Evaluate threats including prompt and indirect prompt injections, data disclosure, excessive agency, insecure tool access, model and data poisoning, insecure output handling, untrusted RAG content, AI supply-chain compromise, excessive privilege, shadow AI, and unauthorized agent actions. Demonstrated experience with several Application Security and DevSecOps capabilities, including SAST and DAST, software composition analysis (SCA), SBOM generation and management, Package and dependency management, Container and image scanning, CI/CD and repository security, Open-source software security, Vulnerability management and remediation.