
Staff Security Engineer, AI & Application Security
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in United States.
• Security Strategy, Roadmap and Prioritization: Establish and sustain a prioritized security roadmap for Marcura to ensure that limited capacity in a single security headcount is allocated to the most significant material risks. This involves assessing the current security posture, setting a limited number of clear objectives for each period, making explicit decisions regarding in-house versus external delivery, and building a compelling evidence-based case for further investment.
• Secure Architecture and Design Review: Evaluate the architecture and design of new and evolving systems to prevent security vulnerabilities from being embedded rather than identified later. This includes incorporating lightweight threat modeling into the delivery lifecycle, defining reusable secure design patterns, and providing teams with timely, pragmatic decisions rather than imposing blocking gates.
• AI and LLM Security Advisory: Function as the group's trusted AI security advisor to facilitate the rapid and safe adoption of AI throughout the organization. This entails engaging early in design processes, defining secure-by-design patterns for LLM, RAG, and agentic systems, and offering teams clear, proportionate guidance instead of blanket restrictions.
• AI Security Framework and Standards: Develop and maintain a practical AI security framework and set of engineering standards to ensure that secure AI deployment is both repeatable and auditable as the environment expands. This includes aligning with OWASP LLM Top 10, MITRE ATLAS, and NIST AI RMF, translating these into concrete controls, checklists, and acceptance criteria, and maintaining a live inventory of deployed models and their controls.
• Internal Penetration Testing Programme: Create and personally manage Marcura's internal penetration testing capabilities to provide continuous, in-depth assurance between and beyond scheduled external tests. This involves defining the scope, methodology, tooling, reporting standards, and a prioritized testing calendar covering applications, APIs, cloud infrastructure, and internal services.
• External Penetration Test Ownership: Oversee and direct Marcura's independent external penetration testing to maintain genuine independence of assurance over systems designed by the role holder. This includes setting the scope and objectives, selecting and managing testing partners, ensuring that internal and external coverage is complementary rather than duplicative, challenging the technical quality of findings, and integrating results into a single prioritized remediation backlog.
• Hands-On Offensive Testing and Red Teaming: Conduct technical penetration tests and red team exercises against production and pre-production systems to identify exploitable weaknesses before adversaries do. This combines manual testing, custom tooling, and automation, demonstrating impact through tangible exploitation instead of theoretical findings.
• AI Red Teaming and Adversarial Testing: Design and implement AI red team exercises for every significant AI and LLM deployment to ensure that AI features cannot be exploited to leak data, bypass controls, or take unauthorized actions. This involves systematically testing for prompt injection, jailbreaks, guardrail bypass, data exfiltration, insecure output handling, and unsafe tool or agent behavior.
• Application and Cloud Security Hardening: Enhance the baseline security of Marcura's applications and cloud environment to systematically reduce the attack surface rather than addressing issues individually. This requires defining hardening standards and secure defaults, driving posture management and configuration baselines, and embedding automated security testing into CI/CD pipelines.
• Identity, Access and Data Protection: Fortify identity, access, and data protection controls to minimize the blast radius of any single compromise. This includes reviewing and enhancing authentication and authorization designs, implementing least privilege and privileged access, managing secrets and keys, ensuring encryption, and establishing data classification and tenancy boundaries.
• MDR Partnership Ownership (eSentire): Manage the technical relationship with Marcura's Managed Detection and Response partner, eSentire, to maximize protective value from the service rather than treating it as an outsourced responsibility. This involves ensuring the appropriate telemetry and log sources are onboarded, validating and tuning detection coverage against Marcura's actual threat model, testing the service through purple team-style exercises, holding the provider accountable for quality and response times, and addressing the gaps the service does not cover.
• Detection Engineering and Incident Response: Enhance Marcura's capability to detect and respond to attacks beyond commodity coverage to shorten the time between compromise and containment. This entails defining logging and telemetry requirements, engineering high signal detections for Marcura-specific and AI-specific attack patterns that an MDR provider may not cover, maintaining incident response runbooks, and providing hands-on technical leadership and escalation ownership during security incidents.
• Vulnerability Management and Remediation Ownership: Oversee the complete vulnerability lifecycle to achieve measurable risk reduction rather than allowing a growing backlog of findings. This involves triaging and prioritizing findings by business impact, agreeing on remediation plans and timelines with engineering owners, verifying fixes through retesting, and escalating unresolved material risks to leadership.
• Security Tooling and Automation: Develop and operate tooling and automation for continuous security testing and monitoring to amplify the impact of a single hands-on engineer. This includes automating repeatable assurance tasks, integrating scanning and AI-specific testing into pipelines, and minimizing manual efforts in recurring security activities.
• Third Party, Vendor and Model Assurance: Evaluate third-party software, AI models, platforms, and service providers to safeguard Marcura and customer data when engaging external providers. This involves reviewing data handling, retention, training use, privacy, residency, and access controls, while providing clear recommendations within group guidelines.
• Engineering Enablement and Security Culture: Enhance the security capabilities of engineering, product, and data teams to reduce the rate at which new vulnerabilities are introduced. This includes delivering hands-on guidance, secure coding and AI security reviews, targeted workshops, and internal champions rather than relying solely on policy.
• Documentation, Metrics and Leadership Reporting: Maintain clear documentation and report on security and AI trust posture to provide leadership with an accurate, decision-ready view of risk and ensure the function is auditable and not dependent on a single individual. This involves documenting methodology, findings, accepted risks, the AI system inventory, approved patterns, and maintaining a concise set of meaningful security metrics.
• No specific degree or certification is mandated for this role. A degree in Computer Science, Information Security, or Engineering is appreciated but not a barrier, and neither are any particular certifications.
• Instead, we are seeking **evidence of having identified actual vulnerabilities in real systems**. Candidates should be prepared to discuss bugs they personally discovered, how they found them, their significance, and the actions taken. Any of the following are strong, credible indicators:
• Vulnerabilities identified in production systems during professional testing engagements, described in technical detail.
• Published CVEs, coordinated disclosures, or security advisories.
• Bug bounty findings with a proven history on recognized platforms or private programs.
• Original security research, technical write-ups, conference presentations, or open-source security tools.
• Strong competitive CTF results, especially in web, cloud, or AI categories.
• Unique prompt injection, jailbreak, or agent abuse discoveries against real LLM deployments.
• Certifications such as OSCP, OSEP, OSWE, GXPN, CRTO, CISSP, or cloud security specialties are beneficial indicators of structured knowledge and are welcomed, but they are explicitly **not** a substitute for a demonstrable history of finding and validating real bugs. Their absence will not be a disadvantage for a candidate who can demonstrate that history.
• 8+ years of total experience in security engineering, encompassing both offensive and defensive roles rather than focusing on just one.
• At least 4 years of hands-on offensive experience: scoping, leading, and personally conducting penetration tests and red team exercises across web applications, APIs, cloud environments, and internal networks.
• Demonstrable defensive engineering experience: hardening cloud and application environments, building or fine-tuning detections, and designing identity, access, and data protection controls.
• Proven experience in assessing and securing LLM or AI systems in production, including prompt injection, jailbreaks, insecure output handling, data exfiltration, and tool or agent abuse.
• Experience as a first, sole, or founding security hire, or building a security capability from the ground up with minimal oversight and limited resources.
• A track record of influencing architectural and design decisions across engineering and product teams, not merely reporting findings.
• Experience supporting or leading security incident response in a production setting.
• Experience managing and deriving value from an MDR or managed SOC provider—onboarding telemetry, validating and tuning detection coverage, and holding the provider accountable—rather than simply consuming its alerts.
• Experience in scoping, commissioning, and critically examining external penetration tests, and integrating third-party findings into an internal remediation process.
• Experience in a regulated B2B, fintech, maritime, or logistics environment is preferred.
• - **Competitive Salary and Bonus**: We recognize and reward your expertise and contributions.
• - **Inclusive Onboarding Experience**: Our onboarding program is designed to ensure your success from day one.
• - **Marcura Wellness Zone**: We prioritize your work-life balance and well-being.
• - **Global Opportunities**: Join an ambitious, growing company with a local touch.
• - **Diverse, Supportive Work Culture**: We are dedicated to inclusion, diversity, and fostering a sense of belonging for all team members.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.