
Senior Product Security Engineer, AI – DevSecOps
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Kansas, +2 more states.
• Perform security architecture evaluations, threat modeling, and security assessments for applications, APIs, cloud services, and AI-driven systems.
• Establish and enforce security requirements, standards, reusable design patterns, and security guardrails throughout the software development lifecycle.
• Identify, evaluate, and assist in mitigating security risks while collaborating with engineering teams to address vulnerabilities and enhance secure coding practices.
• Analyze and secure AI, machine learning, and generative AI solutions, incorporating controls for model governance, secure access, data protection, and AI risk management.
• Create and enforce security controls for cloud-native applications, containers, Kubernetes, serverless platforms, and infrastructure-as-code deployments.
• Integrate security controls and automated testing within CI/CD pipelines, including SAST, DAST, software composition analysis, secrets detection, container scanning, and infrastructure scanning.
• Develop security automation through scripting, infrastructure-as-code, policy-as-code, and compliance-as-code technologies.
• Assist with identity and access management, secrets management, cloud security monitoring, vulnerability management, and incident response activities.
• Contribute to compliance initiatives, security metrics, risk reporting, and continuous improvement efforts.
• Offer technical guidance on secure development practices and advocate for a security-first engineering culture.
• Collaborate with engineering, platform, architecture, and product teams to design secure solutions and enhance the security posture of applications and AI systems.
• Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent experience.
• Generally requires 7+ years of relevant experience in application security, product security, security engineering, or a related cybersecurity discipline.
• Proven experience in conducting security architecture reviews, threat modeling, secure design reviews, and vulnerability remediation.
• Familiarity with implementing DevSecOps practices and integrating security controls into CI/CD pipelines.
• Experience in securing AI/ML platforms, generative AI solutions, large language model applications, or data science workflows.
• Knowledge of secure software development lifecycle practices, vulnerability management, and Agile development methodologies.
• Proficiency with Microsoft Azure, AWS, or Google Cloud Platform, as well as cloud-native technologies including containers and Kubernetes.
• Experience with infrastructure-as-code and CI/CD technologies such as Terraform, GitHub Actions, Azure DevOps, GitLab, Jenkins, or similar tools.
• Proficient in scripting and automation using Python, PowerShell, Bash, or comparable languages.
• Knowledge of security tools including SAST, DAST, software composition analysis (SCA), container security, secrets detection, and infrastructure scanning.
• Understanding of AI security frameworks and controls, including the OWASP Top 10 for LLM Applications and the NIST AI Risk Management Framework.
• Experience implementing policy-as-code, compliance-as-code, or security automation solutions.
• Familiarity with supporting regulatory and control frameworks such as SOC 2, HIPAA, SOX, NIST Cybersecurity Framework (CSF), or ISO 27001.
• Experience with Security Orchestration, Automation, and Response (SOAR) platforms.
• Ability to articulate complex technical risks and tradeoffs to both technical and non-technical stakeholders.
• Capacity to influence across teams, contribute to technical standards, and promote secure engineering practices.
• Competitive compensation package as part of McKesson’s Total Rewards.
• Annual bonus or long-term incentive opportunities may be available.
• Equity options.
• Reasonable accommodation support for applicants with disabilities.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.