Application Security Specialist (AI and Agent Security)
Work Arrangement
Office Days per Week: 3 days
Key Skills
Job Description
Introduction 36 hours per week Start date: 09 November 2026 End date: 08 November 2027 Extension is possible ZZP is not allowed Hybrid model of work: employees are expected to be in office 3 days a week The relocation is not possible for this role Job description Seeking an Application Security Specialist with AI and Agent Security expertise to strengthen Application Security capabilities and enable the secure adoption of AI technologies across the organization. The contractor will design and implement security controls, perform security assessments, provide security architecture guidance, and establish governance across software development, AI platforms, AI agents, and software supply chains. With the following results (SMART) • Deliver agreed Application Security maturity improvements by implementing security controls, standards, and secure-by-design practices within committed timelines. • Improve vulnerability management effectiveness through AI-assisted analysis, risk-based prioritization, and timely remediation support. • Establish and operationalize AI Security controls, guardrails, and assessment processes for AI applications, AI agents, and AI-enabled development platforms within agreed milestones. • Implement Software and AI Supply Chain Security controls, including SBOM/AI-BOM requirements, dependency risk management, and third-party AI governance. • Deliver security assessments, threat modelling, and architecture reviews for application, cloud, and AI initiatives within agreed service levels. • Increase adoption of secure development practices through developer enablement, Security Champion engagement, and security awareness activities. • Demonstrate measurable reduction of application, AI, and software supply chain risks through implementation of security controls and remediation guidance. Requirements Required • 6+ years of experience in Application Security, Security Engineering, or DevSecOps. • Hands-on experience with SAST, DAST, API Security, SCA, Container Security, Threat Modelling, and Vulnerability Management. • Experience with secure software development, CI/CD security, and cloud-native platforms. • Experience securing AI-enabled applications, GenAI solutions, AI Agents, RAG architectures, or similar technologies. • Strong stakeholder management, communication, and advisory skills. Preferred • Experience in financial services or other regulated industries. • Knowledge of NIST AI RMF, OWASP, OWASP SAMM, and NIST SSDF. • Bachelor's or Master's degree in Computer Science, Cyber Security, Artificial Intelligence, or a related field. • Relevant certifications such as CISSP, SecAI+, or equivalent. Additional information • Specialist role focused on Application Security, AI Security, and Security Architecture advisory. • Ideal candidate combines a strong Application Security background with practical experience in securing AI-enabled systems, AI agents, and modern software development platforms. • Proven ability to influence engineering teams and drive security improvements in complex technology environments is essential. • Experience working with Engineering, Architecture, Cloud, DevSecOps, and Product teams is highly desirable. • Strong communication, consulting, and stakeholder management capabilities are critical for success in this role. • The role will work with stakeholders globally (EU, APAC, US).
Core Responsibilities
Design and implement application, AI, and software supply chain security controls, and conduct security assessments, threat modeling, and architecture reviews. Establish AI security governance and guardrails, improve vulnerability management, and enable engineering teams to adopt secure development practices.
Requirements
Requires at least six years of experience in application security, security engineering, or DevSecOps, with hands-on expertise in security testing, vulnerability management, secure development, CI/CD, and cloud-native platforms. Candidates should have practical experience securing AI-enabled applications or agents and strong advisory and stakeholder skills; financial services experience, relevant frameworks, a related degree, and certifications are preferred.
About A2Z-CM N.V.
Industry: Business Consulting and Services
Company size: 51-200 employees
A2Z-CM is an independent private company founded in 2012 with offices in Amsterdam and United Kingdom. A2Z-CM is a vendor-neutral, fully-compliant company offering consultancy services, contract management and international brokering to suppliers and agencies in the Netherlands and other countries according to the principle of think global, act local. The A2Z-CM team assist clients by analysing their organisational issues and implementing realistic and cost-effective development plans. Think global, act local. At A2Z-CM, our specialists offer a combination of IT and technical experience, plus a thorough knowledge of compliance and risk mitigation. Our thorough grasp of both fields means that you get solutions tailored to meet your specific needs - solutions that are fully compliant. A2Z-CM provides Clients and contractors with clear, friendly and professional advice on all aspects of the local fiscal and legal regulations. It's our job to deliver a comprehensive range of services, leaving you free to focus on your core business or project.