Posted on: 03/10/2026
Role Overview:
We are looking for a Senior AI Product Security Engineer to secure enterprise applications and AI-powered products across multiple engineering teams and repositories.
Key Responsibilities:
- Own security assessments across enterprise applications, products, repositories, and engineering teams.
- Perform hands-on Web, API, cloud, and Kubernetes security testing, including vulnerability discovery and validation.
- Conduct threat modeling and security assessments for AI/LLM applications, RAG systems, and AI agents.
- Identify AI-specific risks such as prompt injection, data leakage, RAG poisoning, excessive permissions, and unsafe tool calls.
- Identify and prioritize vulnerabilities based on exploitability, business impact, and risk.
- Work directly with engineering teams to drive remediation, retesting, and closure.
- Integrate security into SDLC and CI/CD pipelines using SAST, DAST, SCA, secrets detection, and security gates.
- Establish scalable security practices across multiple products and teams.
- Communicate technical vulnerabilities, business impact, and remediation requirements to engineering and business stakeholders.
Qualifications:
- 5+ years of hands-on experience in Product Security, Application Security, or Security Engineering.
- Strong experience with Web/API Security, OWASP Top 10, vulnerability assessment, and threat modeling.
- Proven ability to discover and validate real-world vulnerabilities, beyond automated scanners.
- Experience with Burp Suite/ZAP, source-code security review, and root-cause analysis.
- Experience securing cloud, Kubernetes/GKE, IAM, containers, and CI/CD environments.
- Experience with SAST, DAST, and SCA within the SDLC.
- Practical experience with AI/LLM security, RAG security, or AI agent security.
- Ability to prioritize security risks and drive vulnerabilities through remediation and closure.
- Strong communication and stakeholder-management skills.
Nice to Have:
- GCP/GKE, Vertex AI, Gemini, or Model Armor experience.
- Experience with AI red teaming or LLM security testing.
- OSCP, OSWE, GIAC, CREST, or equivalent certification.
The job is for:
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1676484