
Senior Information Security Engineer
Posted Sep 29

Posted Sep 29
This is a fully remote position, open to applicants in Brazil.
• Take ownership of the architecture and progression of Lhasa’s security guardrail files (.md and similar formats), including their structure, range, versioning, update frequency, and integration with development tools.
• Define security specifications for AI engineers utilizing AI to write code, addressing data management, authentication, injection prevention, and AI-related vulnerability patterns.
• Establish and consistently enhance secure-by-design principles for Lhasa’s software engineering processes.
• Continuously adjust guardrails as AI-driven programming tools, threat landscapes, and product architecture develop.
• Lead the implementation of guardrails across solution teams, clarifying ambiguities and managing exceptions with well-founded justifications.
• Extensive experience in information security, particularly in application or product security.
• Demonstrated experience in managing secure development frameworks, guardrail standards, or DevSecOps initiatives.
• Proven track record of integrating security into CI/CD pipelines and automating security gate controls.
• Experience in leading application security evaluations, including threat modeling, SAST/DAST, and coordinating penetration testing.
• Prior experience collaborating closely with software development teams.
• History of independently tackling complex product security issues and achieving results across various teams.
• Advanced understanding of application security, including the OWASP Top 10 and similar frameworks.
• In-depth knowledge of vulnerability patterns in AI-generated code and strategies to address them at both the framework and pipeline levels.
• Strong understanding of AI-specific attack vectors, such as prompt injection, data poisoning, model manipulation, and risks associated with agentic systems.
• Specialized expertise in CI/CD tools and mechanisms for implementing security gates, including SAST, DAST, dependency scanning, and secrets detection.
• Practical knowledge of ISO 27001, NIST, and ISO 42001 in relation to software products.
• CISSP, CEH, or equivalent certification is preferred.
• Experience in the secure design of AI systems or formal AI security assessment frameworks is preferred.
• Familiarity with ISO 42001, the EU AI Act, or contributions to security standards or open-source security tools is preferred.
• Previous experience in software development or DevSecOps engineering is preferred.
• The support necessary to achieve professional success.
• A collaborative and innovative work environment.
Integrity360
Rackspace Technology
Efficient Computer
Presidio
Get handpicked remote jobs straight to your inbox weekly.