Unlock Full Resume Report

New offer - be the first one to apply!

September 1, 2026

Lead AI Security Engineer

Senior • Remote

Katowice, Poland

We are seeking a Lead AI Security Engineer to secure software across the full development lifecycle. This role embeds security into design, code, build, and release; operates application security tooling and pipelines; partners with engineering to drive remediation; and applies AI both to accelerate AppSec work and to secure AI- and LLM-powered applications.

Quick Facts

  • Flexible schedule and opportunity to work remotely within Poland
  • Chance to work abroad for up to 60 days annually
  • Business-driven relocation opportunities
  • Stable income through an Employment Contract or B2B arrangement

Responsibilities

  • Embed security into the full software development lifecycle and drive shift-left and secure-by-design practices across engineering teams.
  • Perform and facilitate threat modeling, architecture security reviews, and design reviews for applications, services, and APIs.
  • Conduct secure code reviews, both manual and AI-assisted, and advise developers on secure coding patterns and remediation.
  • Implement, configure, tune, and operate application security tooling, including SAST, DAST, IAST, SCA, secrets scanning, and IaC scanning, integrated into CI/CD pipelines.
  • Triage, validate, prioritize, and reduce false positives in security findings, and partner with development teams to track issues through remediation.
  • Define, implement, and maintain security gates and policies in CI/CD pipelines that balance risk reduction with developer velocity.
  • Secure the software supply chain, including dependency and open-source risk management, SBOM generation, artifact integrity and signing, and build-pipeline hardening.
  • Support and coordinate application penetration testing and validate fixes for identified vulnerabilities.
  • Drive secrets management, secure configuration, API security, container and image security, and microservice security practices.
  • Establish and run a security champions program; develop and deliver secure-coding training, guidelines, and reusable security patterns for developers.
  • Define and maintain application security standards, baselines, and policy-as-code; contribute to vulnerability-management and risk-acceptance processes.
  • Build, deploy, and maintain AI-assisted automations and agentic workflows for vulnerability triage, deduplication, prioritization, false-positive reduction, code review, remediation guidance, threat modeling, attack-path generation, finding enrichment, root-cause analysis, remediation-PR drafting, compliance evidence collection, and secure-coding documentation and runbook automation.
  • Build and integrate AI agents and LLM-backed automations into the SDLC and CI/CD pipelines, connecting models to scanners, code hosts, ticketing, and security tooling through function calling, REST, and webhooks.
  • Develop, test, and maintain reusable prompts, structured-prompting patterns, and prompt templates for recurring AppSec tasks; tune them for accuracy, signal quality, and safe behavior.
  • Implement retrieval over codebases, security standards, and remediation guidance, such as RAG, so AI assistants use current, authoritative internal context.
  • Build evaluation, validation, and human-in-the-loop checkpoints into AI-assisted AppSec workflows, including output verification, guardrails, and approval gates.
  • Implement security and privacy controls for AppSec AI usage, including least-privilege agent access, source-code and secrets handling, prompt-injection resistance, and auditability of AI-driven actions.
  • Design, implement, and operate security controls for AI- and LLM-powered application features, including input and output validation, prompt-injection and jailbreak defenses, tool- and function-call authorization, rate limiting, and model and data-access governance aligned to the OWASP Top 10 for LLM Applications.
  • Define and enforce guardrails for secure AI adoption in product engineering, including prompt security, model and tool access control, output handling, data protection, auditability, and human-in-the-loop processes.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or equivalent practical experience.
  • Hands-on application security experience across the software development lifecycle.
  • Strong understanding of common application vulnerability classes and mitigations, including the OWASP Top 10, and secure coding principles.
  • Practical experience with SAST, DAST, SCA, secrets scanning, and CI/CD integration.
  • Working knowledge of at least one programming language, such as Python, Java, C#, JavaScript/TypeScript, or Go, sufficient to read code and assess vulnerabilities.
  • Experience with threat modeling and secure design review methodologies.
  • Understanding of DevOps/DevSecOps practices, CI/CD pipelines, and secure-by-design principles.
  • Familiarity with cloud application security concepts in at least one major cloud platform: Azure, AWS, or GCP.
  • Experience participating in several production projects or engineering teams.
  • Ability to work with developers, architects, QA engineers, DevOps, product, and security teams, and influence without owning the codebase.
  • Ability to follow, maintain, and improve defined security processes.
  • Practical understanding of AI-assisted productivity and automation beyond basic chatbot use, including AI agents, security-task automation, LLM integrations with tools, APIs, documents, or workflows, prompt engineering, structured prompting, AI-assisted runbooks, scripts, queries, or documentation, and secure AI use.
  • Good communication skills and the ability to explain security risks, technical decisions, and remediation plans to technical and non-technical stakeholders.

Nice to Have

  • Experience with Snyk, Checkmarx, Veracode, SonarQube, Semgrep, GitHub Advanced Security, Burp Suite, OWASP ZAP, or similar application security platforms and tools.
  • Experience with software supply chain security, including SBOM, SLSA, Sigstore, dependency controls, and artifact-integrity controls.
  • Experience with Infrastructure as Code and policy-as-code security tools, including Terraform, Bicep, ARM templates, OPA, Checkov, or Trivy.
  • Experience with container and Kubernetes security, including image scanning, registries, runtime protection, and network policies.
  • Experience with API security, secrets management such as HashiCorp Vault or Azure Key Vault, and microservice security patterns.
  • Understanding of ISO 27001, NIST, CIS Benchmarks, PCI DSS, HIPAA, SOC 2, SOX, or another compliance or security framework.
  • Experience integrating security findings with SIEM/SOAR, ticketing, and vulnerability-management workflows.
  • Experience with Azure OpenAI, Azure AI Foundry, Amazon Bedrock, Microsoft Copilot Studio, LangChain, AutoGen, or similar AI/LLM platforms and frameworks.
  • Understanding of AI and LLM application-security risks, including prompt injection, insecure output handling, data leakage, excessive agency, insecure tool use, model governance, and AI supply-chain risks.
  • Security certifications such as CSSLP, GWAPT, GWEB, OSCP, OSWE, CISSP, CISM, or CCSP; AI-related certifications such as AI-900 or AI-102 are a plus.

Benefits

  • Engineering community of industry professionals and a friendly working environment.
  • Career roadmap, leadership development, career advising, soft-skills programs, and well-being programs.
  • Certification opportunities for GCP, Azure, and AWS.
  • Unlimited access to LinkedIn Learning, Get Abstract, and Cloud Guru.
  • English classes.
  • Participation in the Employee Stock Purchase Plan.
  • Benefits package including health insurance, multisport, and shopping vouchers.
  • Offices with entertainment and relaxation zones, table tennis, football, free snacks, and coffee.
  • Referral bonuses and corporate, social, and well-being events.

The set of bonuses may vary based on the role; specifics will be discussed during the general interview. Only selected candidates will be contacted.

Similar jobs you might like