Principal Application & AI Security Engineer
Oak Brook, IL - USA
Job Summary
DNV Energy Systems Platform Services is seeking Principal Application & AI Security Engineer.
DNV Energy Systems Platform Services runs the software products and digital platforms our customers depend on including systems with significant operational importance in enterprise and energy environments. As we evolve toward agentic AI architectures security must move from after-the-fact review into architecture development workflows and runtime operations - engineered into the platform and the delivery pipeline with evidence that controls are implemented and operating effectively.
This is a builders role for a senior technical leader who can read and improve code design reusable controls model complex threats conduct authorized security testing and work directly with engineering teams to ship durable fixes. The goal is not simply to identify vulnerabilities. It is to eliminate recurring vulnerability classes reduce exposure and make the secure path the easiest path.
This role is based at our DNV office in Houston TX or Oakland CA presenting a dynamic hybrid schedule where employees will typically spend three (3) days per week working from either aDNV office or client location/site. Further details regarding role-specific requirements will be shared during the interview process.
What youll do
Youll be a technical leader within our organization focused on three core priorities:
- Securing application and AI architecture.Design and implement secure patterns across applications APIs cloud platforms and AI-agent systems with particular emphasis on identity authorization tenant isolation data access tool use and runtime guardrails.
- Automating security in engineering workflows. Build and tune risk-based controls so material issues are caught and acted on inside delivery workflows rather than at manual checkpoints.
- Eliminating recurring vulnerabilities. Find root causes fix weaknesses at the architecture or platform-pattern level and make the same class of issue structurally difficult to reintroduce
The responsibilities below describe how this work shows up day-to-day across architecture delivery AI systems remediation and engineering.
Build security into delivery and platform engineering
- Design and implement scalable controls for software and AI supply chains including dependency integrity SCA SAST DAST build provenance artifact security secrets protection container and infrastructure-as-code assurance and software or AI bills of materials where appropriate.
- Implement platform-level controls: policy as code authorization enforcement data-access guardrails secure defaults and reusable reference implementations.
- Design AI-assisted security-testing environments automated attack scenarios and security-regression suites that prevent resolved issues from silently returning.
- Implement risk-based quality gates with documented exception paths accountable ownership and service-level expectations so material issues block release.
Find prove and fix material weaknesses
- Review source code APIs and application designs for weaknesses in authentication authorization session management input handling data-access scope and multi-tenant isolation including row- and field-level boundaries.
- Conduct authorized application API and AI security testing including targeted manual testing of business logic and trust boundaries that automated tools cannot adequately validate.
- Work alongside engineers to remediate root causes validate fixes create regression tests and put preventive controls or secure patterns in place.
- Establish vulnerability triage and remediation practices including exploitability and exposure analysis accountable ownership target dates exception handling retesting closure evidence and escalation of overdue material risk.
Secure AI agents and AI-assisted development
- Establish agent identities and least-privilege permissions with clear separation of read write execute approval and administrative capabilities.
- Govern model tool skill connector plug-in memory and data access including tenant isolation and boundaries between trusted and untrusted context.
- Validate untrusted inputs and tool outputs and design defenses against direct and indirect prompt injection goal manipulation tool misuse privilege escalation sensitive-data exposure memory poisoning unsafe delegation and cascading failures.
- Assess multi-agent workflows to implement approval requirements for consequential or irreversible actions runtime policy enforcement rate and resource limits and tamper-resistant auditability.
Shape secure architecture at scale
- Lead high-risk threat modeling and architecture reviews for complex multi-tenant cloud-native event-driven and AI-enabled systems.
- Develop and demonstrate reusable secure patterns for microservices APIs event-driven systems containers Kubernetes cloud services and agentic AI applications.
- Contribute to platform roadmaps and engineering practice so controls are implemented at the most effective layer and reused across products.
- Provide evidence from implementation testing and incidents to help Information Security team continuously improve enterprise standards and assurance expectations.
Support engineering teams and incidents
- Partner across distributed engineering hubs including North America and Chennai to drive adoption of secure patterns and automation at scale.
- Translate findings into prioritized actionable engineering work reflecting technical severity exploitability customer impact and delivery context.
- Mentor senior engineers and technical leaders in secure design development threat modeling and remediation.
- Serve as the application and AI security technical lead during relevant incidents coordinating with designated incident lead and Information Security team to support investigation containment eradication recovery remediation validation and lessons learned.
- Represent application and AI security in significant technical executive customer audit and assurance discussions when needed.
Responsibilities
- Generous paid time off (vacation sick days company holidays personal days)
- Multiple Medical and Dental benefit plans to choose from Vision benefits
- Spending accounts FSA Dependent Care Commuter Benefits company-seeded HSA
- Employer-paid therapist-led virtual care services through Talkspace
- 401(k) with company match
- Company provided life insurance short-term and long-term disability benefits
- Education reimbursement program
- Flexible work schedule with hybrid opportunities
- Charitable Matched Giving and Volunteer Rewards through our Impact Program
- Volunteer time off (VTO) paid by the company
- Career advancement opportunities
**Benefits vary based on position tenure location and employee election**
DNV is a proud equal opportunity employer committed to building an inclusive and diverse workforce. All employment is decided on the basis of qualifications merit or business need without regard to race color religion age sex sexual orientation gender identity national origin disability or protected veteran status. DNV is committed to ensuring equal employment opportunity including providing reasonable accommodations to individuals with a applicants with a physical or mental disability who require a reasonable accommodation for any part of the application or hiring process may contact the North America Recruitment Department (). Information received relating to accommodation will be addressed confidentially.
For more information
Qualifications
What Is Required
- 8 years of experience in application security or secure software engineering with demonstrated responsibility for production software and security controls.
- A degree in computer science cybersecurity engineering or a related field is welcome but not required. Equivalent practical experience is fully recognized.
- Deep application and API security expertise including authentication authorization session management data protection input validation and multi-tenant isolation. This is the core of the role.
- Ability to review write test and improve production-quality code in one or more languages commonly used in cloud applications automation and security engineering.
- Experience leading source-code reviews application and API security testing threat modeling and architecture reviews for complex systems.
- Experience integrating and tuning security tooling in CI/CD and converting findings into risk-based automated controls.
- Production experience with a major cloud provider (Azure AWS or comparable) and practical understanding of cloud identity platform services and the shared-responsibility model.
- Demonstrated ability to set technical direction create reusable capabilities across multiple products and influence senior stakeholders without relying on formal authority.
- Ability to explain material security risk clearly to engineers product leaders executives customers and assurance stakeholders.
- Strong written and verbal English communication skills.
- We conduct pre-employment drug and background screening.
What Is Preferred
- Practical AI-agent security experience including excessive permissions insecure tool invocation untrusted inputs memory or context risks sensitive-data exposure insufficient human oversight and unsafe autonomous action.
- Experience applying AI to security testing code analysis vulnerability triage or security automation.
- Experience securing distributed event-driven multi-tenant or critical enterprise systems where authorization and data boundaries are material risks.
- Container Kubernetes infrastructure-as-code and software-supply-chain security.
- Incident response vulnerability investigation exploit validation and remediation verification.
- Hands-on depth with Veracode Burp Suite Professional or equivalents and practical familiarity with OWASP application API and agentic AI security guidance.
- Certifications are a plus demonstrated hands-on ability matters more. Relevant credentials include OSCP GIAC GWAPT GWEB GCSA AZ-500 AWS Certified Security - Specialty CISSP or CCSP.
*Immigration-related employment benefits for example visa sponsorship are not available for this position*
Required Experience:
Staff IC
About Company
Driven by our purpose of safeguarding life, property and the environment, DNV enables organizations to advance the safety and sustainability of their business.