Product Security Engineer (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Product Security Engineer (AI): Leading application and product security for a cloud-native AI medical imaging platform with an accent on secure development, cloud environments, and automated security testing. Focus on threat modeling, architecture assessments, vulnerability remediation, security tooling integration, and building measurable Secure SDLC controls.
Location: Remote
Salary: $97,700–$146,500 per year, plus an annual discretionary bonus.
Company
’ Mosaic Clinical Technologies builds MosaicOS, an AI-native cloud platform for medical imaging and radiology workflows.
What you will do
- Lead SAST, DAST, SCA, IaC, container security, and penetration testing initiatives across cloud-native environments.
- Integrate security tooling, monitoring, policy enforcement, and ASPM capabilities into CI/CD pipelines and development workflows.
- Conduct security reviews, threat modeling, architecture assessments, and risk analyses for applications, APIs, cloud platforms, and deployment environments.
- Partner with engineering, platform, and DevOps teams to implement secure-by-default practices throughout the Secure SDLC.
- Identify vulnerabilities across code, infrastructure, cloud environments, and third-party dependencies, and support remediation.
- Define security policies, standards, governance frameworks, controls, and measurable product security metrics while supporting customer and compliance reviews.
Requirements
- 5+ years of experience in Application Security, Product Security, DevSecOps, Cloud Security, or a related cybersecurity role.
- Strong knowledge of Secure SDLC principles, secure software engineering, microservices, APIs, containers, Kubernetes, and CI/CD pipelines.
- Experience securing AWS, Azure, or GCP cloud-native environments.
- Hands-on experience with SAST, DAST, SCA, container security scanning, IaC scanning, and CI/CD security integrations.
- Familiarity with OWASP, SAMM, NIST SSDF, ISO 27001, SOC 2, and CIS Benchmarks.
- A degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent practical experience.
Nice to have
- CISSP, CCSP, CASE, or an equivalent certification.
Culture & Benefits
- Flexible remote schedules.
- Health and wellness coverage options, including telehealth and family planning benefits.
- 401(k) benefits and a competitive total rewards package.
- Generous PTO plans and paid holidays.
- Compensation reviews and career growth opportunities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →