • Familiarity with ISO 42001, EU AI Act or contribution to security standards or open-source security tooling.
  • Background in software development or DevSecOps engineering.