Application Security Specialist (AI and Agent Security)
Application Security Specialist (AI and Agent Security) voor A2Z-CM, hybride Amsterdam, 36u/week, start 09-11-2026.
- Locatie
- Amsterdam
- Werkvorm
- hybride
- Uren
- 36 uur per week
Eisen
- Experience with secure software development, CI/CD security, and cloud-native platforms
- Strong stakeholder management, communication, and advisory skills
- Experience securing AI-enabled applications, GenAI solutions, AI Agents, RAG architectures, or similar technologies
- Hands-on experience with SAST, DAST, API Security, SCA, Container Security, Threat Modelling, and Vulnerability Management
- 6+ years of experience in Application Security, Security Engineering, or DevSecOps
Wensen
- Relevant certifications such as CISSP, SecAI+, or equivalent
- Experience in financial services or other regulated industries
- Bachelor’s or Master’s degree in Computer Science, Cyber Security, Artificial Intelligence, or a related field
- Knowledge of NIST AI RMF, OWASP, OWASP SAMM, and NIST SSDF
Volledige omschrijving
Introduction: 36 hours per week, start date 09 November 2026, end date 08 November 2027, extension is possible, ZZP is not allowed, hybrid model of work (employees expected in office 3 days a week), relocation not possible.
Function: Seeking an Application Security Specialist with AI and Agent Security expertise to strengthen Application Security capabilities and enable the secure adoption of AI technologies across the organization. The contractor will design and implement security controls, perform security assessments, provide security architecture guidance, and establish governance across software development, AI platforms, AI agents, and software supply chains.
Results (SMART): deliver agreed Application Security maturity improvements by implementing security controls, standards, and secure-by-design practices within committed timelines; improve vulnerability management effectiveness through AI-assisted analysis, risk-based prioritization, and timely remediation support; establish and operationalize AI Security controls, guardrails, and assessment processes for AI applications, AI agents, and AI-enabled development platforms within agreed milestones; implement Software and AI Supply Chain Security controls, including SBOM/AI-BOM requirements, dependency risk management, and third-party AI governance; deliver security assessments, threat modelling, and architecture reviews for application, cloud, and AI initiatives within agreed service levels; increase adoption of secure development practices through developer enablement, Security Champion engagement, and security awareness activities; demonstrate measurable reduction of application, AI, and software supply chain risks through implementation of security controls and remediation guidance.
Requirements: Required: 6+ years of experience in Application Security, Security Engineering, or DevSecOps; hands-on experience with SAST, DAST, API Security, SCA, Container Security, Threat Modelling, and Vulnerability Management; experience with secure software development, CI/CD security, and cloud-native platforms; experience securing AI-enabled applications, GenAI solutions, AI Agents, RAG architectures, or similar technologies; strong stakeholder management, communication, and advisory skills.
Preferred: experience in financial services or other regulated industries; knowledge of NIST AI RMF, OWASP, OWASP SAMM, and NIST SSDF; Bachelor’s or Master’s degree in Computer Science, Cyber Security, Artificial Intelligence, or a related field; relevant certifications such as CISSP, SecAI+, or equivalent.
Additional information: Specialist role focused on Application Security, AI Security, and Security Architecture advisory; ideal candidate combines a strong Application Security background with practical experience in securing AI-enabled systems, AI agents, and modern software development platforms; proven ability to influence engineering teams and drive security improvements in complex technology environments is essential; experience working with Engineering, Architecture, Cloud, DevSecOps, and Product teams is highly desirable; strong communication, consulting, and stakeholder management capabilities are critical for success in this role; the role will work with stakeholders globally (EU, APAC, US).
Je CV en reacties
Voeg een CV toe om de eisen naast jouw ervaring te bekijken.
Je reageert zelf bij de bron. Leg hieronder vast wanneer je je reactie hebt verstuurd.
Bewaar de broker en datum in Mijn reacties.