Sands

Sands

Sr Application Security Engineer - AI-First Development

Remote, United States · Senior

Sponsorship not specifiedDetected 31 days ago
PythonGoRustC++PowerShellCode ReviewGitAWSGCPAzureCloud PlatformsKubernetesLinuxMachine LearningLLMsRAGAgentic AIAI OrchestrationCybersecurityPenetration TestingDetection EngineeringSupply ChainResearchCommunication

About the role

  • This is a tool-builder-forward role: the emphasis is on engineering high-quality offensive tooling and exploit proof-of-concepts as much as on executing engagements.
  • All duties are to be performed in accordance with departmental and Las Vegas Sands Corp.'s policies, practices, and procedures.

Requirements

  • At least 21 years of age.
  • Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or a related field, or equivalent professional experience.
  • Solid working knowledge of Windows and Linux internals, networking fundamentals, and enterprise identity systems such as Active Directory, including common identity and privilege-escalation attack paths.
  • Demonstrated experience conducting thorough code reviews, identifying defects in both human- and AI-generated outputs, and providing constructive technical feedback.
  • Excellent written and verbal communication skills, with the ability to articulate technical decisions and trade-offs, and to write clear, actionable findings reports for both technical and non-technical stakeholders.
  • Strong interpersonal skills with the ability to communicate effectively and interact appropriately with management, other Team Members and outside contacts of different backgrounds and levels of experience.
  • Must be able to obtain and maintain any certification or license, as required by law or policy.

Nice to have

  • Familiarity with tactical context management techniques such as plan mode, context editing, and multi-session splitting.
  • Hands-on experience with vulnerability research, exploit development, fuzzing, or reverse engineering, including container and Kubernetes attack and escape techniques.
  • Knowledge of secure development practices, the OWASP Top 10, adversary frameworks such as MITRE ATT&CK, and threat modeling.
  • Industry certifications such as OSCP, OSEP, OSWE, GXPN, or CRTO.
  • Understanding of data privacy and responsible AI principles.
  • Physical Requirements
  • Must be able to:
  • Physically access assigned workspace areas with or without reasonable accommodation.

Skills

  • Position Overview
  • All testing is performed strictly within authorized scope and defined rules of engagement.

This listing is sourced directly from Sands's careers page and normalized into a canonical job model.