Principal Application & AI Security Engineer

DNVOak Brook, IL
Hybrid

About The Position

DNV Energy Systems' Platform Services is seeking a Principal Application & AI Security Engineer. This role is crucial for securing software products and digital platforms, especially as we evolve towards agentic AI architectures. The position requires a senior technical leader who can improve code, design controls, model threats, conduct security testing, and collaborate with engineering teams to implement durable fixes. The primary goal is to eliminate recurring vulnerability classes, reduce exposure, and make secure practices the easiest path. This role is based in Houston, TX or Oakland, CA, with a hybrid schedule requiring employees to typically work three days per week from a DNV office or client location. Further role-specific details will be provided during the interview process.

Requirements

  • 8+ years of experience in application security or secure software engineering, with demonstrated responsibility for production software and security controls.
  • Deep application and API security expertise, including authentication, authorization, session management, data protection, input validation, and multi-tenant isolation.
  • Ability to review, write, test, and improve production-quality code in one or more languages commonly used in cloud applications, automation, and security engineering.
  • Experience leading source-code reviews, application and API security testing, threat modeling, and architecture reviews for complex systems.
  • Experience integrating and tuning security tooling in CI/CD and converting findings into risk-based automated controls.
  • Production experience with a major cloud provider (Azure, AWS, or comparable) and practical understanding of cloud identity, platform services, and the shared-responsibility model.
  • Demonstrated ability to set technical direction, create reusable capabilities across multiple products, and influence senior stakeholders without relying on formal authority.
  • Ability to explain material security risk clearly to engineers, product leaders, executives, customers, and assurance stakeholders.
  • Strong written and verbal English communication skills.
  • Pre-employment drug and background screening.

Nice To Haves

  • Practical AI-agent security experience, including excessive permissions, insecure tool invocation, untrusted inputs, memory or context risks, sensitive-data exposure, insufficient human oversight, and unsafe autonomous action.
  • Experience applying AI to security testing, code analysis, vulnerability triage, or security automation.
  • Experience securing distributed, event-driven, multi-tenant, or critical enterprise systems where authorization and data boundaries are material risks.
  • Container, Kubernetes, infrastructure-as-code, and software-supply-chain security.
  • Incident response, vulnerability investigation, exploit validation, and remediation verification.
  • Hands-on depth with Veracode, Burp Suite Professional, or equivalents, and practical familiarity with OWASP application, API, and agentic AI security guidance.
  • Relevant credentials include OSCP, GIAC GWAPT, GWEB, GCSA, AZ-500, AWS Certified Security - Specialty, CISSP, or CCSP.

Responsibilities

  • Build security into delivery and platform engineering: Design and implement scalable controls for software and AI supply chains (dependency integrity, SCA, SAST, DAST, build provenance, artifact security, secrets protection, container and IaC assurance, SBOMs). Implement platform-level controls (policy as code, authorization enforcement, data-access guardrails, secure defaults, reusable reference implementations). Design AI-assisted security-testing environments, automated attack scenarios, and security-regression suites. Implement risk-based quality gates with documented exception paths, accountable ownership, and service-level expectations.
  • Find, prove, and fix material weaknesses: Review source code, APIs, and application designs for weaknesses in authentication, authorization, session management, input handling, data-access scope, and multi-tenant isolation. Conduct authorized application, API, and AI security testing, including targeted manual testing of business logic and trust boundaries. Work alongside engineers to remediate root causes, validate fixes, create regression tests, and implement preventive controls or secure patterns. Establish vulnerability triage and remediation practices, including exploitability and exposure analysis, accountable ownership, target dates, exception handling, retesting, closure evidence, and escalation of overdue material risk.
  • Secure AI agents and AI-assisted development: Establish agent identities and least-privilege permissions. Govern model, tool, skill, connector, plug-in, memory, and data access, including tenant isolation and boundaries. Validate untrusted inputs and tool outputs, and design defenses against prompt injection, goal manipulation, tool misuse, privilege escalation, sensitive-data exposure, memory poisoning, unsafe delegation, and cascading failures. Assess multi-agent workflows to implement approval requirements for consequential actions, runtime policy enforcement, rate and resource limits, and tamper-resistant auditability.
  • Shape secure architecture at scale: Lead high-risk threat modeling and architecture reviews for complex systems. Develop and demonstrate reusable secure patterns for microservices, APIs, event-driven systems, containers, Kubernetes, cloud services, and agentic AI applications. Contribute to platform roadmaps and engineering practices. Provide evidence to continuously improve enterprise standards and assurance expectations.
  • Support engineering teams and incidents: Partner across distributed engineering hubs to drive adoption of secure patterns and automation. Translate findings into prioritized, actionable engineering work. Mentor senior engineers and technical leaders in secure design, development, threat modeling, and remediation. Serve as the application and AI security technical lead during incidents. Represent application and AI security in technical, executive, customer, audit, and assurance discussions.

Benefits

  • Generous paid time off (vacation, sick days, company holidays, personal days)
  • Multiple Medical and Dental benefit plans to choose from, Vision benefits
  • Spending accounts – FSA, Dependent Care, Commuter Benefits, company-seeded HSA
  • Employer-paid, therapist-led, virtual care services through Talkspace
  • 401(k) with company match
  • Company provided life insurance, short-term, and long-term disability benefits
  • Education reimbursement program
  • Flexible work schedule with hybrid opportunities
  • Charitable Matched Giving and Volunteer Rewards through our Impact Program
  • Volunteer time off (VTO) paid by the company
  • Career advancement opportunities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service