{"schemaVersion":"jobsearcher.job.v1","id":"5c4abab03ac9c8b3240b52f2","url":"https://jobsearcher.com/jobs/5c4abab03ac9c8b3240b52f2","canonicalUrl":"https://jobsearcher.com/jobs/5c4abab03ac9c8b3240b52f2","title":"Lead Cybersecurity - Application Security Engineer - Dynamic, Runtime & API Security","description":"This position requires office presence of a minimum of 5 days per week and is only located in the location(s) posted. No relocation is offered.\r\nJoin AT&T and reimagine the communications and technologies that connect the world. Our Chief Security Office ensures that our assets are safeguarded through truthful transparency, enforce accountability and master cybersecurity to stay ahead of threats. Bring your bold ideas and fearless risk-taking to redefine connectivity and transform how the world shares stories and experiences that matter. When you step into a career with AT&T, you won't just imagine the future-you'll create it.\r\nWe are seeking an Application Security Engineer to strengthen the security of our applications and APIs through a combination of dynamic application security testing (DAST), runtime application self-protection (RASP), and API security engineering. This is an application security engineering role, not a traditional security operations position.\r\nThe ideal candidate is a security-minded engineer with strong hands-on experience in web application and API security, who understands modern application attacks and can translate that understanding into practical testing, protection, and remediation strategies. This role sits at the intersection of AppSec engineering and production defense, with responsibility for identifying exploitable vulnerabilities both before deployment and while applications are running in production, reducing risk from active attacks, misuse, and exposed application behavior.\r\nThis candidate will also evaluate and implement AI-assisted security capabilities to improve coverage, prioritization, and speed — such as intelligent scan orchestration, alert triage, anomaly detection for API abuse, and developer-facing remediation guidance — while ensuring results are valid, measurable, explainable, and safe for production use.\r\nJob Summary\r\nYou will own and scale dynamic security capabilities across the Software Delivery Lifecycle (SDLC) and production, with a strong emphasis on:\r\nDAST automation and integration into CI/CD pipelines\r\nRASP and in-process runtime protection (e.g., JVM/.NET CLR instrumentation)\r\nAPI Security engineering for internal and external/internet-facing endpoints, including edge/API gateway protections and continuous API discovery (shadow/zombie APIs)\r\nThis role is best suited for a candidate with an application security mindset first: someone who can assess real-world exploitability, validate findings, work directly with developers on durable remediation, and build or extend automation in code when existing tooling does not fully solve the problem.\r\nYou'll partner closely with security teams, platform teams, and developers to define policy, deploy controls safely, tune security tool detections, reduce false positives, and measurably improve security outcomes.\r\nDetailed Job Description\r\nThis role focuses on active defense for web applications and APIs through a combination of security testing, runtime instrumentation, and API protection. The candidate will help design and mature security programs that combine:\r\nDynamic application and API testing to identify exploitable vulnerabilities, logic weaknesses, and misconfigurations as early as possible\r\nRuntime protection and instrumentation via runtime security principals and tools such as RASP to detect and, where appropriate, block exploit attempts in production, with an emphasis on protecting API traffic, application workflows, and business logic\r\nAPI security capabilities such as API gateway onboarding and policy enforcement, abuse prevention (e.g., scraping/bots), technical reviews and deep-dives, and continuous discovery of undocumented, unmanaged, or exposed APIs\r\nSuccess in this role requires deep application security knowledge — including web and API attack patterns, authentication and authorization weaknesses, exploitability analysis, and vulnerability remediation — as well as ability to script, automate, integrate, and build lightweight solutions when commercial tooling is insufficient.\r\nThe right candidate will be comfortable moving between hands-on security testing, technical analysis, developer partnership, and security engineering automation, with a focus on reducing meaningful application risk.\r\nKey Responsibilities\r\nAI-Assisted Security Engineering\r\nIdentify practical opportunities to apply AI-assisted approaches across DAST, API testing, runtime telemetry, and security workflows (e.g., prioritization, correlation, anomaly detection, automated enrichment, and remediation support).\r\nImplement AI-enabled workflows to reduce false positives, improve triage efficiency, and accelerate remediation (e.g., intelligent deduplication, exploitability scoring, and auto-generated developer guidance with human review).\r\nPartner with platform and engineering teams to integrate AI-assisted and automated security capabilities into pipelines and operational processes in a measurable, repeatable, and secure way.\r\nDAST & Dynamic Testing (Scale and Automation)\r\nOwn the DAST lifecycle, including onboarding, authenticated scanning, scan orchestration, environment readiness, tuning, and false-positive reduction.\r\nIntegrate DAST and automated API testing into CI/CD pipelines using repeatable, maintainable security-as-code patterns.\r\nCreate standards and runbooks for scan profiles, test data, authentication/session handling, and release readiness criteria.\r\nPerform triage and validate exploitability of findings, distinguishing between theoretical issues and meaningful application risk.\r\nTranslate findings into clear, actionable developer remediation guidance, and partner with teams to verify effective fixes.\r\nAPI Security Engineering (Internet-Facing, Gateway, Discovery)\r\nPartner with API gateway and edge teams to implement and tune security controls such as schema/contract validation, request filtering, threat protections, rate limiting, and throttling.\r\nDrive API discovery and inventory capabilities to identify and govern \"shadow\" and \"zombie\" APIs and establish processes to bring them under security review and lifecycle management.\r\nPerform and automate security testing aligned to the OWASP API Security Top 10, including authorization failures such as BOLA/BFLA.\r\nAssess API exposure and abuse risk, including authentication/authorization weaknesses, object access patterns, input validation issues, data leakage, and business logic abuse.\r\nHelp implement protections against abuse of exposed endpoints, including bot/automation defenses, scraping prevention, and volumetric misuse controls.\r\nRASP & Runtime Active Defense (In-Process Instrumentation)\r\nDeploy, configure, and tune runtime security solutions (such as RASP) integrated into application runtimes (e.g., JVM, .NET CLR) to monitor execution and defend against attacks in production.\r\nEstablish safe rollout patterns (detect-only > tuned detection > selective enforcement), with guardrails to minimize performance impact and avoid breaking application behavior.\r\nAnalyze runtime telemetry to identify attack patterns such as injection attempts, exploitation chains, abnormal access behavior, and policy violations.\r\nTune runtime protections based on observed application behavior and threat patterns, with a focus on reducing exploitability while supporting development teams in achieving long-term remediation.\r\nCollaborate closely with developers and architects to ensure runtime protections complement, rather than replace, secure design and code-level fixes.\r\nSecurity Engineering & Collaboration\r\nBuild and maintain metrics that reflect meaningful security outcomes, such as coverage, false-positive rate, exploit validation rate, time-to-triage, and time-to-remediation.\r\nDevelop automation, integrations, scripts, and lightweight internal tooling to improve testing coverage, reduce manual effort, and extend security capabilities where needed.\r\nCreate documentation, templates, and self-service enablement that help engineering teams adopt secure patterns and scale security practices.\r\nSupport application/API-related security investigations by providing technical analysis, exploit context, and remediation guidance.\r\nQualifications / Requirements / Skills\r\n5+ years (or equivalent) of experience in application security, product security, offensive security, or secure software engineering with strong hands-on technical depth.\r\nStrong hands-on experience in web application and API security, including vulnerability identification, exploit validation, remediation support, and secure design considerations.\r\nDemonstrated ability to evaluate, implement, and operationalize AI-assisted security tooling/workflows (build vs. buy), with a focus on measurable improvements in signal quality, coverage, and remediation efficiency.\r\nDemonstrated experience scaling DAST and automated dynamic testing, including authenticated scanning, scan tuning, and CI/CD integration.\r\nStrong expertise in API security, including OAuth2/OIDC, JWT, API gateways, authorization testing, and testing techniques for REST and GraphQL APIs.\r\nPractical experience implementing and tuning RASP or similar in-process runtime protections in production environments.\r\nDeep understanding of the OWASP Top 10 and OWASP API Security Top 10, especially authorization failures (BOLA/BFLA), injection, SSRF, deserialization, security misconfiguration, and business logic abuse.\r\nAbility to write code and build technical solutions to automate workflows, develop integrations, create test harnesses/utilities, or build lightweight internal security tools when needed.\r\nProficiency in one or more scripting/programming languages such as Python, Go, JavaScript, or Bash, with demonstrated ability to apply coding skills to security engineering problems.\r\nStrong understanding of modern application architectures, including APIs, microservices, cloud-native design patterns, authentication flows, and runtime environments.\r\nWorking knowledge of cloud-native platforms and production concepts (containers, Kubernetes, observability/logging/tracing), with the ability to use that knowledge in support of application security engineering.\r\nStrong communication skills and the ability to translate security findings into clear, prioritized engineering actions for developers and stakeholders.\r\nNice-to-Haves / Preferred or Desired Skills\r\nExperience developing internal security tools, custom integrations, reusable libraries, or testing frameworks to extend AppSec capabilities.\r\nBackground in offensive security, adversarial testing, bug bounty, web exploitation, or vulnerability research.\r\nExperience applying analytics/ML concepts to security telemetry (behavior baselining, anomaly detection, clustering/deduplication) for APIs and runtime signals.\r\nFamiliarity with AI-assisted secure SDLC use cases such as code/query generation for test cases, guided threat modeling, and intelligent fuzzing, with strong validation practices.\r\nExperience defining quality metrics for AI outputs (precision/recall proxies, FP/FN tracking, drift detection) and operating feedback loops.\r\nExperience with API discovery platforms and managing shadow/zombie API reduction programs (inventory, ownership, governance workflows).\r\nHands-on experience with GraphQL-specific risks, including introspection exposure, depth/complexity attacks, and field-level authorization weaknesses.\r\nExperience designing safe enforcement strategies for production protections, including progressive rollout, canarying, SLO awareness, and performance testing.\r\nFamiliarity with service mesh patterns (mTLS, traffic policies) and edge protections (WAF/WAAP concepts) as they relate to API protection.\r\nRelevant certifications such as OSWE, GIAC GWAPT/GWEB, or similar hands-on application security credentials.\r\nJoining our team comes with amazing perks and benefits\r\nMedical/Dental/Vision coverage\r\n401(k) plan\r\nTuition reimbursement program\r\nPaid Time Off and Holidays (based on date of hire, at least 23 days of vacation each year and 9 company-designated holidays)\r\nPaid Parental Leave\r\nPaid Caregiver Leave\r\nAdditional sick leave beyond what state and local law require may be available but is unprotected\r\nAdoption Reimbursement\r\nDisability Benefits (short term and long term)\r\nLife and Accidental Death Insurance\r\nSupplemental benefit programs: critical illness/accident hospital indemnity/group legal\r\nEmployee Assistance Programs (EAP)\r\nExtensive employee wellness programs\r\nEmployee discounts up to 50% off on eligible AT&T mobility plans and accessories,\r\nAT&T internet (and fiber where available) and AT&T phone.\r\nWeekly Hours: 40\r\nTime Type: Regular\r\nLocation: Alpharetta, Georgia, Atlanta, Georgia, Bedminster, New Jersey, Bothell, Washington, Dallas, Texas, Middletown, New Jersey, USA:NC:Charlotte / Research Dr - Dat:9139 Research Dr\r\nSalary Range: $141,300.00 - $237,400.00\r\nIt is the policy of AT&T to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, AT&T will provide reasonable accommodations for qualified individuals with disabilities. AT&T is a fair chance employer and does not initiate a background check until an offer is made.\r\nJ-18808-Ljbffr","company":"Dormont Manufacturing Company","rawCompany":"dormont manufacturing company","city":"Whitehall","state":"NY","isRemote":false,"isActive":false,"createdAt":"2026-07-16T02:15:19.726Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.04","title":"Penetration Testers","slug":"penetration-testers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Lead Cybersecurity - Application Security Engineer - Dynamic, Runtime & API Security","description":"This position requires office presence of a minimum of 5 days per week and is only located in the location(s) posted. No relocation is offered.\r\nJoin AT&T and reimagine the communications and technologies that connect the world. Our Chief Security Office ensures that our assets are safeguarded through truthful transparency, enforce accountability and master cybersecurity to stay ahead of threats. Bring your bold ideas and fearless risk-taking to redefine connectivity and transform how the world shares stories and experiences that matter. When you step into a career with AT&T, you won't just imagine the future-you'll create it.\r\nWe are seeking an Application Security Engineer to strengthen the security of our applications and APIs through a combination of dynamic application security testing (DAST), runtime application self-protection (RASP), and API security engineering. This is an application security engineering role, not a traditional security operations position.\r\nThe ideal candidate is a security-minded engineer with strong hands-on experience in web application and API security, who understands modern application attacks and can translate that understanding into practical testing, protection, and remediation strategies. This role sits at the intersection of AppSec engineering and production defense, with responsibility for identifying exploitable vulnerabilities both before deployment and while applications are running in production, reducing risk from active attacks, misuse, and exposed application behavior.\r\nThis candidate will also evaluate and implement AI-assisted security capabilities to improve coverage, prioritization, and speed — such as intelligent scan orchestration, alert triage, anomaly detection for API abuse, and developer-facing remediation guidance — while ensuring results are valid, measurable, explainable, and safe for production use.\r\nJob Summary\r\nYou will own and scale dynamic security capabilities across the Software Delivery Lifecycle (SDLC) and production, with a strong emphasis on:\r\nDAST automation and integration into CI/CD pipelines\r\nRASP and in-process runtime protection (e.g., JVM/.NET CLR instrumentation)\r\nAPI Security engineering for internal and external/internet-facing endpoints, including edge/API gateway protections and continuous API discovery (shadow/zombie APIs)\r\nThis role is best suited for a candidate with an application security mindset first: someone who can assess real-world exploitability, validate findings, work directly with developers on durable remediation, and build or extend automation in code when existing tooling does not fully solve the problem.\r\nYou'll partner closely with security teams, platform teams, and developers to define policy, deploy controls safely, tune security tool detections, reduce false positives, and measurably improve security outcomes.\r\nDetailed Job Description\r\nThis role focuses on active defense for web applications and APIs through a combination of security testing, runtime instrumentation, and API protection. The candidate will help design and mature security programs that combine:\r\nDynamic application and API testing to identify exploitable vulnerabilities, logic weaknesses, and misconfigurations as early as possible\r\nRuntime protection and instrumentation via runtime security principals and tools such as RASP to detect and, where appropriate, block exploit attempts in production, with an emphasis on protecting API traffic, application workflows, and business logic\r\nAPI security capabilities such as API gateway onboarding and policy enforcement, abuse prevention (e.g., scraping/bots), technical reviews and deep-dives, and continuous discovery of undocumented, unmanaged, or exposed APIs\r\nSuccess in this role requires deep application security knowledge — including web and API attack patterns, authentication and authorization weaknesses, exploitability analysis, and vulnerability remediation — as well as ability to script, automate, integrate, and build lightweight solutions when commercial tooling is insufficient.\r\nThe right candidate will be comfortable moving between hands-on security testing, technical analysis, developer partnership, and security engineering automation, with a focus on reducing meaningful application risk.\r\nKey Responsibilities\r\nAI-Assisted Security Engineering\r\nIdentify practical opportunities to apply AI-assisted approaches across DAST, API testing, runtime telemetry, and security workflows (e.g., prioritization, correlation, anomaly detection, automated enrichment, and remediation support).\r\nImplement AI-enabled workflows to reduce false positives, improve triage efficiency, and accelerate remediation (e.g., intelligent deduplication, exploitability scoring, and auto-generated developer guidance with human review).\r\nPartner with platform and engineering teams to integrate AI-assisted and automated security capabilities into pipelines and operational processes in a measurable, repeatable, and secure way.\r\nDAST & Dynamic Testing (Scale and Automation)\r\nOwn the DAST lifecycle, including onboarding, authenticated scanning, scan orchestration, environment readiness, tuning, and false-positive reduction.\r\nIntegrate DAST and automated API testing into CI/CD pipelines using repeatable, maintainable security-as-code patterns.\r\nCreate standards and runbooks for scan profiles, test data, authentication/session handling, and release readiness criteria.\r\nPerform triage and validate exploitability of findings, distinguishing between theoretical issues and meaningful application risk.\r\nTranslate findings into clear, actionable developer remediation guidance, and partner with teams to verify effective fixes.\r\nAPI Security Engineering (Internet-Facing, Gateway, Discovery)\r\nPartner with API gateway and edge teams to implement and tune security controls such as schema/contract validation, request filtering, threat protections, rate limiting, and throttling.\r\nDrive API discovery and inventory capabilities to identify and govern \"shadow\" and \"zombie\" APIs and establish processes to bring them under security review and lifecycle management.\r\nPerform and automate security testing aligned to the OWASP API Security Top 10, including authorization failures such as BOLA/BFLA.\r\nAssess API exposure and abuse risk, including authentication/authorization weaknesses, object access patterns, input validation issues, data leakage, and business logic abuse.\r\nHelp implement protections against abuse of exposed endpoints, including bot/automation defenses, scraping prevention, and volumetric misuse controls.\r\nRASP & Runtime Active Defense (In-Process Instrumentation)\r\nDeploy, configure, and tune runtime security solutions (such as RASP) integrated into application runtimes (e.g., JVM, .NET CLR) to monitor execution and defend against attacks in production.\r\nEstablish safe rollout patterns (detect-only > tuned detection > selective enforcement), with guardrails to minimize performance impact and avoid breaking application behavior.\r\nAnalyze runtime telemetry to identify attack patterns such as injection attempts, exploitation chains, abnormal access behavior, and policy violations.\r\nTune runtime protections based on observed application behavior and threat patterns, with a focus on reducing exploitability while supporting development teams in achieving long-term remediation.\r\nCollaborate closely with developers and architects to ensure runtime protections complement, rather than replace, secure design and code-level fixes.\r\nSecurity Engineering & Collaboration\r\nBuild and maintain metrics that reflect meaningful security outcomes, such as coverage, false-positive rate, exploit validation rate, time-to-triage, and time-to-remediation.\r\nDevelop automation, integrations, scripts, and lightweight internal tooling to improve testing coverage, reduce manual effort, and extend security capabilities where needed.\r\nCreate documentation, templates, and self-service enablement that help engineering teams adopt secure patterns and scale security practices.\r\nSupport application/API-related security investigations by providing technical analysis, exploit context, and remediation guidance.\r\nQualifications / Requirements / Skills\r\n5+ years (or equivalent) of experience in application security, product security, offensive security, or secure software engineering with strong hands-on technical depth.\r\nStrong hands-on experience in web application and API security, including vulnerability identification, exploit validation, remediation support, and secure design considerations.\r\nDemonstrated ability to evaluate, implement, and operationalize AI-assisted security tooling/workflows (build vs. buy), with a focus on measurable improvements in signal quality, coverage, and remediation efficiency.\r\nDemonstrated experience scaling DAST and automated dynamic testing, including authenticated scanning, scan tuning, and CI/CD integration.\r\nStrong expertise in API security, including OAuth2/OIDC, JWT, API gateways, authorization testing, and testing techniques for REST and GraphQL APIs.\r\nPractical experience implementing and tuning RASP or similar in-process runtime protections in production environments.\r\nDeep understanding of the OWASP Top 10 and OWASP API Security Top 10, especially authorization failures (BOLA/BFLA), injection, SSRF, deserialization, security misconfiguration, and business logic abuse.\r\nAbility to write code and build technical solutions to automate workflows, develop integrations, create test harnesses/utilities, or build lightweight internal security tools when needed.\r\nProficiency in one or more scripting/programming languages such as Python, Go, JavaScript, or Bash, with demonstrated ability to apply coding skills to security engineering problems.\r\nStrong understanding of modern application architectures, including APIs, microservices, cloud-native design patterns, authentication flows, and runtime environments.\r\nWorking knowledge of cloud-native platforms and production concepts (containers, Kubernetes, observability/logging/tracing), with the ability to use that knowledge in support of application security engineering.\r\nStrong communication skills and the ability to translate security findings into clear, prioritized engineering actions for developers and stakeholders.\r\nNice-to-Haves / Preferred or Desired Skills\r\nExperience developing internal security tools, custom integrations, reusable libraries, or testing frameworks to extend AppSec capabilities.\r\nBackground in offensive security, adversarial testing, bug bounty, web exploitation, or vulnerability research.\r\nExperience applying analytics/ML concepts to security telemetry (behavior baselining, anomaly detection, clustering/deduplication) for APIs and runtime signals.\r\nFamiliarity with AI-assisted secure SDLC use cases such as code/query generation for test cases, guided threat modeling, and intelligent fuzzing, with strong validation practices.\r\nExperience defining quality metrics for AI outputs (precision/recall proxies, FP/FN tracking, drift detection) and operating feedback loops.\r\nExperience with API discovery platforms and managing shadow/zombie API reduction programs (inventory, ownership, governance workflows).\r\nHands-on experience with GraphQL-specific risks, including introspection exposure, depth/complexity attacks, and field-level authorization weaknesses.\r\nExperience designing safe enforcement strategies for production protections, including progressive rollout, canarying, SLO awareness, and performance testing.\r\nFamiliarity with service mesh patterns (mTLS, traffic policies) and edge protections (WAF/WAAP concepts) as they relate to API protection.\r\nRelevant certifications such as OSWE, GIAC GWAPT/GWEB, or similar hands-on application security credentials.\r\nJoining our team comes with amazing perks and benefits\r\nMedical/Dental/Vision coverage\r\n401(k) plan\r\nTuition reimbursement program\r\nPaid Time Off and Holidays (based on date of hire, at least 23 days of vacation each year and 9 company-designated holidays)\r\nPaid Parental Leave\r\nPaid Caregiver Leave\r\nAdditional sick leave beyond what state and local law require may be available but is unprotected\r\nAdoption Reimbursement\r\nDisability Benefits (short term and long term)\r\nLife and Accidental Death Insurance\r\nSupplemental benefit programs: critical illness/accident hospital indemnity/group legal\r\nEmployee Assistance Programs (EAP)\r\nExtensive employee wellness programs\r\nEmployee discounts up to 50% off on eligible AT&T mobility plans and accessories,\r\nAT&T internet (and fiber where available) and AT&T phone.\r\nWeekly Hours: 40\r\nTime Type: Regular\r\nLocation: Alpharetta, Georgia, Atlanta, Georgia, Bedminster, New Jersey, Bothell, Washington, Dallas, Texas, Middletown, New Jersey, USA:NC:Charlotte / Research Dr - Dat:9139 Research Dr\r\nSalary Range: $141,300.00 - $237,400.00\r\nIt is the policy of AT&T to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, AT&T will provide reasonable accommodations for qualified individuals with disabilities. AT&T is a fair chance employer and does not initiate a background check until an offer is made.\r\nJ-18808-Ljbffr","datePosted":"2026-07-16T02:15:19.726Z","dateModified":"2026-07-16T02:15:19.726Z","hiringOrganization":{"@type":"Organization","name":"Dormont Manufacturing Company","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Whitehall","addressRegion":"NY","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"5c4abab03ac9c8b3240b52f2"},"url":"https://jobsearcher.com/jobs/5c4abab03ac9c8b3240b52f2"}}