Staff Product Security Engineer (AI Security)
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
Location: McLean, Virginia; hybrid with 3 days per week onsite. Candidates in the Tysons Corner vicinity are prioritized.
Annual base salary: $154,000β$205,000.
Company
provides the Experience Cloud SaaS platform for managing customer, employee, patient, resident, and candidate experiences.
What you will do
- Lead security reviews, threat modeling, and secure architecture assessments for complex products, services, features, and engineering initiatives.
- Embed secure-by-default practices and automated security controls throughout the software development lifecycle.
- Analyze, prioritize, investigate, and remediate complex product vulnerabilities and systemic security risks.
- Design and optimize SAST, SCA, secrets detection, DAST, container, cloud, ASPM, and AI-assisted security capabilities.
- Review GenAI and AI-enabled products, including LLMs, AI agents, MCP integrations, tool invocation, and emerging AI architectures.
- Lead cross-functional initiatives, influence technical decisions, represent Product Security in architecture and customer security discussions, and mentor security engineers.
Requirements
- 8+ years of experience in application security, product security, security engineering, or a related field.
- Hands-on experience with application security, SSDLC, threat modeling, security architecture reviews, vulnerability management, and secure coding practices.
- Experience securing APIs, microservices, Kubernetes, containers, cloud-native services, and public cloud environments, preferably AWS.
- Experience with SAST, SCA, secrets detection, DAST, and ASPM platforms, plus knowledge of OWASP and common application security risks.
- Ability to independently investigate complex security issues, develop practical remediation strategies, and influence engineering teams without direct authority.
- Professional working proficiency in written and spoken English is required.
Nice to have
- Experience securing AI/ML systems, GenAI applications, LLMs, AI agents, or MCP-based architectures.
- Experience with security automation, CI/CD integrations, cloud and container security technologies.
- Familiarity with NIST, SOC 2, ISO 27001, PCI DSS, or similar frameworks.
- Customer security review or security escalation experience.
- CISSP, CSSLP, GIAC, AWS Security Specialty, or equivalent certification.
Culture & Benefits
- Hybrid work with regular onsite collaboration.
- Medical, dental, and vision coverage.
- 401(k), disability, life, and AD&D insurance.
- Statutory leaves, paid parental leave, and paid holidays.
- Equal opportunity workplace committed to diversity and inclusion.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β