Sands
Sr Application Security Engineer - AI-First Development
Remote, United States · Senior
Sponsorship not specifiedDetected 31 days ago
PythonGoRustC++PowerShellCode ReviewGitAWSGCPAzureCloud PlatformsKubernetesLinuxMachine LearningLLMsRAGAgentic AIAI OrchestrationCybersecurityPenetration TestingDetection EngineeringSupply ChainResearchCommunication
About the role
- This is a tool-builder-forward role: the emphasis is on engineering high-quality offensive tooling and exploit proof-of-concepts as much as on executing engagements.
- All duties are to be performed in accordance with departmental and Las Vegas Sands Corp.'s policies, practices, and procedures.
Requirements
- At least 21 years of age.
- Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or a related field, or equivalent professional experience.
- Solid working knowledge of Windows and Linux internals, networking fundamentals, and enterprise identity systems such as Active Directory, including common identity and privilege-escalation attack paths.
- Demonstrated experience conducting thorough code reviews, identifying defects in both human- and AI-generated outputs, and providing constructive technical feedback.
- Excellent written and verbal communication skills, with the ability to articulate technical decisions and trade-offs, and to write clear, actionable findings reports for both technical and non-technical stakeholders.
- Strong interpersonal skills with the ability to communicate effectively and interact appropriately with management, other Team Members and outside contacts of different backgrounds and levels of experience.
- Must be able to obtain and maintain any certification or license, as required by law or policy.
Nice to have
- Familiarity with tactical context management techniques such as plan mode, context editing, and multi-session splitting.
- Hands-on experience with vulnerability research, exploit development, fuzzing, or reverse engineering, including container and Kubernetes attack and escape techniques.
- Knowledge of secure development practices, the OWASP Top 10, adversary frameworks such as MITRE ATT&CK, and threat modeling.
- Industry certifications such as OSCP, OSEP, OSWE, GXPN, or CRTO.
- Understanding of data privacy and responsible AI principles.
- Physical Requirements
- Must be able to:
- Physically access assigned workspace areas with or without reasonable accommodation.
Skills
- Position Overview
- All testing is performed strictly within authorized scope and defined rules of engagement.
This listing is sourced directly from Sands's careers page and normalized into a canonical job model.