{"id":1455175,"url":"https://alion.io/job/bloomberg-industry-application-security-engineer-3","title":"Application Security Engineer 3","company":{"id":1898606,"name":"Bloomberg Industry","domain":"bloombergindustry.com","url":"https://alion.io/company/bloombergindustry","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":null},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Arlington, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":155000,"max":185000,"currency":"USD","period":"year","gross":null,"usd_annual":185000},"salary_estimate":null,"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"CI/CD","optional":false},{"name":"JavaScript","optional":false},{"name":"Kubernetes","optional":false},{"name":"LLM","optional":false},{"name":"Model Context Protocol","optional":false},{"name":"NIST 800-53","optional":false},{"name":"NIST AI RMF","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP ASVS","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Python","optional":false},{"name":"Threat Modeling","optional":false}],"status":"live","first_seen_at":"2026-07-01T00:00:00Z","employer_posted_date":"2026-07-01","last_verified_at":"2026-10-04T22:21:12Z","board_verified":true,"closed_at":null,"days_open":96,"trust":{"level":"stale","repost_count":0,"flags":["stale"],"days_open":95},"description":"Responsible for leading application security engineering efforts, designing scalable security architectures, performing advanced risk assessments, integrating security across the SDLC, driving AI-related security controls, evaluating vendor solutions, scaling automation, and contributing to incident response and strategic security improvements.About the Team:\nBloomberg Industry Group's Application Security team is focused on providing best-in-class security for all internal and external applications. We are constantly evolving our security practices to tackle modern-day threats and ensure our applications remain secure.\nJob Summary:\nAs an Application Security Engineer III, you will lead security engineering initiatives, perform advanced risk assessments, and design scalable security controls across critical applications. You will serve as a subject matter expert (SME) in application, guiding engineering teams, influencing security strategy, and driving automation across the SDLC.\nThis role requires deep technical expertise, leadership potential, and the ability to shape long-term Application Security direction.\nWhat You Will Do:\nDesign and implement security architectures and controls for large-scale, cloud-native applications.\nConduct in-depth risk assessments, including penetration testing and code reviews.\nCollaborate with developers and DevOps teams to integrate security at all stages of the software development lifecycle (SDLC).\nDrive security for AI-powered features by defining secure architectures, assessing AI/ML risks, and implementing advanced testing and controls for AI models, agents, and MCP servers.\nIdentify areas of improvements in security tools and practices, and remediate the identified gap by implementing innovative solutions.\nEvaluate third-party security tools and vendor-provided controls for technical effectiveness, enterprise fit, and alignment with organization’s security architecture and standards.\nCollaborate with vendors to provide actionable technical feedback, drive product improvements, and ensure controls are implemented and configured appropriately for Bloomberg Industry Group’s environment.\nBuild, improve, and scale security automation, integrating tooling across CI/CD pipelines and cloud platforms.\nProvide guidance to junior engineers and cross-functional teams on security best practices.\nParticipate in incident response efforts and investigations into security incidents.\nStay ahead of the curve by keeping informed of industry trends and emerging threats, applying this knowledge to continually improve security.\nYou Need to Have:\nDeep expertise in application security, secure software design, and risk management, including frameworks such as OWASP ASVS, OWASP Top 10, and NIST 800-53.\nExtensive experience conducting complex security assessments and building automated security controls for large engineering environments.\nProficiency in multiple programming languages (e.g., Python, Java, JavaScript) and hands-on experience with SAST, DAST, SCA, IaC, container, and cloud security tools.\nStrong understanding of modern architectures (cloud-native, microservices, Kubernetes, containers, serverless) and DevSecOps processes.\nAdvanced understanding of AI/ML security, including model vulnerability analysis, AI threat modeling, secure LLM integration patterns, and familiarity with NIST AI RMF or OWASP Top 10 for LLMs.\n5-7 years of relevant experience in Application Security, AppSec engineering, Cloud Security, or Software Engineering.\nWe would Love to See :\nCertifications such as\nAWS Certified Security - Specialty\nCSSLP or CISSP\nCertified DevSecOps Expert (CDE) or equivalent\nA bachelor's degree in information security, Computer Science, or a related field, or equivalent experience.\nCompensation Range:\n$155,000.00-$185,000.00Placement in the salary range will be decided upon completion of the interview process. Salary determination will be determined based on factors including but not limited to relevant experience, demonstrated skills related to the requirements of the role, education, certifications, and geographic location.\nEqual Opportunity\nBloomberg Industry Group maintains a continuing policy of non-discrimination in employment. It is Bloomberg Industry Group’s policy to provide equal opportunity and access for all persons, and the Company is committed to attracting, retaining, developing, and promoting the most qualified individuals without regard to age, ancestry, color, gender identity or expression, genetic predisposition or carrier status, marital status, national or ethnic origin, race, religion or belief, sex, sexual orientation, sexual and other reproductive health decisions, parental or caring status, physical or mental disability, pregnancy or maternity/parental leave, protected veteran status, status as a victim of domestic violence, or any other classification protected by applicable law (“Protected Characteristic”). Bloomberg prohibits treating applicants or employees less favorably in connection with the terms and conditions of employment, in all phases of the employment process, because of one or more Protected Characteristics (“Discrimination”).","description_format":"text","description_chars":5183,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Parental leave"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Artificial Intelligence","Professional Services","Publishing"],"lifecycle":[{"event":"open","at":"2026-09-29T09:25:16Z"}],"visa":[],"liveness":{"score":9,"band":"cold","label":"Long shot","p_open":1,"p_active":0.33,"p_room":0.28,"age_days":95,"expected_fill_days":25,"reasons":["conf:1","velocity","win:tail","crowd:"],"computed_at":"2026-10-04T05:45:00Z"},"pay":{"stated_usd_annual":185000,"is_top_pay":true},"html_url":"https://alion.io/job/bloomberg-industry-application-security-engineer-3","json_url":"https://alion.io/job/bloomberg-industry-application-security-engineer-3.json","meta":{"generated_at":"2026-10-05T01:34:57Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2081,"day_limit":5000,"remaining_today":2919,"minute_limit":60,"resets_at":"2026-10-06T00:00:00Z"}}}