
Senior Product Security Engineer
Posted 9 hours ago

Posted 9 hours ago
This is a fully remote position, open to applicants in United States.
• Guide the design and execution of secure, scalable, and reliable products within AlphaSense’s AI-native platform.
• Collaborate with architects, engineering, and product teams to incorporate security from the ground up throughout the software development lifecycle.
• Design and enforce security measures for AI/ML systems, covering model training, data pipelines, inference environments, and agentic workflows.
• Detect and address AI-specific vulnerabilities such as prompt injection, data poisoning, model inversion, and model theft.
• Implement controls for model provenance, integrity, and auditability.
• Align AI security efforts with governance and compliance teams in accordance with frameworks like NIST AI RMF and the EU AI Act.
• Ensure that security, privacy, and compliance are integral to application and cloud ecosystems.
• Set and uphold secure development standards, guidance, and best practices.
• Conduct threat modeling, secure design reviews, and risk assessments.
• Develop and sustain security automation and governance integrated into development workflows.
• Create customer-facing security assurance documents, including responses to security questionnaires, security whitepapers, and trust collateral.
• Represent product security in discussions with customers, cross-functional teams, and leadership.
• Provide mentorship to teams on secure coding, AI risk management, and secure design principles.
• Foster a security-first culture through advocacy, documentation, and training.
• 5–7+ years of experience in product, application, or cloud security engineering.
• Profound knowledge of secure SDLC, threat modeling, and secure architecture design.
• Ability to read and evaluate code to inform threat models and design reviews.
• Experience in securing AI/ML pipelines, data workflows, and model-serving infrastructure.
• Working familiarity with AI/LLM security, including prompt injection, model integrity, and provenance.
• Expertise in cloud security principles and best practices across multi-cloud environments.
• Knowledge of DevSecOps and CI/CD frameworks.
• Understanding of encryption fundamentals, including symmetric and asymmetric cryptography, TLS/mTLS, key management, and secrets management.
• Familiarity with OAuth 2.0, OIDC, SAML, RBAC, and ABAC.
• Capability to lead cross-functional security initiatives involving engineering, product, and compliance teams.
• Nice to have: proficiency in Python, Java, and/or JavaScript.
• Nice to have: experience with container and orchestration security, including Kubernetes runtime protection.
• Nice to have: knowledge of software supply chain security and artifact integrity verification.
• Nice to have: experience with bug bounty programs.
• Nice to have: familiarity with SOC 2, ISO 27001, NIST 800-53, and NIST AI RMF.
• Nice to have: certifications such as CKS, CISSP, CSSLP, or credentials in AI/ML security.
• Performance-based bonus.
• Equity options.
• Comprehensive benefits program.
• Opportunities for career advancement.
• Reasonable accommodations for qualified employees with protected disabilities.
Zscaler
Viatris
ActBlue
SysMap Solutions
Get handpicked remote jobs straight to your inbox weekly.