Lead - AI and Application Security

LeadSquared · Bengaluru

  • Experience3–5 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Posted28 Sept 2026

About LeadSquared

LeadSquared is hiring in Bengaluru in technology software. This role looks for around 3+ years of experience.

Skills

  • Secure SDLC
  • Application Security Testing
  • Release Security Testing
  • Static Application Security Testing (SAST)
  • Secure Code Review
  • Vulnerability Validation
  • Burp Suite
  • Nessus
  • OWASP Top 10
  • OWASP API Security Top 10
  • STRIDE
  • Red Teaming
  • Adversarial Testing
  • AI Security
  • Container Security

The role

An application security engineer at a software product company conducts Application Security Testing, Secure Code Review, and AI Security Reviews across applications, APIs, and cloud-hosted workloads, applying OWASP Top 10 and Red Teaming.

Full job description

Lead – AI and Application security

The Role We are looking for an AI and Application Security Engineer with strong hands-on experience in secure SDLC practices, application security testing, red teaming, code review, container/image review, release security testing, SAST, and AI implementation security reviews. The role involves identifying security risks across applications, APIs, AI-enabled features, and cloud-hosted workloads, and partnering with engineering teams to implement scalable, practical, and measurable security improvements.

Responsibilities Perform application security assessments across web applications, APIs, mobile applications, services, and integrations as part of the secure SDLC. Conduct release security testing, including manual testing, SAST result validation, vulnerability verification, and security sign-off support before production releases. Perform secure code reviews and identify vulnerabilities related to authentication, authorization, input validation, session management, insecure dependencies, business logic flaws, and API security. Conduct container and image security reviews, including dependency, package, secret, configuration, and vulnerability checks before deployment. Perform AI implementation security reviews for AI-enabled features, LLM integrations, prompt flows, data exposure risks, model misuse scenarios, and security control gaps. Plan and execute red teaming and adversarial testing activities for applications, APIs, and AI-enabled workflows, including abuse-case testing and AI-driven security testing techniques. Use tools such as Burp Suite, Nessus, SAST platforms, dependency scanners, and other application security testing tools to identify, validate, and track vulnerabilities. Apply OWASP Top 10, OWASP API Security Top 10, STRIDE threat modeling, and secure design principles to assess application and AI implementation risks. Work closely with engineering, DevOps, product, and security teams to prioritize vulnerabilities, define remediation actions, and verify fixes. Maintain clear documentation of findings, risk ratings, remediation recommendations, vulnerability status, and release security outcomes.

Requirements 3–5 years of relevant experience in application security, product security, secure SDLC, DevSecOps, or AI/application security testing. Bachelor’s degree in computer science, information security, engineering, or a related field. Mandatory hands-on experience with SDLC security testing, release security testing, SAST, secure code reviews, and vulnerability validation. Mandatory experience with application security testing tools such as Burp Suite and vulnerability assessment tools such as Nessus. Strong working knowledge of OWASP Top 10, OWASP API Security Top 10, STRIDE threat modeling, secure coding practices, and application risk assessment. Hands-on experience in red teaming, abuse-case testing, adversarial testing, or offensive security testing for applications, APIs, or AI-enabled systems. Experience reviewing AI implementations, including LLM integrations, prompt security, data leakage risks, insecure AI workflows, model misuse scenarios, and AI-specific threat vectors. Experience with container/image security reviews, dependency scanning, package vulnerability checks, and secrets/configuration review.