9 дней назад
Principal Product Security Engineer (AI)
85 000 - 100 000€
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Principal Product Security Engineer (AI): Building secure-by-default practices, threat models, and systemic protections for HR technology products with an accent on application security, vulnerability research, and AI feature security. Focus on performing offensive testing, eliminating root causes across services and APIs, and shaping the product security roadmap.
Location: Remote or hybrid across the Netherlands, Germany and Poland
Salary: €85,000–€100,000 per year, based on the Netherlands salary range; compensation may vary by location.
Company
builds a Talent Management Suite combining Applicant Tracking, HRIS and Performance Management for more than 7,000 companies across 100+ countries.
What you will do
- Perform manual security reviews and offensive testing across services, APIs and clients, focusing on authorization, multi-tenancy and business logic.
- Threat model high-risk product surfaces, including new AI functionality, and help engineering teams adopt the practice.
- Own the technical strategy for application security tooling, including Aikido, with emphasis on actionable findings and low false-positive rates.
- Triage vulnerabilities from internal tools, penetration tests and external researchers, assess severity and verify remediation.
- Build secure-by-default libraries, paved paths and development standards that prevent recurring vulnerability classes.
- Shape the product security roadmap and collaborate with Backend, Frontend, QA, DevOps, Product and Security.
Requirements
- Deep hands-on application or product security experience, ideally across both engineering and security roles.
- Demonstrated experience identifying vulnerabilities, proving their impact and driving fixes.
- Strong knowledge of access control, authentication and authorization, session management, injection, SSRF, deserialization, business logic abuse and supply-chain risk.
- Ability to read and write production code and work across unfamiliar systems, languages and technology stacks.
- Experience with threat modeling, cloud security, containers, CI/CD and infrastructure as code.
- Excellent English communication and a collaborative approach to partnering with engineering teams.
Nice to have
- Experience with AI and LLM application security, including prompt injection, excessive agency, data leakage, model context and RAG.
- Experience with privacy engineering, OAuth 2.0, OIDC, SAML, offensive security, platform integrations or building a product security practice.
- OSCP, CISSP, CISM or CSSLP certification.
Culture & Benefits
- Hybrid or remote working setup across the Netherlands, Germany and Poland.
- Opportunity to establish product security within Engineering with significant autonomy and direct leadership collaboration.
- €1,500 annual training budget, two dedicated learning days, a tooling budget and conference or research opportunities.
- Pension plan, travel reimbursement, wellness perks and 28 paid holiday days plus two additional relaxation days.
- Work from anywhere for four weeks per year, with an Apple MacBook and a €200 home office budget.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →