
Senior Product Security Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United Kingdom.
• Oversee the design and execution of secure, scalable, and reliable products within AlphaSense’s AI-native platform.
• Collaborate with architects, engineering, and product teams to integrate security by design throughout the software development lifecycle.
• Design and enforce security measures for AI/ML systems, which include model training, data pipelines, inference environments, and agentic workflows.
• Detect and address AI-specific vulnerabilities such as prompt injection, data poisoning, model inversion, and model theft.
• Establish controls for model provenance, integrity, and auditability.
• Align AI security efforts with governance and compliance teams in accordance with NIST AI RMF and the EU AI Act.
• Ensure design incorporates security, privacy, and compliance principles.
• Develop and uphold secure development standards, guidelines, and best practices.
• Lead threat modeling, secure design assessments, and risk evaluations.
• Create and sustain security automation and governance mechanisms integrated into development processes.
• Generate customer-facing security assurance documents, including questionnaire responses, security whitepapers, and trust collateral.
• Act as a representative of product security in discussions with customers, cross-functional teams, and leadership.
• Guide teams on secure coding practices, AI risk management, and secure design principles.
• Foster a security-first culture through advocacy, documentation, and training initiatives.
• 5–7+ years of experience in product, application, or cloud security engineering.
• In-depth knowledge of secure SDLC, threat modeling, and secure architecture design.
• Capable of reading and examining code to inform threat models and design evaluations.
• Experience in securing AI/ML pipelines, data workflows, and model-serving infrastructure.
• Familiarity with AI/LLM security, including prompt injection, model integrity, and provenance.
• Established expertise in cloud security concepts and best practices across multi-cloud environments.
• Understanding of DevSecOps and CI/CD environments.
• Knowledge of symmetric and asymmetric cryptography, TLS/mTLS, key management, and secrets management.
• Understanding of OAuth 2.0, OIDC, SAML, RBAC, and ABAC.
• Ability to lead cross-functional security initiatives alongside engineering, product, and compliance teams.
• Nice to have: proficiency in Python, Java, and/or JavaScript.
• Nice to have: experience in container and orchestration security, including Kubernetes runtime protection.
• Nice to have: knowledge in software supply chain security and artifact integrity verification.
• Nice to have: experience with bug bounty programs.
• Nice to have: familiarity with SOC 2, ISO 27001, NIST 800-53, and NIST AI RMF.
• Nice to have: credentials such as CKS, CISSP, CSSLP, or AI/ML security certifications.
• Performance-based bonus.
• Equity opportunities.
• Comprehensive benefits program.
• Opportunities for career advancement.
• Competitive salary.
• A collaborative and security-focused engineering culture.
• An equal-opportunity workplace.
• Reasonable accommodations for qualified employees with protected disabilities.
• AlphaSense does not require candidates to pay for job applications, equipment, or training.
Cloudiax
Cisco
Cisco
Skylight
Get handpicked remote jobs straight to your inbox weekly.