Director of Application Security
webAI is a sovereign AI platform that lets organizations build, deploy, and operate custom AI on their own infrastructure. It serves enterprise teams across industries such as healthcare, manufacturing, financial services, aviation, public sector, and retail.
Projects
About webAI
webAI provides a full-stack, locally operated AI platform for enterprises seeking private, controllable AI. Its platform includes Navigator for building, training, and deploying custom models; Companion, an on-device AI assistant; Runtime for distributed workload orchestration; webFrame for optimized inference and training; Network for secure local connectivity; and a CLI for programmatic management. The company emphasizes data sovereignty, local deployment, predictable costs, and support for edge devices and private clusters.
Skills
About the Role
You will lead application and product security initiatives with ownership of security outcomes. You will establish security architecture for decentralized and on-device AI systems, define trust boundaries and data-protection strategies, lead threat modeling, and embed security into system design. You will integrate security into software and ML lifecycles, define AI and model-integrity safeguards, and work with engineering on secure-by-default capabilities. You will secure cloud, hybrid, edge, and on-device environments; protect data, identity, access, networking, and distributed systems; secure deployments and update mechanisms; and operate risk assessment, vulnerability management, and supply-chain risk programs.
Requirements
- 12+ years of professional technical cybersecurity experience
- 5+ years of technical cybersecurity leadership experience
- Deep background in product and platform security
- Experience with cloud infrastructure, distributed systems, and modern architectures
- Understanding of edge computing, application security, infrastructure security, and adversarial thinking
- Knowledge of AI/ML security, including model integrity, data poisoning, and adversarial attacks
- Deep technical literacy and ability to coach others on delivery best practices
- Strong communication skills for technical and non-technical discussions
- Ability to work with evolving processes, priorities, and imperfect systems
- Recommended certifications include CISSP, CSSLP, OSWE, or GAIPS
Responsibilities
- Establish the security model for decentralized, on-device AI systems and enterprise technology
- Define trust boundaries, identity frameworks, and data protection strategies
- Lead threat modeling for edge, distributed, and AI-driven environments
- Embed security into system design
- Integrate security into the software and ML lifecycle
- Define safeguards for model integrity, adversarial attacks, data poisoning, and AI/ML threats
- Build secure-by-default product capabilities with engineering
- Own security across cloud, hybrid, edge, and on-device environments
- Establish controls for data, identity, access, networking, and distributed systems
- Secure deployments, firmware, and update mechanisms
- Develop, operate, and maintain cybersecurity risk assessment and vulnerability management programs
- Mitigate supply-chain and third-party risks and vulnerabilities
Benefits
- Comprehensive health, dental, and vision benefits package
- 401(k) match for U.S.-based employees
- $200/month Health & Wellness stipend
- Continuing Education support
- $500/year Function Health subscription for U.S.-based employees
- Free parking for in-office employees
- Flexible Time Off
- Parental leave for eligible employees
- Supplemental life insurance
