{"id":1289774,"url":"https://alion.io/job/millennium-management-application-security-engineer","title":"Application Security Engineer","company":{"id":704283,"name":"Millennium Management","domain":"mlp.com","url":"https://alion.io/company/millennium-management","size_band":"11-50","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Eightfold","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Bengaluru, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":34000,"max_usd":76000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":1098},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AI Agents","optional":false},{"name":"Ansible","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"C#","optional":false},{"name":"C++","optional":false},{"name":"CI/CD","optional":false},{"name":"CloudFormation","optional":false},{"name":"Delinea","optional":false},{"name":"GCP","optional":false},{"name":"GitHub","optional":false},{"name":"HashiCorp Vault","optional":false},{"name":"ISO 27001","optional":false},{"name":"Java","optional":false},{"name":"Jenkins","optional":false},{"name":"Linux","optional":false},{"name":"LLM Guardrails","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Python","optional":false},{"name":"Red Teaming","optional":false},{"name":"SBOM","optional":false},{"name":"Terraform","optional":false},{"name":"Threat Modeling","optional":false},{"name":"Vault","optional":false}],"status":"live","first_seen_at":"2026-06-01T00:00:00Z","employer_posted_date":"2026-06-01","last_verified_at":"2026-09-26T23:06:14Z","board_verified":true,"closed_at":null,"days_open":118,"trust":{"level":"stale","repost_count":0,"flags":["stale"],"days_open":117},"description":"Application Security EngineerThe successful candidate will be a subject matter expert with direct experience in a wide range of security technologies, tools, and methodologies. The role is suited for an experienced Application Security engineer with proven understanding in enterprise security and AI security and will focus on building toolsets and processes to drive adoption of secure practices across the enterprise. The team fosters a collaborative environment and is building a best-in-class program to partner with the business to protect the Firm’s information and computer systems. Millennium is a complex and robust technical environment and securing the Firm from external and internal threats is a top priority.\nPrincipal Responsibilities\nAI Security Strategy: Define and implement security guardrails for Generative AI, LLMs, and Agentic frameworks, ensuring safe enterprise adoption.\n\nAI Risk Management: Conduct specialized threat modeling, red teaming, and risk assessments for AI/ML models (e.g., testing for prompt injection, model theft, and data poisoning).\n\nSecurity Consulting: Lead risk management activities, including application risk assessments, design reviews, and mitigation strategies for IT projects.\n\nLifecycle Engagement: Engage throughout the SDLC to identify vulnerabilities, conduct code reviews/penetration testing, and enforce secure coding standards.\n\nProgram Development: Evangelize AppSec and AI security best practices through developer education, training materials, and outreach.\n\nTooling & Architecture: Design robust security architectures and integrate automated security testing (SAST/DAST/SCA) into CI/CD pipelines.\n\nStakeholder Liaison: Partner with Technology, Trading, Legal, and Compliance to create policies and communicate technical risks to non-technical stakeholders.\n\nQualifications/Skills Required\nBachelor's degree or higher in Computer Science, Computer Engineering, IT Security or related field.\n\n5+ years’ experience working as an Application Security Engineer, Software Engineer, or similar role.\n\nDeep understanding of AI-specific risks (OWASP Top 10 for LLMs) and experience securing applications utilizing LLMs.\n\nExperience working with AI models, Agentic frameworks and security risks associated with AI.\n\nExperience in working with global teams, collaborating on code and presentations.\n\nDemonstrated work experience in hybrid on-premise and Public Cloud environments (AWS/GCP/Azure)\n\nStrong understanding of security architectures, secure configuration principles/coding practices, cryptography fundamentals and encryption protocols.\n\nExperience with common SCM & CI/CD technologies like GitHub, Jenkins, Artifactory, etc. and integrating Security Scanning and Vulnerability Management into the CI/CD Pipelines\n\nFamiliarity with static and dynamic security analysis tools, and SCA/SBOM solutions.\n\nHands on experience with Secrets Management & Password Vault technologies such as Delinea Secret Server and/or Hashicorp Vault, etc.\n\nStrong experience in secure programming in languages such as Python, Java, C++, C#, or similar.\n\nFamiliarity with Infrastructure as Code tools (CloudFormation, Terraform, Ansible, etc.)\n\nFamiliarity with web application security testing tools and methodologies.\n\nKnowledge of various security frameworks and standards such as ISO 27001, NIST, OWASP, etc.\n\nKnowledge of Linux, OS internals and containers is a plus.\n\nCertifications like CISSP, CISM, CompTIA Security+, or CEH are advantageous.","description_format":"text","description_chars":3494,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Hedge Funds & Alternative Investments"],"lifecycle":[{"event":"open","at":"2026-09-26T07:37:06Z"}],"liveness":{"score":7,"band":"cold","label":"Long shot","p_open":1,"p_active":0.259,"p_room":0.28,"age_days":118,"expected_fill_days":33,"reasons":["conf:1","win:tail","crowd:brand"],"computed_at":"2026-09-27T00:12:58Z"},"pay":null,"html_url":"https://alion.io/job/millennium-management-application-security-engineer","json_url":"https://alion.io/job/millennium-management-application-security-engineer.json","meta":{"generated_at":"2026-09-27T00:12:58Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":133,"day_limit":5000,"remaining_today":4867,"minute_limit":60,"resets_at":"2026-09-28T00:00:00Z"}}}