3 дня назад
Security Engineer (AI, Automation, Enterprise Resilience)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Engineer (AI, Automation, Enterprise Resilience): Lead application security reviews, AI governance, zero-trust architecture, and automated compliance tooling with an accent on integrating security into SDLC and AI safety. Focus on designing secure AI systems, managing audits, mentoring engineers on secure coding, and maintaining incident runbooks for emerging AI threats.
Location
Location: Prague, Czech Republic (On-site)
Company
is a startup redefining enterprise software security with an AI agent for autonomous vulnerability remediation, focusing on AI, automation, and enterprise resilience.
What you will do
- Lead application security reviews and threat modeling for core products, microservices, and AI/LLM integrations.
- Translate AI governance policies into engineering guardrails and implement AI observability and risk controls.
- Design and enforce zero-trust architecture and automated cloud compliance with Infrastructure/DevOps teams.
- Build internal security automation for vulnerability triage, log analysis, and audit evidence collection.
- Serve as technical lead for ISO 27001, SOC 2, and ISO 42001 audits, interfacing with external auditors.
- Mentor engineers on secure coding, threat modeling, and secure AI usage; create secure-by-default code patterns.
- Maintain incident and threat runbooks for AI-specific and emerging security scenarios.
Requirements
- 5+ years of combined GRC/Audit and hands-on Application Security, Security Engineering, or Cloud Infrastructure experience.
- Experience with CI/CD security tools (SAST/DAST), cloud controls, scripting (Python, Bash, Go), and automated GRC platforms.
- Deep knowledge of security frameworks (SOC2, ISO 27001, ISO 42001, NIST, GDPR) mapped to infrastructure and code.
- Understanding of AI/LLM security including OWASP Top 10 for LLMs and threat modeling for RAG pipelines.
- Ability to analyze code and logs and communicate vulnerabilities effectively across technical and executive levels.
- Bonus: Background in Software Engineering, Cloud Architecture, or certifications like CISSP, CCSP, OSCP, CISA.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →