Senior Product Security Engineer – AI, DevSecOps

Posted 4 hours ago

This is a fully remote position, open to applicants in Kansas, +2 more states.

📋 Description

• Perform reviews of security architecture, threat modeling, and security evaluations for applications, APIs, cloud services, and AI-driven systems.

• Establish and enforce security requirements, standards, reusable design patterns, and security guidelines throughout the software development lifecycle.

• Recognize, evaluate, and assist in mitigating security risks while collaborating with engineering teams to address vulnerabilities and enhance secure coding practices.

• Evaluate and secure AI, machine learning, and generative AI solutions, including governance controls, secure access, data protection, and AI risk management.

• Design and implement security measures for cloud-native applications, containers, Kubernetes, serverless platforms, and infrastructure-as-code deployments.

• Embed security controls and automated testing within CI/CD pipelines, encompassing SAST, DAST, software composition analysis, secrets detection, container scanning, and infrastructure scanning.

• Create security automation through scripting, infrastructure-as-code, policy-as-code, and compliance-as-code technologies.

• Assist with identity and access management, secrets management, cloud security monitoring, vulnerability management, and incident response activities.

• Contribute to compliance efforts, security metrics, risk reporting, and initiatives for continuous improvement.

• Offer technical advice on secure development practices and advocate for a security-first engineering culture.

• Collaborate with engineering, platform, architecture, and product teams to design secure solutions and enhance the security posture of applications and AI systems.


⛳️ Requirements

• Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent professional experience.

• Generally requires 7+ years of applicable experience in application security, product security, security engineering, or a related cybersecurity field.

• Proficient in conducting security architecture reviews, threat modeling, secure design assessments, and vulnerability remediation.

• Familiarity with implementing DevSecOps practices and integrating security measures into CI/CD pipelines.

• Experience in securing AI/ML platforms, generative AI solutions, large language model applications, or data science workflows.

• Knowledge of secure software development lifecycle practices, vulnerability management, and Agile development methodologies.

• Experience with Microsoft Azure, AWS, or Google Cloud Platform, along with cloud-native technologies, including containers and Kubernetes.

• Proficiency in infrastructure-as-code and CI/CD tools such as Terraform, GitHub Actions, Azure DevOps, GitLab, Jenkins, or similar technologies.

• Strong scripting and automation skills using Python, PowerShell, Bash, or similar programming languages.

• Familiarity with security tools including SAST, DAST, software composition analysis (SCA), container security, secrets detection, and infrastructure scanning.

• Understanding of AI security frameworks and controls, including the OWASP Top 10 for LLM Applications and the NIST AI Risk Management Framework.

• Experience with policy-as-code, compliance-as-code, or security automation solutions.

• Knowledge of regulatory and control frameworks such as SOC 2, HIPAA, SOX, NIST Cybersecurity Framework (CSF), or ISO 27001.

• Familiarity with Security Orchestration, Automation, and Response (SOAR) platforms.

• Capable of communicating complex technical risks and trade-offs to both technical and non-technical audiences.

• Strong ability to influence across teams, contribute to the development of technical standards, and promote secure engineering practices.


🏝️ Benefits

• Competitive compensation package.

• Opportunities for annual bonuses or long-term incentives may be available.

• Commitment to equal employment opportunities.

• Reasonable accommodations offered for job searches or applications.

People also viewed

Alcoa4 hours ago

Senior Cybersecurity Specialist

BR flagBrazil OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Zillow4 hours ago

Director, Application Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$220.2k – $351.8k/year
ApplyView job
Truelogic Software4 hours ago

AI Security Engineer – Offensive Security Engineer

DO flagDominican Republic OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Truelogic Software4 hours ago

AI Security Engineer – Offensive Security Engineer

Latin AmericaFull-timeCybersecurity / Security Engineer
ApplyView job
Truelogic Software4 hours ago

AI Security Engineer / Offensive Security Engineer – Technology

CO flagColombia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Truelogic Software4 hours ago

AI Security Engineer, Offensive Security Engineer

BR flagBrazil OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers