Senior Security Engineer: AI & DevSecOps
Summary
As a Senior Security Engineer, you'll implement security initiatives across cloud infrastructure, software delivery pipelines, and AI-enabled development environments, focusing on AI security, DevSecOps, and cloud-native security controls.
What You'll Be Doing
As a Senior DevSecOps & AI Security Engineer, you'll own the technical implementation of security initiatives across cloud infrastructure, software delivery pipelines, and AI-enabled development environments.
π€ Secure AI Platforms & Agentic AI
- Design and implement security architectures that enable the safe adoption of Generative AI, AI coding assistants, LLMs, and autonomous AI agents.
- Define and enforce security guardrails for AI systems capable of executing code, accessing enterprise resources, interacting with APIs, and handling sensitive information.
- Assess and mitigate AI-specific risks, including:
- Prompt Injection
- Data Exfiltration
- Model Supply Chain Risks
- AI Agent Abuse
- LLM Security Vulnerabilities
- Sensitive Data Exposure
- Support the secure integration of externally developed AI services and platforms into enterprise environments.
- Collaborate with engineering and data teams to ensure AI solutions are designed with security, privacy, and compliance by default.
βοΈ Cloud Security & DevSecOps
- Design, implement, and continuously improve security controls across modern cloud-native infrastructure.
- Embed automated security controls into CI/CD pipelines, Infrastructure as Code (IaC), and software delivery workflows.
- Promote DevSecOps best practices by integrating security into every stage of the software development lifecycle.
- Continuously assess cloud environments to identify vulnerabilities, misconfigurations, and opportunities for security improvement.
π‘οΈ Security Engineering
- Own and administer enterprise security platforms, ensuring they are correctly configured, monitored, and continuously optimized.
- Implement automated security monitoring, vulnerability management, endpoint protection, cloud security posture management, and zero-trust networking.
- Build internal automation tools that improve operational efficiency and reduce manual security processes.
- Develop security scripts and integrations using Python and other automation technologies.
Protect Modern Development Environments
- Secure developer platforms, CI/CD pipelines, source code repositories, build systems, and internal engineering tooling.
- Define least-privilege access models for cloud resources, AI systems, and development environments.
- Strengthen identity, authentication, authorization, and audit capabilities across engineering platforms.
- Ensure traceability, logging, and security monitoring for AI workloads and cloud-native applications.
π€ Collaboration & Security Leadership
- Partner with Software Engineers, DevOps Engineers, Platform Teams, Data Scientists, Architects, and Security professionals to build secure engineering practices.
- Translate governance and compliance requirements into practical, automated technical controls.
- Support security reviews, architecture discussions, and technology evaluations from a security engineering perspective.
- Represent the technical security function during internal and external audits by presenting security controls, technical evidence, and implementation practices.
- Champion a security-first engineering culture without compromising developer productivity or innovation.
π οΈ What We're Looking For
Required Experience
βοΈ Strong background in Software Engineering, Platform Engineering, DevOps, or Cloud Engineering, followed by experience in Cybersecurity or Security Engineering.
βοΈ Hands-on experience securing modern cloud-native infrastructure and containerized environments.
βοΈ Experience implementing DevSecOps practices and integrating security into CI/CD pipelines.
βοΈ Strong understanding of Infrastructure as Code (IaC) and cloud automation principles.
βοΈ Experience administering enterprise security platforms covering areas such as:
- Cloud Security Posture Management (CNAPP)
- Endpoint Detection & Response (EDR)
- Security Information & Event Management (SIEM)
- Zero Trust Networking
βοΈ Strong scripting and automation skills using Python.
βοΈ Excellent communication skills with the ability to collaborate across engineering, security, and business teams.
Technical Stack
Security
- Cloud Security
- DevSecOps
- Zero Trust Architecture
- Vulnerability Management
- Identity & Access Management (IAM)
- Least Privilege
- Security Automation
- Security Monitoring
- Threat Detection
- Compliance & Audit
AI Security
- Generative AI
- Agentic AI
- Large Language Models (LLMs)
- AI Coding Assistants
- AI Governance
- Prompt Injection Mitigation
- AI Supply Chain Security
- Secure AI Adoption
Cloud & Infrastructure
- Cloud-Native Applications
- Containers
- Kubernetes
- Infrastructure as Code (IaC)
- CI/CD Pipelines
Automation
- Python
- Security Automation
- Infrastructure Automation
Security Platforms (Ideally)
- Wiz
- CrowdStrike
- Google SecOps
- Tailscale
β Nice to Have
β Experience securing AI workloads, machine learning platforms, or enterprise data pipelines.
β Knowledge of container security and Kubernetes security best practices.
β Experience implementing cloud-native security architectures.
β Familiarity with secure software supply chain practices (SBOM, SAST, DAST, dependency scanning, secrets management).
β Experience working in highly regulated industries where security, privacy, and compliance are business-critical.