Lead Application Security Engineer

Carters Inc.Atlanta, GA

About The Position

The Lead Security Engineer – Application Security is a senior technical leader within the IT Security team, reporting to the Sr. Director, IT Security. This role serves as the primary architect and subject matter expert for application security across the enterprise, owning the AppSec program strategy, standards, and tooling roadmap. Working autonomously and with broad organizational influence, the Lead exercises expert-level judgment to define how security is built into software from the ground up. A critical distinction of this role is hands-on experience with artificial intelligence: the Lead is expected to build, secure, and govern AI-powered capabilities as they become embedded in Carter’s applications and infrastructure. The Lead acts as a force multiplier – elevating the security posture of every engineering team they engage with and translating complex risk into clear, actionable direction for both technical and business stakeholders.

Requirements

  • 5+ years of application security, software engineering, or secure code review experience
  • Strong proficiency in one or more languages (e.g., Python, Java, JavaScript, Go) with ability to perform in-depth code review and threat modeling.
  • Experience with SAST/DAST tooling (e.g., Snyk, SonarQube, Semgrep, Checkmarx, Burp Suite, OWASP ZAP) and ownership of AppSec program design.
  • Proven communication and presentation skill set abilities with multilevel stakeholders
  • Ability to meet deadlines and work with management across various disciplines
  • Proven collaborative experience with cross functional teams
  • Ability to perform on-call duties during off-hours and holidays
  • An adaptable and flexible attitude towards changing business needs

Nice To Haves

  • Bachelor’s degree in computer science or related field
  • Demonstrated experience leading or conducting red team, penetration testing, or adversarial simulation exercises.
  • Experience designing and scaling security observability pipelines, including log analysis and application-layer telemetry.
  • Working knowledge of PCI-DSS, NIST, OWASP, and other regulatory frameworks; experience representing security in audit and compliance reviews.
  • Proven experience securing cloud-native or hybrid-cloud application environments (AWS, Azure, or GCP).
  • Hands-on experience building, deploying, or integrating AI/ML-powered tools, combined with the ability to assess and govern their security posture (prompt injection, data leakage, model supply chain risks).
  • Proven ability to define and enforce security standards across engineering organizations; prior experience owning a security capability or domain.
  • Security+, ISC2 CC, CompTIA A+, CompTIA Network+, SSCP, CCT, GWEB, CSSLP, CEH, or OSCP certifications

Responsibilities

  • Defining and owning the enterprise application security architecture, standards, and secure-by-default patterns
  • Establishing and maintaining AppSec tooling strategy, evaluating vendors, and driving adoption across engineering teams
  • Leading threat modeling sessions for critical applications and new product features
  • Serving as the final technical authority on AppSec decisions, including security design reviews and architecture signoffs
  • Conducting and directing advanced secure code reviews, SAST/DAST assessments, and manual penetration testing across web, mobile, and API surfaces
  • Owning API security standards including REST and GraphQL, enforcing OWASP API Top 10 controls and authentication/authorization design patterns
  • Driving vulnerability triage, risk prioritization, and remediation accountability across development teams at scale
  • Owning the DevSecOps toolchain: designing, deploying, and maturing security gates within CI/CD pipelines enterprise-wide
  • Acting as the primary security partner to engineering leadership, embedding security into system design, SDLC processes, and platform decisions
  • Driving continuous improvement of AppSec metrics, dashboards, and KPIs to demonstrate program maturity and risk reduction
  • Hands-on building and deploying AI-powered security tooling and automation (e.g., AI-assisted code review, threat detection, or vulnerability triage)
  • Securing AI/ML integrations and connectors: assessing prompt injection, data leakage, model supply chain, and third-party AI service risks
  • Developing and enforcing AI governance policies: defining acceptable use, security review gates, and risk acceptance criteria for AI adoption
  • Representing the IT Security team in architecture reviews, cross-functional planning, and executive risk reporting
  • Owning security policy and standards documentation relevant to application security, AI use, and API governance
  • Leading AppSec representation in PCI-DSS, NIST, and OWASP compliance audits and evidence collection

Benefits

  • Meaningful work
  • Constant learning
  • Genuine people
  • Community guided by core values that promote inclusion and innovation
  • Training and development programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service