AppSec Jobs
← Back to all jobs

Millennium

Application Security Engineer

Onsite
Bengaluru, Karnataka, IndiaPosted 4 days agoWebsite
Apply on LinkedIn →

At a Glance

AWSAzureGCPPythonJavaTerraform

About This Role

The successful candidate will be a subject matter expert with direct experience in a wide range of security technologies, tools, and methodologies. The role is suited for an experienced Application Security engineer with proven understanding in enterprise security and AI security and will focus on building toolsets and processes to drive adoption of secure practices across the enterprise. The team fosters a collaborative environment and is building a best-in-class program to partner with the business to protect the Firm's information and computer systems. Millennium is a complex and robust technical environment and securing the Firm from external and internal threats is a top priority.

Responsibilities

  • AI Security Strategy: Define and implement security guardrails for Generative AI, LLMs, and Agentic frameworks, ensuring safe enterprise adoption.
  • AI Risk Management: Conduct specialized threat modeling, red teaming, and risk assessments for AI/ML models (e.g., testing for prompt injection, model theft, and data poisoning).
  • Security Consulting: Lead risk management activities, including application risk assessments, design reviews, and mitigation strategies for IT projects.
  • Lifecycle Engagement: Engage throughout the SDLC to identify vulnerabilities, conduct code reviews/penetration testing, and enforce secure coding standards.
  • Program Development: Evangelize AppSec and AI security best practices through developer education, training materials, and outreach.
  • Tooling & Architecture: Design robust security architectures and integrate automated security testing (SAST/DAST/SCA) into CI/CD pipelines.
  • Stakeholder Liaison: Partner with Technology, Trading, Legal, and Compliance to create policies and communicate technical risks to non-technical stakeholders.

Requirements

OWASPAWSGCPAzureCI/CDSCAPythonJavaTerraformNISTCISSP
  • Bachelor's degree or higher in Computer Science, Computer Engineering, IT Security or related field
  • 5+ years' experience working as an Application Security Engineer, Software Engineer, or similar role
  • Deep understanding of AI-specific risks (OWASP Top 10 for LLMs) and experience securing applications utilizing LLMs
  • Experience working with AI models, Agentic frameworks and security risks associated with AI
  • Experience in working with global teams, collaborating on code and presentations
  • Demonstrated work experience in hybrid on-premise and Public Cloud environments (AWS/GCP/Azure)
  • Strong understanding of security architectures, secure configuration principles/coding practices, cryptography fundamentals and encryption protocols
  • Experience with common SCM & CI/CD technologies like GitHub, Jenkins, Artifactory, etc. and integrating Security Scanning and Vulnerability Management into the CI/CD Pipelines
  • Familiarity with static and dynamic security analysis tools, and SCA/SBOM solutions
  • Hands on experience with Secrets Management & Password Vault technologies such as Delinea Secret Server and/or Hashicorp Vault, etc.
  • Strong experience in secure programming in languages such as Python, Java, C++, C#, or similar
  • Familiarity with Infrastructure as Code tools (CloudFormation, Terraform, Ansible, etc.)
  • Familiarity with web application security testing tools and methodologies
  • Knowledge of various security frameworks and standards such as ISO 27001, NIST, OWASP, etc.
  • Knowledge of Linux, OS internals and containers is a plus
  • Certifications like CISSP, CISM, CompTIA Security+, or CEH are advantageous

About Millennium

Millennium Management is a global, diversified alternative investment firm founded in 1989, managing over $83.5 billion in assets. Headquartered in New York City, the firm operates in more than 140 locations worldwide and employs around 6,500 professionals across over 330 investment teams. The firm's mission is to deliver high-quality returns for investors through a combination of scale, specialization, and an entrepreneurial culture. Millennium utilizes an entrepreneurial investing model, empowering skilled professionals with the resources and technology needed to pursue a diverse range of investment strategies, including fundamental equity and equity arbitrage. With a focus on capital stability and a rigorous risk framework, Millennium aims to provide consistent long-term returns while actively managing a portfolio valued at approximately $207 billion.

Industry

investment management

Employees

6,300

1106 engineers

Revenue

$2.6B

Website

Visit →

Security at Millennium

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

  • Millennium's AppSec philosophy emphasizes securing emerging AI technologies through specialized oversight.
  • The team is focused on defining and implementing security guardrails for Generative AI, LLMs, and Agentic frameworks.
  • The approach prioritizes developer enablement through integration into the development lifecycle, with engagement throughout the SDLC to identify vulnerabilities.
  • The risk philosophy focuses on specialized assessments for high-complexity models, including threat modeling, red teaming, and risk assessments for AI/ML models.
  • Key goals include automating security within the delivery pipeline through integration of automated security testing (SAST/DAST/SCA) into CI/CD pipelines.

Key Initiatives

Millennium's security initiatives focus on shift-left practices with integration of automated testing into the build process and CI/CD pipelines. The team conducts specialized threat modeling, red teaming, and risk assessments for AI/ML models with continuous engagement throughout the SDLC. Recent initiatives center on establishing security frameworks for agentic AI and defining security guardrails for Generative AI, LLMs, and Agentic frameworks. No public information is available regarding vulnerability remediation SLAs, security champions programs, or specific ticketing workflows.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.

Interested in this role?

Apply on LinkedIn