Unlock Full Resume Report

New offer - be the first one to apply!

September 1, 2026

Senior AI Security Engineer

Senior • Remote

Krakow, MA, Poland

We are seeking a Senior AI Security Engineer to secure software across the full development lifecycle. This role embeds security into design, code, build, and release; operates application security tooling and pipelines; partners with engineering to drive remediation; and applies AI both to accelerate AppSec work and to secure AI- and LLM-powered applications.

Quick Facts

  • Flexible schedule and opportunity to work remotely within Poland
  • Chance to work abroad for up to 60 days annually
  • Business-driven relocation opportunities
  • Stable income through an Employment Contract or B2B arrangement

Responsibilities

  • Embed security into the full software development lifecycle and drive shift-left and secure-by-design practices across engineering teams.
  • Perform and facilitate threat modeling, architecture security reviews, and design reviews for applications, services, and APIs.
  • Conduct secure code reviews, both manual and AI-assisted, and advise developers on secure coding patterns and remediation.
  • Implement, configure, tune, and operate application security tooling, including SAST, DAST, IAST, SCA, secrets scanning, and IaC scanning, integrated into CI/CD pipelines.
  • Triage, validate, prioritize, and reduce false positives in security findings, and partner with development teams to track issues through remediation.
  • Define, implement, and maintain security gates and policies in CI/CD pipelines that balance risk reduction with developer velocity.
  • Secure the software supply chain, including dependency and open-source risk management, SBOM generation, artifact integrity and signing, and build-pipeline hardening.
  • Support and coordinate application penetration testing and validate fixes for identified vulnerabilities.
  • Drive secrets management, secure configuration, API security, container and image security, and microservice security practices.
  • Establish and run a security champions program, and develop and deliver secure-coding training, guidelines, and reusable security patterns for developers.
  • Define and maintain application security standards, baselines, and policy-as-code, and contribute to vulnerability management and risk-acceptance processes.
  • Build, deploy, and maintain AI-assisted automations and agentic workflows for vulnerability triage, deduplication, prioritization, false-positive reduction, code review, remediation guidance, threat-modeling support, finding enrichment, root-cause analysis, remediation-PR drafting, compliance evidence collection, and documentation automation.
  • Build and integrate AI agents and LLM-backed automations into the SDLC and CI/CD pipelines, connecting models to scanners, code hosts, ticketing, and security tooling through function calling, REST, and webhooks.
  • Develop, test, and maintain reusable prompts, structured-prompting patterns, and prompt templates for recurring AppSec tasks; tune them for accuracy, signal quality, and safe behavior.
  • Implement retrieval over codebases, security standards, and remediation guidance, such as RAG, so AI assistants use current, authoritative internal context.
  • Build evaluation, validation, and human-in-the-loop checkpoints into AI-assisted AppSec workflows, including output verification, guardrails, and approval gates.
  • Implement security and privacy controls for AppSec AI usage, including least-privilege agent access, source-code and secrets handling, prompt-injection resistance, and auditability of AI-driven actions.
  • Design, implement, and operate security controls for AI- and LLM-powered application features, including input and output validation, prompt-injection and jailbreak defenses, tool- and function-call authorization, rate limiting, and model and data access governance, aligned to the OWASP Top 10 for LLM Applications.
  • Define and enforce guardrails for secure AI adoption in product engineering, covering prompt security, model and tool access control, output handling, data protection, auditability, and human-in-the-loop processes.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or equivalent practical experience.
  • Hands-on application security experience across the software development lifecycle.
  • Strong understanding of common application vulnerability classes and mitigations, including the OWASP Top 10, and secure coding principles.
  • Practical experience with application security tooling, such as SAST, DAST, SCA, and secrets scanning, and integrating it into CI/CD.
  • Working knowledge of at least one programming language, such as Python, Java, C#, JavaScript/TypeScript, or Go, sufficient to read code and assess vulnerabilities.
  • Experience with threat modeling and secure design review methodologies.
  • Understanding of DevOps/DevSecOps practices, CI/CD pipelines, and secure-by-design principles.
  • Familiarity with cloud application security concepts in at least one major cloud platform, such as Azure, AWS, or GCP.
  • Experience participating in several production projects or engineering teams.
  • Ability to work closely with developers, architects, QA engineers, DevOps, product, and security teams, and to influence without owning the codebase.
  • Ability to follow, maintain, and improve defined security processes.
  • Practical understanding of AI-assisted productivity and automation beyond basic chatbot usage, including AI agents, LLM integrations, prompt engineering, AI-assisted runbooks, scripts, queries, or documentation, and secure AI usage.
  • Good communication skills and the ability to explain security risks, technical decisions, and remediation plans to technical and non-technical stakeholders.

Nice to Have

  • Experience with application security platforms and tools such as Snyk, Checkmarx, Veracode, SonarQube, Semgrep, GitHub Advanced Security, Burp Suite, and OWASP ZAP.
  • Experience with software supply chain security, including SBOM, SLSA, Sigstore, dependency controls, and artifact integrity controls.
  • Experience with Infrastructure as Code and policy-as-code security tools such as Terraform, Bicep, ARM templates, OPA, Checkov, or Trivy.
  • Experience with container and Kubernetes security, including image scanning, registries, runtime protection, and network policies.
  • Experience with API security, secrets management, such as HashiCorp Vault or Azure Key Vault, and microservice security patterns.
  • Understanding of a compliance or security framework, such as ISO 27001, NIST, CIS Benchmarks, PCI DSS, HIPAA, SOC 2, or SOX.
  • Experience integrating security findings with SIEM/SOAR, ticketing, and vulnerability-management workflows.
  • Experience with AI/LLM platforms or frameworks such as Azure OpenAI, Azure AI Foundry, Amazon Bedrock, Microsoft Copilot Studio, LangChain, or AutoGen.
  • Understanding of AI and LLM application-security risks, including prompt injection, insecure output handling, data leakage, excessive agency, insecure tool use, model governance, and AI supply-chain risks.
  • Security certifications such as CSSLP, GWAPT, GWEB, OSCP, OSWE, CISSP, CISM, or CCSP; AI-related certifications such as AI-900 or AI-102 are also a plus.

Benefits

  • Engineering community of industry professionals and a friendly working environment.
  • Career roadmap, leadership development, career advising, soft-skills, and well-being programs.
  • Certification opportunities in GCP, Azure, and AWS.
  • Unlimited access to LinkedIn Learning, Get Abstract, and Cloud Guru.
  • English classes.
  • Participation in the Employee Stock Purchase Plan.
  • Benefits package including health insurance, multisport, and shopping vouchers.
  • Offices with entertainment and relaxation zones, table tennis, football, free snacks, and coffee.
  • Referral bonuses and corporate, social, and well-being events.

The set of bonuses may vary based on the role; specifics will be discussed during the general interview. Only selected candidates will be contacted.

Similar jobs you might like