Назад
Company hidden
3 часа назад

Principal Security Engineer (AI)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Principal Security Engineer (AI): Designing and evolving SaaS Security Posture Management (SSPM) programs with an accent on third-party security risk, secure baseline configurations, and AI-driven automation. Focus on leveraging LLMs and autonomous AI Agents to scale security assessments, streamline workflows, and secure complex enterprise supply chains.

Location: Remote (USA). Must be based in the United States.

Company

A global leader in customer relationship management software and enterprise cloud solutions.

What you will do

  • Lead the design and lifecycle management of secure configuration baselines for enterprise SaaS solutions.
  • Perform high-quality security assessments of third-party suppliers using penetration testing and audit findings.
  • Spearhead the integration of LLMs and autonomous AI Agents to automate complex security operations.
  • Define security requirements for emerging technologies and manage the lifecycle of shadow IT integrations.
  • Act as the subject matter expert for SaaS-related telemetry and security data analysis.
  • Partner with legal, sourcing, and business teams to ensure supplier compliance with security requirements.

Requirements

  • 12+ years of professional experience in a security role.
  • Proven expertise in managing large-scale third-party security programs.
  • Demonstrated experience defining and deploying secure configuration baselines in an enterprise SaaS environment.
  • Strong background in utilizing LLMs and AI Agents for security workflow automation.
  • Ability to perform web application penetration tests aligned with OWASP methodologies.
  • Relevant technical degree or equivalent industry certifications.

Nice to have

  • Familiarity with ISO 27001, SOC 2, NIST CSF, and PCI DSS standards.
  • Experience with contract language review regarding security clauses.
  • Knowledge of MITRE ATT&CK framework and CWE Top 25.
  • Professional certifications such as CISSP, CISM, or CCSK.

Culture & Benefits

  • Focus on continuous improvement and innovation within security engineering.
  • Opportunity to contribute to internal research papers and present at industry conferences.
  • Cross-functional collaboration with diverse business and technical departments.
  • Work on high-impact projects at the intersection of AI and enterprise cybersecurity.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →