freehire launches on Product Hunt on 26 August.

Follow β†’

Senior Security Engineer: AI & DevSecOps

Summary

As a Senior Security Engineer, you'll implement security initiatives across cloud infrastructure, software delivery pipelines, and AI-enabled development environments, focusing on AI security, DevSecOps, and cloud-native security controls.

What You'll Be Doing

As a Senior DevSecOps & AI Security Engineer, you'll own the technical implementation of security initiatives across cloud infrastructure, software delivery pipelines, and AI-enabled development environments.

πŸ€– Secure AI Platforms & Agentic AI

  • Design and implement security architectures that enable the safe adoption of Generative AI, AI coding assistants, LLMs, and autonomous AI agents.
  • Define and enforce security guardrails for AI systems capable of executing code, accessing enterprise resources, interacting with APIs, and handling sensitive information.
  • Assess and mitigate AI-specific risks, including:
  • Prompt Injection
  • Data Exfiltration
  • Model Supply Chain Risks
  • AI Agent Abuse
  • LLM Security Vulnerabilities
  • Sensitive Data Exposure
  • Support the secure integration of externally developed AI services and platforms into enterprise environments.
  • Collaborate with engineering and data teams to ensure AI solutions are designed with security, privacy, and compliance by default.

☁️ Cloud Security & DevSecOps

  • Design, implement, and continuously improve security controls across modern cloud-native infrastructure.
  • Embed automated security controls into CI/CD pipelines, Infrastructure as Code (IaC), and software delivery workflows.
  • Promote DevSecOps best practices by integrating security into every stage of the software development lifecycle.
  • Continuously assess cloud environments to identify vulnerabilities, misconfigurations, and opportunities for security improvement.

πŸ›‘οΈ Security Engineering

  • Own and administer enterprise security platforms, ensuring they are correctly configured, monitored, and continuously optimized.
  • Implement automated security monitoring, vulnerability management, endpoint protection, cloud security posture management, and zero-trust networking.
  • Build internal automation tools that improve operational efficiency and reduce manual security processes.
  • Develop security scripts and integrations using Python and other automation technologies.

Protect Modern Development Environments

  • Secure developer platforms, CI/CD pipelines, source code repositories, build systems, and internal engineering tooling.
  • Define least-privilege access models for cloud resources, AI systems, and development environments.
  • Strengthen identity, authentication, authorization, and audit capabilities across engineering platforms.
  • Ensure traceability, logging, and security monitoring for AI workloads and cloud-native applications.

🀝 Collaboration & Security Leadership

  • Partner with Software Engineers, DevOps Engineers, Platform Teams, Data Scientists, Architects, and Security professionals to build secure engineering practices.
  • Translate governance and compliance requirements into practical, automated technical controls.
  • Support security reviews, architecture discussions, and technology evaluations from a security engineering perspective.
  • Represent the technical security function during internal and external audits by presenting security controls, technical evidence, and implementation practices.
  • Champion a security-first engineering culture without compromising developer productivity or innovation.

πŸ› οΈ What We're Looking For

Required Experience

βœ”οΈ Strong background in Software Engineering, Platform Engineering, DevOps, or Cloud Engineering, followed by experience in Cybersecurity or Security Engineering.

βœ”οΈ Hands-on experience securing modern cloud-native infrastructure and containerized environments.

βœ”οΈ Experience implementing DevSecOps practices and integrating security into CI/CD pipelines.

βœ”οΈ Strong understanding of Infrastructure as Code (IaC) and cloud automation principles.

βœ”οΈ Experience administering enterprise security platforms covering areas such as:

  • Cloud Security Posture Management (CNAPP)
  • Endpoint Detection & Response (EDR)
  • Security Information & Event Management (SIEM)
  • Zero Trust Networking

βœ”οΈ Strong scripting and automation skills using Python.

βœ”οΈ Excellent communication skills with the ability to collaborate across engineering, security, and business teams.

Technical Stack

Security

  • Cloud Security
  • DevSecOps
  • Zero Trust Architecture
  • Vulnerability Management
  • Identity & Access Management (IAM)
  • Least Privilege
  • Security Automation
  • Security Monitoring
  • Threat Detection
  • Compliance & Audit

AI Security

  • Generative AI
  • Agentic AI
  • Large Language Models (LLMs)
  • AI Coding Assistants
  • AI Governance
  • Prompt Injection Mitigation
  • AI Supply Chain Security
  • Secure AI Adoption

Cloud & Infrastructure

  • Cloud-Native Applications
  • Containers
  • Kubernetes
  • Infrastructure as Code (IaC)
  • CI/CD Pipelines

Automation

  • Python
  • Security Automation
  • Infrastructure Automation

Security Platforms (Ideally)

  • Wiz
  • CrowdStrike
  • Google SecOps
  • Tailscale

⭐ Nice to Have

βž• Experience securing AI workloads, machine learning platforms, or enterprise data pipelines.

βž• Knowledge of container security and Kubernetes security best practices.

βž• Experience implementing cloud-native security architectures.

βž• Familiarity with secure software supply chain practices (SBOM, SAST, DAST, dependency scanning, secrets management).

βž• Experience working in highly regulated industries where security, privacy, and compliance are business-critical.

See also

Tailor your CV for this role?

We couldn't check your fit for this role β€” add a CV to your profile to see it next time.

A new version of freehire is available