[Remote] AI Application Security Analyst - AppSec & ML Security
Note: The job is a remote job and is open to candidates in USA. PURE Insurance is a member-owned property and casualty insurer dedicated to providing exceptional service and smart insurance solutions. They are seeking an AI Application Security Analyst to secure modern applications, particularly those utilizing AI and machine learning technologies, by identifying and mitigating vulnerabilities throughout the application lifecycle.
Responsibilities
- Perform application security assessments using SAST, DAST, and interactive testing tools
- Identify, triage, and prioritize vulnerabilities across web, API, and microservices architectures
- Integrate security testing into CI/CD pipelines (DevSecOps)
- Assess security risks in AI/ML-enabled applications, including model exposure and inference endpoints
- Identify vulnerabilities such as adversarial inputs, model abuse, and data poisoning
- Secure AI APIs, plugins, and third-party integrations
- Implement and tune WAF, RASP, and API security controls
- Conduct threat modeling and secure design reviews for applications and AI use cases
- Assess and harden identity and access flows ensuring least privilege
- Partner with developers to remediate vulnerabilities and improve secure coding practices
- Monitor and respond to application-layer security incidents
Skills
- 3–6+ years of experience in Application Security or Product Security
- Hands-on experience with SAST, DAST, IAST tools
- Strong knowledge of OWASP Top 10 vulnerabilities
- Experience securing APIs and microservices
- Experience with modern authentication and authorization protocols (OAuth 2.0, OpenID Connect, SAML)
- Familiarity with CI/CD pipelines
- Basic understanding of AI/ML systems
- Security certification or willingness to obtain within 6 months
- Experience with ML frameworks is a plus
- Familiarity with AI threat models
- Experience with WAF, RASP, or API security solutions
- Experience with cloud platforms (AWS, Azure, GCP)
- Scripting skills (Python, Bash)
Company Overview