
Senior Product Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Canada.
• Take the lead in designing and implementing secure, scalable, and reliable products within AlphaSense’s AI-native platform.
• Collaborate with architects, engineering, and product teams to integrate security by design throughout the software development lifecycle.
• Develop and enforce security controls for AI/ML systems, encompassing model training, data pipelines, inference environments, and agentic workflows.
• Detect and address AI-specific attack vectors such as prompt injection, data poisoning, model inversion, and model theft.
• Execute model provenance, integrity, and auditability controls.
• Align AI security initiatives with governance and compliance teams in accordance with frameworks like NIST AI RMF and the EU AI Act.
• Establish and uphold secure development standards, guidance, and best practices.
• Lead threat modeling exercises, secure design reviews, and risk assessments.
• Create and sustain security automation and governance that integrates seamlessly into development workflows.
• Generate customer-facing security assurance materials, including responses to questionnaires, security whitepapers, and trust collateral.
• Represent product security in discussions with customers, cross-functional teams, and leadership.
• Mentor teams in secure coding practices, AI risk management, and secure design principles.
• Foster a security-first culture through advocacy, documentation, and training.
• 5–7+ years of experience in product, application, or cloud security engineering.
• Profound knowledge of secure SDLC, threat modeling, and secure architecture design.
• Capability to read and review code to inform threat models and design assessments.
• Experience in securing AI/ML pipelines, data workflows, and model-serving infrastructures.
• Working familiarity with AI/LLM security, including prompt injection, model integrity, and provenance.
• Expertise in cloud security principles and best practices across multi-cloud environments.
• Understanding of DevSecOps and CI/CD practices.
• Knowledge of encryption basics, including symmetric and asymmetric cryptography, TLS/mTLS, key management, and secrets handling.
• Comprehension of OAuth 2.0, OIDC, SAML, RBAC, and ABAC.
• Ability to lead cross-functional security initiatives with engineering, product, and compliance teams.
• Preferred: proficiency in Python, Java, and/or JavaScript.
• Preferred: knowledge of container and orchestration security, including Kubernetes runtime protection.
• Preferred: experience in software supply chain security and artifact integrity verification.
• Preferred: familiarity with bug bounty programs.
• Preferred: knowledge of SOC 2, ISO 27001, NIST 800-53, and NIST AI RMF.
• Preferred: certifications such as CKS, CISSP, CSSLP, or AI/ML security.
• Performance-based bonus.
• Equity opportunities.
• Comprehensive benefits program.
• Opportunities for career advancement.
• A collaborative and security-focused engineering culture.
• Engage with cutting-edge security challenges in a rapidly growing company.
• Chance to influence and direct product security strategy.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.