Назад
Company hidden
3 часа назад

Senior Product Security Engineer (AI)

Формат работы
remote (только United_kingdom)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Product Security Engineer (AI): Securing a regulated digital health platform and its clinical, patient-facing, cloud-native, and AI-powered systems with an accent on threat modelling, application security, and secure-by-design engineering. Focus on testing web and API products, protecting agentic workflows and LLM integrations, embedding security controls into CI/CD, and addressing complex attack paths across GCP and Kubernetes environments.

Location: Remote, London, United Kingdom

Company

hirify.global builds and operates a regulated digital health platform handling clinical data, identity documents, and payment details.

What you will do

  • Run STRIDE-based threat modelling sessions for new features and architectural changes, incorporating clinical safety, abuse, and business-logic risks.
  • Own and evolve the Secure by Design process, including self-evaluation screening, secure design reviews, threat modelling, and automated tooling for technical artefacts.
  • Translate threat models into prioritised security controls and influence engineering decisions early in the development lifecycle.
  • Assess and secure production AI systems, including LLM features, retrieval pipelines, agentic workflows, tool-calling integrations, MCP surfaces, and APIs.
  • Perform automated application and API penetration testing across web products, mobile backends, GCP services, internal tooling, and AI features; lead third-party penetration engagements.
  • Embed SAST, SCA, secrets detection, IaC scanning, container security, dependency hygiene, authentication, authorisation, secrets management, tenancy isolation, and logging standards into engineering workflows.

Requirements

  • Substantial hands-on application security experience in a product engineering environment at senior level.
  • Demonstrable practical threat modelling experience and offensive security skills against modern web and API stacks.
  • OSCP, OSWE, CREST, Burp Suite Certified Practitioner, or equivalent demonstrable experience.
  • Ability to read production code and meaningfully review pull requests in at least one programming language.
  • Working knowledge of cloud-native architecture, GCP security, Kubernetes security, and cloud security posture management using CNAPP and CSPM solutions; AWS or Azure experience is transferable.
  • Experience integrating security tooling into CI/CD, shipping security improvements through other teams, and securing AI or agentic systems in production.

Nice to have

  • Experience in regulated environments such as healthcare or fintech, with knowledge of ISO 27001.
  • Detection engineering or incident response experience related to application attacks.
  • Community contributions through talks, published research, maintained projects, OWASP, meetups, CTFs, or research groups.

Culture & Benefits

  • Security operates through influence, credibility, and early collaboration rather than gatekeeping.
  • Direct collaboration with Engineering, Product, Clinical, Legal, and executive stakeholders.
  • Permanent remote employment.
  • Opportunities to publish research, write-ups, and blog posts under your own name.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →