2 месяца назад
Product Security Engineer II (AI Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Product Security Engineer II (AI Security): Identifying, assessing, and remediating security risks across applications, APIs, cloud environments, and AI-enabled features with an accent on vulnerability management, security reviews, and secure development practices. Focus on integrating SAST, SCA, DAST, container, and cloud security tooling into CI/CD, validating vulnerabilities, and testing risks such as prompt injection and sensitive data exposure.
Location: Palermo, Ciudad Autónoma de Buenos Aires (CABA), Argentina
Company
provides the Experience Cloud, a SaaS platform for managing customer, employee, patient, candidate, and resident experiences.
What you will do
- Perform security reviews of applications, APIs, features, product changes, architectures, and implementations.
- Triage, validate, prioritize, track, and close vulnerabilities from security tools, penetration tests, bug bounty reports, and internal reviews.
- Operate SAST, SCA, secrets detection, DAST, container security, cloud security, and ASPM tooling.
- Integrate security controls into CI/CD and developer workflows, improve scan coverage, reduce false positives, and develop lightweight automation.
- Support penetration testing, targeted security validation, bug bounty triage, and secure development lifecycle activities.
- Review GenAI and AI-enabled features, including risks such as prompt injection, sensitive data exposure, and unsafe tool invocation.
Requirements
- 2–5 years of experience in application security, product security, penetration testing, security engineering, or software engineering with a security focus.
- Working knowledge of OWASP Top 10, web and API security, authentication and authorization, common application vulnerabilities, and secure coding principles.
- Experience with at least one application security or vulnerability management tool, such as SAST, SCA, DAST, or secrets detection.
- Basic understanding of cloud and container technologies, plus scripting or programming experience with Python, Java, JavaScript, Go, or similar.
- Ability to analyze technical findings, provide remediation guidance to developers, work independently on defined tasks, and collaborate on complex investigations.
- Professional working proficiency in written and spoken English is required.
Nice to have
- Experience with AWS or other major cloud platforms, Kubernetes, containers, microservices, or modern API architectures.
- Experience with penetration testing, vulnerability research, CI/CD, or DevSecOps practices.
- Exposure to GenAI, LLM, or AI application security and experience working directly with software engineering teams.
- Security certifications or relevant technical training.
Culture & Benefits
- Collaborate with Product Security, Engineering, Product, Cloud Security, and other Security teams.
- Participate in Product Security on-call and intake processes.
- Contribute to documentation, knowledge sharing, process improvements, and automation.
- Work in an environment committed to diversity and equal opportunity.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →