Unlock Full Resume Report

New offer - be the first one to apply!

September 21, 2026

Lead AI Security Engineer

Senior • Remote

Poznań, Pl-30, Poland

Quick Facts

  • Role: Lead AI Security Engineer
  • Focus: Application security across the full SDLC plus security for AI/LLM-powered applications

Description

Lead efforts to embed security into design, code, build, and release, driving shift-left and secure-by-design practices across engineering teams. Operate and improve AppSec tooling and pipelines, partner on remediation and penetration testing, and implement CI/CD security gates and software supply-chain protections. Build AI-assisted, agentic automations with guardrails to accelerate AppSec activities such as triage, deduplication, prioritization, enriched analysis, and secure code review.

Responsibilities

  • Embed security into the full software development lifecycle and drive shift-left/secure-by-design
  • Facilitate threat modeling, architecture security reviews, and design reviews for applications, services, and APIs
  • Perform secure code reviews (manual and AI-assisted) and advise developers on secure coding patterns and remediation
  • Implement and operate AppSec tooling in CI/CD: SAST, DAST, IAST, SCA, secrets scanning, IaC scanning
  • Triage, validate, prioritize findings, reduce false positives, and track issues through remediation
  • Define and maintain CI/CD security gates and policies that balance risk reduction with developer velocity
  • Secure the software supply chain: dependency/open-source risk management, SBOM generation, artifact integrity and signing, build pipeline hardening
  • Coordinate application penetration testing and validate fixes
  • Drive secure practices for secrets management, secure configuration, API security, container/image security, and microservice security
  • Establish a security champions program and deliver secure-coding training, guidelines, and reusable patterns
  • Define and maintain application security standards/baselines and policy-as-code; contribute to vulnerability management and risk-acceptance processes
  • Build and maintain AI-assisted automations and agentic workflows for AppSec triage, assisted code review, threat modeling support, enrichment, root-cause analysis, remediation-PR drafting, and compliance evidence collection
  • Integrate AI agents/LLM-backed automations into SDLC/CI/CD via function calling, REST, and webhooks
  • Develop and tune reusable prompts, structured prompting patterns, and templates for recurring AppSec tasks
  • Use retrieval over codebases and internal standards (e.g., RAG) for authoritative AI answers
  • Add evaluation/validation and human-in-the-loop checkpoints, including guardrails and approval gates
  • Implement AI usage security/privacy controls: least-privilege agent access, secure code/secrets handling, prompt-injection resistance, and auditability
  • Design and enforce AI/LLM feature security controls aligned with OWASP Top 10 for LLM Applications (validation, prompt-injection/jailbreak defenses, tool/function authorization, rate limiting, governance)
  • Enforce guardrails for secure AI adoption in product engineering and advise teams on building AI features securely

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or equivalent practical experience
  • Hands-on application security experience across the software development lifecycle
  • Strong understanding of application vulnerability classes and mitigations (OWASP Top 10) and secure coding principles
  • Practical experience with SAST/DAST/SCA/secrets scanning and CI/CD integration
  • Working knowledge of at least one programming language (to read code and assess vulnerabilities)
  • Experience with threat modeling and secure design review methodologies
  • Understanding of DevOps/DevSecOps practices, CI/CD pipelines, and secure-by-design
  • Familiarity with cloud application security on AWS, Azure, or GCP
  • Experience collaborating with multiple production engineering teams
  • Ability to influence without owning the codebase
  • Ability to follow, maintain, and improve defined security processes
  • Practical understanding of AI-assisted automation beyond basic chatbots (agents, LLM/tool integrations, prompt engineering, secure AI usage)
  • Strong communication skills for technical and non-technical stakeholders

Benefits

  • Hybrid work model with the ability to work remotely within Poland
  • Opportunity to work abroad for up to 60 days annually
  • Business-driven relocation opportunities
  • Career development programs and mentoring
  • Certification support (e.g., Anthropic, Gemini, GCP, Azure, AWS)
  • English classes
  • Stable pay and Employee Stock Purchase Plan with a 15% discount
  • Benefits package (health insurance, multisport, shopping vouchers)
  • Referral bonuses up to $2,000

Similar jobs you might like