Unlock Full Resume Report
ATS Pass
Missing keywords
Tailored AI suggestions
Job match analysis
Interview-focused insights
New offer - be the first one to apply!
September 1, 2026
Lead AI Security Engineer
Senior • Remote
Warsaw, Poland
Apply now
We are seeking a Lead AI Security Engineer to secure software across the full development lifecycle. This role embeds security into design, code, build, and release; operates application security tooling and pipelines; partners with engineering to drive remediation; and applies AI both to accelerate AppSec work and to secure AI- and LLM-powered applications.
Responsibilities
- Embed security into the full software development lifecycle and drive shift-left and secure-by-design practices across engineering teams.
- Perform and facilitate threat modeling, architecture security reviews, and design reviews for applications, services, and APIs.
- Conduct secure code reviews, both manual and AI-assisted, and advise developers on secure coding patterns and remediation.
- Implement, configure, tune, and operate application security tooling, including SAST, DAST, IAST, SCA, secrets scanning, and IaC scanning, integrated into CI/CD pipelines.
- Triage, validate, prioritize, and reduce false positives in security findings, and partner with development teams to track issues through remediation.
- Define, implement, and maintain security gates and policies in CI/CD pipelines that balance risk reduction with developer velocity.
- Secure the software supply chain, including dependency and open-source risk management, SBOM generation, artifact integrity and signing, and build-pipeline hardening.
- Support and coordinate application penetration testing and validate fixes for identified vulnerabilities.
- Drive secrets management, secure configuration, API security, container and image security, and microservice security practices.
- Establish and run a security champions program, and develop and deliver secure-coding training, guidelines, and reusable security patterns for developers.
- Define and maintain application security standards, baselines, and policy-as-code, and contribute to vulnerability management and risk-acceptance processes.
- Build, deploy, and maintain AI-assisted automations and agentic workflows that reduce manual effort across application security activities, including vulnerability triage, deduplication, prioritization, false-positive reduction, code review, remediation guidance, threat modeling, finding enrichment, root-cause analysis, remediation-PR drafting, compliance evidence collection, and security documentation automation.
- Build and integrate AI agents and LLM-backed automations into the SDLC and CI/CD pipelines, connecting models to scanners, code hosts, ticketing, and security tooling through function calling, REST, and webhooks.
- Develop, test, and maintain reusable prompts, structured-prompting patterns, and prompt templates for recurring AppSec tasks; tune them for accuracy, signal quality, and safe behavior.
- Implement retrieval over codebases, security standards, and remediation guidance, such as RAG, so AI assistants use current, authoritative internal context.
- Build evaluation, validation, and human-in-the-loop checkpoints into AI-assisted AppSec workflows, including output verification, guardrails, and approval gates.
- Implement security and privacy controls for AppSec AI usage, including least-privilege agent access, source-code and secrets handling, prompt-injection resistance, and auditability of AI-driven actions.
- Design, implement, and operate security controls for AI- and LLM-powered application features, including input and output validation, prompt-injection and jailbreak defenses, tool- and function-call authorization, rate limiting, and model and data access governance, aligned with the OWASP Top 10 for LLM Applications.
- Define and enforce guardrails for secure AI adoption in product engineering, covering prompt security, model and tool access control, output handling, data protection, auditability, and human-in-the-loop processes.
Requirements
- Bachelor’s degree in Computer Science, Information Security, Engineering, or equivalent practical experience.
- Hands-on application security experience across the software development lifecycle.
- Strong understanding of common application vulnerability classes and mitigations, including the OWASP Top 10, and secure coding principles.
- Practical experience with SAST, DAST, SCA, secrets scanning, and CI/CD integration.
- Working knowledge of at least one programming language—such as Python, Java, C#, JavaScript/TypeScript, or Go—sufficient to read code and assess vulnerabilities.
- Experience with threat modeling and secure design review methodologies.
- Understanding of DevOps/DevSecOps practices, CI/CD pipelines, and secure-by-design principles.
- Familiarity with cloud application security concepts in Azure, AWS, or GCP.
- Experience participating in several production projects or engineering teams.
- Ability to collaborate with developers, architects, QA engineers, DevOps, product, and security teams and influence without owning the codebase.
- Ability to follow, maintain, and improve defined security processes.
- Practical understanding of AI-assisted productivity and automation beyond basic chatbot usage, including AI agents, automation of repetitive security or engineering tasks, LLM integrations, prompt engineering, AI-assisted runbooks, scripts, queries, or documentation, and secure AI tool use.
- Good communication skills and the ability to explain security risks, technical decisions, and remediation plans to technical and non-technical stakeholders.
Nice to have
- Experience with Snyk, Checkmarx, Veracode, SonarQube, Semgrep, GitHub Advanced Security, Burp Suite, OWASP ZAP, or similar application security tools.
- Experience with software supply-chain security, including SBOM, SLSA, Sigstore, dependency controls, and artifact-integrity controls.
- Experience with Infrastructure as Code and policy-as-code security tools such as Terraform, Bicep, ARM templates, OPA, Checkov, or Trivy.
- Experience with container and Kubernetes security, including image scanning, registries, runtime protection, and network policies.
- Experience with API security, secrets management tools such as HashiCorp Vault or Azure Key Vault, and microservice security patterns.
- Understanding of ISO 27001, NIST, CIS Benchmarks, PCI DSS, HIPAA, SOC 2, SOX, or another compliance or security framework.
- Experience integrating security findings with SIEM/SOAR, ticketing, and vulnerability-management workflows.
- Experience with Azure OpenAI, Azure AI Foundry, Amazon Bedrock, Microsoft Copilot Studio, LangChain, AutoGen, or similar AI/LLM platforms or frameworks.
- Understanding of AI and LLM application-security risks, including prompt injection, insecure output handling, data leakage, excessive agency, insecure tool use, model governance, and AI supply-chain risks.
- Security certifications such as CSSLP, GWAPT, GWEB, OSCP, OSWE, CISSP, CISM, or CCSP; AI-related certifications such as AI-900 or AI-102 are also a plus.
We offer
- Engineering community of industry professionals.
- Friendly team and enjoyable working environment.
- Flexible schedule and opportunity to work remotely within Poland.
- Chance to work abroad for up to 60 days annually.
- Business-driven relocation opportunities.
- Career roadmap, leadership development, career advising, soft-skills, and well-being programs.
- Certification opportunities in GCP, Azure, and AWS.
- Unlimited access to LinkedIn Learning, Get Abstract, and Cloud Guru.
- English classes.
- Stable income through an Employment Contract or B2B arrangement.
- Participation in the Employee Stock Purchase Plan.
- Benefits package including health insurance, multisport, and shopping vouchers.
- Offices with entertainment and relaxation zones, table tennis and football, free snacks, and coffee.
- Referral bonuses.
- Corporate, social, and well-being events.
The set of bonuses may vary by role. Only selected candidates will be contacted.
Similar jobs you might like
Lead AI Security Engineer
EPAM Systems
Senior
Technology
Wroclaw, DS, Poland · Remote
N/A
1h ago
Lead AI Security Engineer
EPAM Systems
Senior
Technology
Poznań, WP, Poland · Remote
N/A
1h ago
Lead AI Security Engineer
EPAM Systems
Senior
Technology
Katowice, Poland · Remote
N/A
1h ago
Senior AI Security Engineer
EPAM Systems
Senior
Technology
Krakow, MA, Poland · Remote
N/A
1h ago
Senior AI Security Engineer
EPAM Systems
Senior
Technology
Gdansk, PM, Poland · Remote
N/A
1h ago
Senior AI Security Engineer
EPAM Systems
Senior
Technology
Lodz, Poland · Remote
N/A
1h ago
Lead Azure AI Security Engineer
EPAM Systems
Senior
Technology
Wroclaw, DS, Poland · Remote
N/A
1h ago
Lead Azure AI Security Engineer
EPAM Systems
Senior
Technology
Poznan, WP, Poland · Remote
N/A
1h ago
Lead Azure AI Security Engineer
EPAM Systems
Senior
Technology
Gdansk, PM, Poland · Remote
N/A
1h ago
Lead Azure AI Security Engineer
EPAM Systems
Senior
Technology
Warsaw, MZ, Poland · Remote
N/A
1h ago