Qualifications & Experience 7+ years in cybersecurity, with depth in application security and a working grasp of how AI changes it. Candidates who are deep in AI security and fluent in AppSec are an equally strong fit Client-facing consulting or advisory experience; comfortable briefing executives and defending findings under scrutiny Working knowledge of how AI-enabled applications are built, including model APIs, RAG, vector stores, agent frameworks, and MCP-style tool integrations. Enough depth to engage credibly with engineering teams; client teams handle implementation Familiarity with NIST AI RMF, ISO/IEC 42001, OWASP Top 10 for LLM Applications, and MITRE ATLAS, plus grounding in NIST CSF, ISO 27001, or the CIS Controls Experience advising on secure SDLC, AppSec tooling, and software supply chain security in enterprise environments Strong writing skills; in advisory work, the deliverable is the product Nice to have: CISSP, CSSLP, CCSP, AIGP, or GIAC certifications, and prior work in regulated industries such as financial services, healthcare, or energy Want to learn more about Consulting & Security Services? Check us out on our platform: https://www.wwt.com/consulting-services https://www.wwt.com/category/security-transformation Certain states and localities require employers to post a reasonable estimate of salary range. A reasonable estimate of the current base pay range for this position is $137,200 to $171,500 annually. Actual salary will be based on a variety of factors, including shift, location, experience, skill set, performance, licensure and certification, and business needs. The range for this position in other geographic locations may differ. Certain positions may also be eligible for variable incentive compensation, such as bonuses or commissions, that is not included in the base pay. The well-being of WWT employees is essential. When it comes to our benefits package, WWT has one of the best. We offer the following benefits to all full-time employees: Health and Wellbeing: Health (Medical & Prescription), Dental, and Vision Care, Onsite Health Centers (MO & IL), Employee Assistance Program, Wellness program Financial Benefits: Competitive Pay, Profit Sharing, 401k Plan with Company Matching, Life and Disability Insurance, Flexible Spending Accounts, Tuition Reimbursement Paid Time Off: PTO & Holidays, Parental Leave, Medical Leave, Military Leave, Bereavement, Day of Caring Additional Perks: Family Planning Benefits, Nursing Mothers Benefits, Voluntary Legal, Voluntary Supplemental Accident/Illness/Hospital, Voluntary ID Theft, Pet Insurance, Employee Discount Program Note: This is not an all-encompassing list and should not be used as a complete description of the plan’s benefits. For more information, see our US benefits website at wwt.com/us-benefits. We strive to create an environment where all employees are empowered to succeed based on their skills, performance, and dedication. Our goal is to cultivate a culture of belonging that encourages innovation, collaboration, and respect for all team members, ensuring that WWT remains a great place to work for all! If you require accessibility accommodation(s) or adjustment during any stage of the hiring process, please let your WWT Recruiter know. The recruiter will work with you to understand your needs and help ensure an accessible experience throughout the interview process. World Wide Technology is an Equal Opportunity Employer. If you have any questions or concerns about this posting, please email [email protected] . #LI-TB1 Why WWT? World Wide Technology (WWT) strives to make a new world happen. WWT's work benefits clients and partners as much as it does its people and community across the globe. Founded in 1990, WWT brings together strategy, deep technical expertise and world-class partnerships to help public and private sector organizations design, build and scale intelligent AI, digital, cybersecurity, cloud and infrastructure solutions. Through its Advanced Technology Center (ATC)—a collaborative ecosystem featuring state-of-the-art hardware and software—WWT enables clients and partners to conceptualize, test and validate innovative technology and then deploy solutions at scale using its global integration and distributions capabilities. With more than 14,000 team members and over 60 locations globally, WWT's culture—grounded in core values and leadership philosophies—has been recognized by Fortune® and Great Place to Work for its commitment to innovation, trust and creating a great place to work for all. WWT provides products and services to large enterprise, global service provider and public sector clients in up to 130 countries across six continents. Softchoice, a World Wide Technology company, supports commercial and SMB markets in the U.S. and Canada. Want to work with highly motivated individuals on high-performance teams? Join WWT today! What is the Solutions Consulting & Engineering (SC&E) Team and why join? Solutions Consulting & Engineering is an organization that is Customer Focused and Solutions Led. We deliver end-to-end and emerging solutions to drive customer satisfaction, increase profitability and growth. Our success is enabled by our world-class management consulting, delivery excellence and engineering brilliance. Our goal is to bring together business acumen with full-stack technical know-how to develop innovative solutions for our clients' most complex challenges. Position Overview: WWT's Global Security practice is hiring a Lead Consultant in AI application security. This is a client-facing advisory role. You will work directly with client security organizations, including CISOs, security architects, application security leads, and GRC and risk teams, to assess and strengthen how their security programs address AI adoption across the application portfolio. Enterprise applications increasingly include model APIs, retrieval pipelines, and agent frameworks. Most application security programs were established before any of these existed. You will help clients close that gap: leading readiness and maturity assessments, running threat modeling workshops, advising on control design, and building prioritized roadmaps that extend established AppSec practices to cover AI systems. The engagement model is advisory. Client teams implement and operate the controls; you provide the assessment and the direction. This is a strong fit for a consultant who wants variety across industries and a direct view into how large enterprises are adopting AI. The practice is growing quickly. There is room to help shape the offering as it scales. Key Responsibilities Client Advisory & Delivery Deliver advisory engagements on securing AI-enabled applications: readiness and maturity assessments, threat modeling workshops, governance reviews, gap analyses, and prioritized remediation roadmaps Advise client security teams across the full attack surface of a modern application, spanning established areas such as API security, dependencies, secrets, and CI/CD, along with the exposures AI introduces: prompt injection, model and data supply chain compromise, data poisoning, unsafe output handling, and agent tool misuse and excessive autonomy Guide teams as they extend the programs they already run (threat modeling, secure code review, penetration testing, vulnerability management) to cover models, RAG pipelines, vector stores, and agent frameworks, so AI coverage grows within one program rather than a parallel second one Advise on application security program design: secure SDLC, tooling strategy across SAST, DAST, SCA, and ASPM, including how coverage changes for LLM-backed applications, API security, software supply chain integrity, and secrets and non-human identity hygiene. Deliver recommendations and reference patterns that client engineering teams implement themselves Run workshops and working sessions that bring security, engineering, and governance stakeholders to a shared answer Communicate across two main stakeholder groups: detailed guidance for practitioners, and clear, defensible summaries for executives and boards Lead delivery workstreams within larger engagements and run smaller engagements end to end, managing scope and client expectations alongside a Principal or Practice Director Anchor recommendations in the frameworks clients are measured against, including OWASP (both the application Top 10 and the LLM Top 10), NIST AI RMF, ISO/IEC 42001, MITRE ATLAS, NIST CSF, and ISO 27001 Practice Development & Thought Leadership Contribute to practice IP: assessment methodologies, control catalogs, workshop kits, and briefing materials that make the next engagement better than the last one Support pursuits with scoping input, proposal content, and SOW review Publish and present where it helps the practice, whether that is a blog post, a client briefing, a conference talk, or internal enablement Mentor consultants building depth in this space Collaboration & Ecosystem Integration Work with the client's security organization as your primary audience, and engage their engineering, data science, and platform teams where the guidance has to land Coordinate with WWT peers across cloud security, identity, and infrastructure so the client hears one coherent point of view
Application Security Engineer
Teksystems
Application Security Engineer
Guild Mortgage
Senior Application Security Engineer
TripleLift
Senior Product Security Engineer, Application Security (Remote)
Crowdstrike
Security Engineer, Application Security
GameChanger
Lead Strategic Services Consultant (Application Security)
Black Duck Software, Inc.