3 часа назад
Senior Product Security Engineer (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Product Security Engineer (AI): Securing a regulated digital health platform and its clinical, patient-facing, cloud-native, and AI-powered systems with an accent on threat modelling, application security, and secure-by-design engineering. Focus on testing web and API products, protecting agentic workflows and LLM integrations, embedding security controls into CI/CD, and addressing complex attack paths across GCP and Kubernetes environments.
Location: Remote, London, United Kingdom
Company
builds and operates a regulated digital health platform handling clinical data, identity documents, and payment details.
What you will do
- Run STRIDE-based threat modelling sessions for new features and architectural changes, incorporating clinical safety, abuse, and business-logic risks.
- Own and evolve the Secure by Design process, including self-evaluation screening, secure design reviews, threat modelling, and automated tooling for technical artefacts.
- Translate threat models into prioritised security controls and influence engineering decisions early in the development lifecycle.
- Assess and secure production AI systems, including LLM features, retrieval pipelines, agentic workflows, tool-calling integrations, MCP surfaces, and APIs.
- Perform automated application and API penetration testing across web products, mobile backends, GCP services, internal tooling, and AI features; lead third-party penetration engagements.
- Embed SAST, SCA, secrets detection, IaC scanning, container security, dependency hygiene, authentication, authorisation, secrets management, tenancy isolation, and logging standards into engineering workflows.
Requirements
- Substantial hands-on application security experience in a product engineering environment at senior level.
- Demonstrable practical threat modelling experience and offensive security skills against modern web and API stacks.
- OSCP, OSWE, CREST, Burp Suite Certified Practitioner, or equivalent demonstrable experience.
- Ability to read production code and meaningfully review pull requests in at least one programming language.
- Working knowledge of cloud-native architecture, GCP security, Kubernetes security, and cloud security posture management using CNAPP and CSPM solutions; AWS or Azure experience is transferable.
- Experience integrating security tooling into CI/CD, shipping security improvements through other teams, and securing AI or agentic systems in production.
Nice to have
- Experience in regulated environments such as healthcare or fintech, with knowledge of ISO 27001.
- Detection engineering or incident response experience related to application attacks.
- Community contributions through talks, published research, maintained projects, OWASP, meetups, CTFs, or research groups.
Culture & Benefits
- Security operates through influence, credibility, and early collaboration rather than gatekeeping.
- Direct collaboration with Engineering, Product, Clinical, Legal, and executive stakeholders.
- Permanent remote employment.
- Opportunities to publish research, write-ups, and blog posts under your own name.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
22 часа назад
Product Security Engineer (Cybersecurity)
115 000 - 145 000$
5 дней назад
Staff Product Security Engineer (AI Security)
154 000 - 205 000$
5 дней назад
Application Security Engineer (Cybersecurity)
5 дней назад
Senior Product Security Engineer (AI)
4 дня назад
Security Engineer (AI/LLM)
120 000 - 150 000$
6 дней назад