AI-Application Security Engineer
duvari group · Saint Louis, MO
$150,000
Jun 29, 2026
Saint Louis, MO
Jul 21, 2026
What this job asks for AI summary
A hands-on engineering role focused on embedding security into cloud-native applications and AI systems. Day-to-day work spans configuring and automating security testing tools (SAST, DAST, SCA, API, and AI-specific), integrating controls into CI/CD pipelines, reviewing AI platforms and models for risk, and guiding development teams on secure coding practices. Best suited to someone with a software development background who wants to build security capabilities rather than just audit for gaps.
Senior level · National · Full-time
“or” means any one of them counts — you don't need all of them.
Posted 2 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (6)
No work location or metro area is specified in the posting; CBSA is left blank. The role is described as direct hire (full-time) but no remote/hybrid policy is stated — remote is defaulted to false.
SOC classification is a genuine judgment call: the role sits at the intersection of security engineering (15-1212) and software/DevSecOps engineering (15-1252). The emphasis on building/automating security tooling and a required software development background pulls toward 15-1252, but the primary framing — AppSec, vulnerability management, AI security reviews, and security posture — tips it to 15-1212.
AWS is listed under Required as 'preferably AWS', making it a hard gate on cloud experience with AWS as the named preference; Azure and GCP are noted as alternatives a hiring manager would likely accept.
C# and Python appear together under Required as 'ideally with languages such as C# or Python or similar object-oriented languages' — treated as a hard gate on OO development experience with C# as primary and Python as the named alternative.
SAST, DAST, SCA, GitHub, Azure DevOps, LLMs, and Azure appear only in the 'technologies that may include' stack narrative section, not in the Required block, so they are treated as preferred context rather than hard gates.
No total years of experience, degree requirement, compensation, or security clearance is stated in the posting.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.