ServiceTitan is transforming product security into a core part of how engineering delivers software. They are seeking an AI-Focused Senior Application Security Engineer to define and deliver secure automated patterns that enable R&D teams to build securely without hindering innovation.
Responsibilities:
- Embed security directly into the development pipeline through intelligent prompting and AI driven agents
- Collaborate with Engineering to develop and maintain secure microservice templates and libraries that have security controls built in from the start
- Implement controls to secure dependencies, build artifacts, and third party integrations
- Evaluate, configure, and implement AI agentic tooling to autonomously test our web applications for vulnerabilities
- Use agentic tooling to run proactive simulations based on emerging threats to validate our defenses in real time
- Drive adherence to vulnerability remediation SLAs by partnering with engineering teams to track, prioritize, and resolve security issues
- Design and implement technical guardrails for AI Coding Agents and Model Context Protocols (MCP)
- Help operationalize AI based tooling to act as a "GPS" for developers, tuning the system to provide accurate, on demand threat modeling, design, and development advice
- Partner with engineering to define and implement strategies for managing machine identities across AI systems
- Act as the AppSec technical expert for the Security Champions Program
- Assist in setting up "Just in Time" training campaigns that trigger micro-trainings when engineers introduce vulnerabilities
- Own the initial triage of incoming vulnerability tickets (SAST/SCA)
Requirements:
- 5+ years of experience in Product/Application Security, with a strong background in software engineering
- Proven experience at the intersection of AI and security, including securing AI workloads and leveraging AI agents to enhance defensive capabilities
- Experience implementing tools and driving for secure outcomes throughout the Secure Software Development Lifecycle including Threat Modeling, Code Scanning, and Penetration testing
- Proven ability to prompt, script, and automate security tasks. You prefer building a tool to solve a problem over fixing it manually