Millennium
Application Security Engineer
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About Millennium
Millennium Management is a global, diversified alternative investment firm founded in 1989, managing over $83.5 billion in assets. Headquartered in New York City, the firm operates in more than 140 locations worldwide and employs around 6,500 professionals across over 330 investment teams. The firm's mission is to deliver high-quality returns for investors through a combination of scale, specialization, and an entrepreneurial culture. Millennium utilizes an entrepreneurial investing model, empowering skilled professionals with the resources and technology needed to pursue a diverse range of investment strategies, including fundamental equity and equity arbitrage. With a focus on capital stability and a rigorous risk framework, Millennium aims to provide consistent long-term returns while actively managing a portfolio valued at approximately $207 billion.
Security at Millennium
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- Millennium's AppSec philosophy emphasizes securing emerging AI technologies through specialized oversight.
- The team is focused on defining and implementing security guardrails for Generative AI, LLMs, and Agentic frameworks.
- The approach prioritizes developer enablement through integration into the development lifecycle, with engagement throughout the SDLC to identify vulnerabilities.
- The risk philosophy focuses on specialized assessments for high-complexity models, including threat modeling, red teaming, and risk assessments for AI/ML models.
- Key goals include automating security within the delivery pipeline through integration of automated security testing (SAST/DAST/SCA) into CI/CD pipelines.
Key Initiatives
Millennium's security initiatives focus on shift-left practices with integration of automated testing into the build process and CI/CD pipelines. The team conducts specialized threat modeling, red teaming, and risk assessments for AI/ML models with continuous engagement throughout the SDLC. Recent initiatives center on establishing security frameworks for agentic AI and defining security guardrails for Generative AI, LLMs, and Agentic frameworks. No public information is available regarding vulnerability remediation SLAs, security champions programs, or specific ticketing workflows.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.