Lead Cybersecurity - Application Security Engineer - Dynamic, Runtime & API Security
AT&TAbout the role
This position requires office presence of a minimum of 5 days per week and is only located in the location(s) posted. No relocation is offered.
Join AT&T and reimagine the communications and technologies that connect the world. Our Chief Security Office ensures that our assets are safeguarded through truthful transparency, enforce accountability and master cybersecurity to stay ahead of threats. Bring your bold ideas and fearless risk-taking to redefine connectivity and transform how the world shares stories and experiences that matter. When you step into a career with AT&T, you won’t just imagine the future-you’ll create it.
We are seeking an Application Security Engineer to strengthen the security of our applications and APIs through a combination of dynamic application security testing (DAST), runtime application self-protection (RASP), and API security engineering. This is an application security engineering role, not a traditional security operations position.
The ideal candidate is a security-minded engineer with strong hands-on experience in web application and API security, who understands modern application attacks and can translate that understanding into practical testing, protection, and remediation strategies. This role sits at the intersection of AppSec engineering and production defense, with responsibility for identifying exploitable vulnerabilities both before deployment and while applications are running in production, reducing risk from active attacks, misuse, and exposed application behavior.
This candidate will also evaluate and implement AI-assisted security capabilities to improve coverage, prioritization, and speed — such as intelligent scan orchestration, alert triage, anomaly detection for API abuse, and developer-facing remediation guidance — while ensuring results are valid, measurable, explainable, and safe for production use.
Job Summary:
You will own and scale dynamic security capabilities across the Software Delivery Lifecycle (SDLC) and production, with a strong emphasis on:
- DAST automation and integration into CI/CD pipelines
- RASP and in-process runtime protection (e.g., JVM/.NET CLR instrumentation)
- API Security engineering for internal and external/internet-facing endpoints, including edge/API gateway protections and continuous API discovery (shadow/zombie APIs)
This role is best suited for a candidate with an application security mindset first: someone who can assess real-world exploitability, validate findings, work directly with developers on durable remediation, and build or extend automation in code when existing tooling does not fully solve the problem.
You’ll partner closely with security teams, platform teams, and developers to define policy, deploy controls safely, tune security tool detections, reduce false positives, and measurably improve security outcomes.
Detailed Job Description:
This role focuses on active defense for web applications and APIs through a combination of security testing, runtime instrumentation, and API protection. The candidate will help design and mature security programs that combine:
- Dynamic application and API testing to identify exploitable vulnerabilities, logic weaknesses, and misconfigurations as early as possible
- Runtime protection and instrumentation via runtime security principals and tools such as RASP to detect and, where appropriate, block exploit attempts in production, with an emphasis on protecting API traffic, application workflows, and business logic
- API security capabilities such as API gateway onboarding and policy enforcement, abuse prevention (e.g., scraping/bots), technical reviews and deep-dives, and continuous discovery of undocumented, unmanaged, or exposed APIs
Success in this role requires deep application security knowledge — including web and API attack patterns, authentication and authorization weaknesses, exploitability analysis, and vulnerability remediation — as well as ability to script, automate, integrate, and build lightweight solutions when commercial tooling is insufficient.
The right candidate will be comfortable moving between hands-on security testing, technical analysis, developer partnership, and security engineering automation, with a focus on reducing meaningful application risk.
Key Responsibilities:
AI-Assisted Security Engineering
- Identify practical opportunities to apply AI-assisted approaches across DAST, API testing, runtime telemetry, and security workflows (e.g., prioritization, correlation, anomaly detection, automated enrichment, and remediation support).
- Implement AI-enabled workflows to reduce false positives, improve triage efficiency, and accelerate remediation
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s