Principal Application & AI Security Engineer

All locations
  • Houston, TX, United States
  • Oakland, CA, United States
Business:
Energy Systems
Position type:
Full Time
Contract type:
Permanent Employee
Job ID:
7396
Apply

Overview

About us

We are the independent expert in assurance and risk management. Driven by our purpose, to safeguard life, property, and the environment, we empower our customers and their stakeholders with facts and reliable insights so that critical decisions can be made with confidence.

As a trusted voice for many of the world’s most successful organizations, we use our knowledge to advance safety and performance, set industry benchmarks, and inspire and invent solutions to tackle global transformations.

About Energy Systems

We help customers navigate the complex transition to a decarbonized and more sustainable energy future. We do this by assuring that energy systems work safely and effectively, using solutions that are increasingly digital. We also help industries and governments to navigate the many complex, interrelated transitions taking place globally and regionally, in the energy industry.

About the role

DNV Energy Systems' Platform Services is seeking Principal Application & AI Security Engineer.

DNV Energy Systems' Platform Services runs the software products and digital platforms our customers depend on, including systems with significant operational importance in enterprise and energy environments. As we evolve toward agentic AI architectures, security must move from after-the-fact review into architecture, development workflows, and runtime operations - engineered into the platform and the delivery pipeline, with evidence that controls are implemented and operating effectively.

This is a builder's role for a senior technical leader who can read and improve code, design reusable controls, model complex threats, conduct authorized security testing, and work directly with engineering teams to ship durable fixes. The goal is not simply to identify vulnerabilities. It is to eliminate recurring vulnerability classes, reduce exposure, and make the secure path the easiest path.

This role is based at our DNV office in Houston, TX or Oakland, CA, presenting a dynamic hybrid schedule where employees will typically spend three (3) days per week working from either a DNV office or client location/site. Further details regarding role-specific requirements will be shared during the interview process.

What you'll do
You’ll be a technical leader within our organization focused on three core priorities:

  • Securing application and AI architecture. Design and implement secure patterns across applications, APIs, cloud platforms, and AI-agent systems, with particular emphasis on identity, authorization, tenant isolation, data access, tool use, and runtime guardrails.
  • Automating security in engineering workflows. Build and tune risk-based controls so material issues are caught and acted on inside delivery workflows, rather than at manual checkpoints.
  • Eliminating recurring vulnerabilities. Find root causes, fix weaknesses at the architecture or platform-pattern level, and make the same class of issue structurally difficult to reintroduce

The responsibilities below describe how this work shows up day-to-day across architecture, delivery, AI systems, remediation, and engineering.

Build security into delivery and platform engineering

  • Design and implement scalable controls for software and AI supply chains, including dependency integrity, SCA, SAST, DAST, build provenance, artifact security, secrets protection, container and infrastructure-as-code assurance, and software or AI bills of materials where appropriate.
  • Implement platform-level controls: policy as code, authorization enforcement, data-access guardrails, secure defaults, and reusable reference implementations.
  • Design AI-assisted security-testing environments, automated attack scenarios, and security-regression suites that prevent resolved issues from silently returning.
  • Implement risk-based quality gates with documented exception paths, accountable ownership, and service-level expectations, so material issues block release.

Find, prove, and fix material weaknesses

  • Review source code, APIs, and application designs for weaknesses in authentication, authorization, session management, input handling, data-access scope, and multi-tenant isolation, including row- and field-level boundaries.
  • Conduct authorized application, API, and AI security testing, including targeted manual testing of business logic and trust boundaries that automated tools cannot adequately validate.
  • Work alongside engineers to remediate root causes, validate fixes, create regression tests, and put preventive controls or secure patterns in place.
  • Establish vulnerability triage and remediation practices, including exploitability and exposure analysis, accountable ownership, target dates, exception handling, retesting, closure evidence, and escalation of overdue material risk.

Secure AI agents and AI-assisted development

  • Establish agent identities and least-privilege permissions, with clear separation of read, write, execute, approval, and administrative capabilities.
  • Govern model, tool, skill, connector, plug-in, memory, and data access, including tenant isolation and boundaries between trusted and untrusted context.
  • Validate untrusted inputs and tool outputs, and design defenses against direct and indirect prompt injection, goal manipulation, tool misuse, privilege escalation, sensitive-data exposure, memory poisoning, unsafe delegation, and cascading failures.
  • Assess multi-agent workflows to implement approval requirements for consequential or irreversible actions, runtime policy enforcement, rate and resource limits, and tamper-resistant auditability.

Shape secure architecture at scale

  • Lead high-risk threat modeling and architecture reviews for complex, multi-tenant, cloud-native, event-driven, and AI-enabled systems.
  • Develop and demonstrate reusable secure patterns for microservices, APIs, event-driven systems, containers, Kubernetes, cloud services, and agentic AI applications.
  • Contribute to platform roadmaps and engineering practice so controls are implemented at the most effective layer and reused across products.
  • Provide evidence from implementation, testing, and incidents to help Information Security team continuously improve enterprise standards and assurance expectations.

Support engineering teams and incidents

  • Partner across distributed engineering hubs, including North America and Chennai, to drive adoption of secure patterns and automation at scale.
  • Translate findings into prioritized, actionable engineering work reflecting technical severity, exploitability, customer impact, and delivery context.
  • Mentor senior engineers and technical leaders in secure design, development, threat modeling, and remediation.
  • Serve as the application and AI security technical lead during relevant incidents – coordinating with designated incident lead and Information Security team to support investigation, containment, eradication, recovery, remediation validation, and lessons learned.
  • Represent application and AI security in significant technical, executive, customer, audit, and assurance discussions when needed.

What we offer

  • Generous paid time off (vacation, sick days, company holidays, personal days)
  • Multiple Medical and Dental benefit plans to choose from, Vision benefits
  • Spending accounts – FSA, Dependent Care, Commuter Benefits, company-seeded HSA
  • Employer-paid, therapist-led, virtual care services through Talkspace
  • 401(k) with company match
  • Company provided life insurance, short-term, and long-term disability benefits
  • Education reimbursement program
  • Flexible work schedule with hybrid opportunities
  • Charitable Matched Giving and Volunteer Rewards through our Impact Program
  • Volunteer time off (VTO) paid by the company
  • Career advancement opportunities

**Benefits vary based on position, tenure, location, and employee election**

DNV is a proud equal opportunity employer committed to building an inclusive and diverse workforce. All employment is decided on the basis of qualifications, merit, or business need, without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status. DNV is committed to ensuring equal employment opportunity, including providing reasonable accommodations to individuals with a disability. US applicants with a physical or mental disability who require a reasonable accommodation for any part of the application or hiring process may contact the North America Recruitment Department (hrrecruitment.northamerica@dnv.com). Information received relating to accommodation will be addressed confidentially.

For more information

https://www.eeoc.gov/know-your-rights-workplace-discrimination-illegal

DNV provides a reasonable range of compensation for this role. The actual compensation is influenced by a wide array of factors, including but not limited to skill set, level of experience, and specific location. For the states of California, Connecticut, Illinois, Maine, Massachusetts, New Jersey, New York, Virginia and Washington only, the starting pay range for this role is $175,000 - $225,000.

About you

What Is Required

  • 8+ years of experience in application security or secure software engineering, with demonstrated responsibility for production software and security controls.
  • A degree in computer science, cybersecurity, engineering, or a related field is welcome but not required. Equivalent practical experience is fully recognized.
  • Deep application and API security expertise, including authentication, authorization, session management, data protection, input validation, and multi-tenant isolation. This is the core of the role.
  • Ability to review, write, test, and improve production-quality code in one or more languages commonly used in cloud applications, automation, and security engineering.
  • Experience leading source-code reviews, application and API security testing, threat modeling, and architecture reviews for complex systems.
  • Experience integrating and tuning security tooling in CI/CD and converting findings into risk-based automated controls.
  • Production experience with a major cloud provider (Azure, AWS, or comparable) and practical understanding of cloud identity, platform services, and the shared-responsibility model.
  • Demonstrated ability to set technical direction, create reusable capabilities across multiple products, and influence senior stakeholders without relying on formal authority.
  • Ability to explain material security risk clearly to engineers, product leaders, executives, customers, and assurance stakeholders.
  • Strong written and verbal English communication skills.
  • We conduct pre-employment drug and background screening.

What Is Preferred

  • Practical AI-agent security experience, including excessive permissions, insecure tool invocation, untrusted inputs, memory or context risks, sensitive-data exposure, insufficient human oversight, and unsafe autonomous action.
  • Experience applying AI to security testing, code analysis, vulnerability triage, or security automation.
  • Experience securing distributed, event-driven, multi-tenant, or critical enterprise systems where authorization and data boundaries are material risks.
  • Container, Kubernetes, infrastructure-as-code, and software-supply-chain security.
  • Incident response, vulnerability investigation, exploit validation, and remediation verification.
  • Hands-on depth with Veracode, Burp Suite Professional, or equivalents, and practical familiarity with OWASP application, API, and agentic AI security guidance.
  • Certifications are a plus, demonstrated hands-on ability matters more. Relevant credentials include OSCP, GIAC GWAPT, GWEB, GCSA, AZ-500, AWS Certified Security - Specialty, CISSP, or CCSP.

*Immigration-related employment benefits, for example visa sponsorship, are not available for this position*

Benefits

Please note, benefits may depend on your contract type, please confirm with your recruiter.

Profit Share

You’ll be part of our global profit share scheme that means we all share in our success as a business. If we profit, so do you. This will be part of our Total Compensation approach each year and depends on our year-end results.

Personal Development

You’ll have a lot of opportunities to learn and grow. Whether it’s building your network, having resources to plan and realise your career goals or enjoying genuine freedom to satisfy your curiosity, we’ll make sure you’re always growing and developing.

401(k)

DNV provides the option for eligible employees to enroll in our professional managed 401(k) plan. We’ll match up to a percentage of employee elected investment, which will become fully vested after a few years.

Healthcare and more

You’ll have multiple medical plans to choose from including Dental, Vision, RX plans, AD&D, Critical Illness, ST/LT Disability, Paid Parental Leave, Virtual TalkSpace Therapy.

Additional benefits

ID theft protection, generous PTO accrual including paid volunteer time off, company paid holidays, discounted pet insurance, dollar-for-dollar charitable donation matching, Dollars for Doers, additional vacation hours purchase plan, commuter benefits, Employee Assistance Program (EAP), tuition reimbursement.

Values-led organization

Our values show a commitment to employees and the community they serve. These serve a guiding light on our journey to fulfill our Purpose of safeguarding life, property, and the environment. Driven by these Values, you’ll have the opportunity to give back through not only charitable matched giving, but through direct support to community organizations and as a mentor to students in underserved communities.

Diversity, Equity and Inclusion

At DNV, our commitment to Diversity, Equity, and Inclusion is not only an ethical choice, but also a business decision.

Diversity, fairness, and a sense of belonging are a source of strength for our people, our business, and our customers, and help us to deliver on our purpose, vision, and values.

Learn more

Working here

Since 1864 we’ve been dedicated to safeguarding life, property and the environment. Today we remain at the forefront of new technologies and techniques to help our customers transform for a more sustainable future.

At DNV you can expect to deliver career and industry defining work. You’ll be given the time to build your network, the resources to support your development, and the freedom to satisfy your curiosity and desire to learn.

Learn more

Application Process

FAQs

Welcome to our Frequently Asked Questions page. We’ve put together answers to the questions we’re asked most often to help you find the information you need quickly and easily. Whether you're curious about our recruitment process, benefits or career growth and development, you should find the information below.

How can I find job openings that fit my skills and interests?

Explore our official job search page where you can use filters such as job type, location, and department to find roles that best match your qualifications and career aspirations.

What’s your application process like?

You can apply directly through our careers page by submitting your CV and any other documents we require (i.e. university diplomas/transcripts; visas; previous employment reference letters). Make sure your application is fully completed, and you tailor it to the specific job listing. 

Is your recruitment process designed to be inclusive and accessible?

Yes, it is. We're an equal opportunities employer and welcome applications from all candidates. We’re happy to support your need for any adjustments during the application and hiring process. Share the details of what you need within your application.

What types of interviews might I undergo?

Depending on your role, our interview process may include initial phone screenings, video conferences, and in-person interviews, focusing on both your technical abilities and our shared values. You can ask your recruiter specifically about the interview process for your role. 

How long does the hiring process typically take from application to decision?

The timeline can vary but we make every effort to reply to each candidate as soon as possible and keep everyone up-to-date with where they are in the recruitment process.

How do I know if a recruitment contact is legitimately from your company?

Official communication will come from our verified company email addresses. Carefully check any suspicious looking emails and if you have any doubts, don’t engage.

Are there any fees involved in your recruitment process?

No, we do not charge any fees at any stage of our recruitment process. All applications and interviews are free of charge, we will never ask you to pay any fees or make any payments – please be wary of any requests for payment as these are likely scams.

What should I do if I suspect a job scam?

If you encounter suspicious job postings or recruitment practices, do not provide personal information and contact your recruiter as soon as possible. We take these matters seriously. We will never ask you to pay any fees or make any payments part of our recruitment process.

Join Our Talent Community

Can't find the right fit?

Be the first one to learn about new job opportunities that might be a perfect fit for you.

Join

Disclaimer

Please beware of recruitment scams that pretend to be from DNV or its employees. We will never ask you to pay any fees or make any payments as part of our recruitment process.