Unlock Full Resume Report

New offer - be the first one to apply!

September 21, 2026

Lead AI Security Engineer

Senior • Remote

Wrocław, Poland

Quick Facts

  • Role: Lead AI Security Engineer

  • Focus: Embed application security across the full SDLC, secure AI/LLM-powered applications, and build AI-assisted AppSec automations

Description

Lead security engineering for AI and LLM-enabled applications across design, coding, build, and release. You will run and improve application security tooling and CI/CD pipelines, drive threat modeling and secure design reviews, and partner with engineering on remediation. You will also build AI-assisted workflows with guardrails to accelerate vulnerability triage, secure code review, threat modeling support, and secure adoption of AI features.

Responsibilities

  • Drive secure-by-design and shift-left practices across engineering teams

  • Facilitate threat modeling and architecture/design security reviews for apps, services, and APIs

  • Perform secure code reviews (manual and AI-assisted) and guide secure coding patterns

  • Operate and tune AppSec tooling (SAST, DAST, IAST, SCA, secrets scanning, IaC scanning) integrated into CI/CD

  • Triage and validate findings, reduce false positives, and track issues through remediation

  • Define and maintain security gates and policies in CI/CD

  • Secure the software supply chain (dependency/open-source risk, SBOM, artifact integrity and signing, build pipeline hardening)

  • Coordinate and support application penetration testing and verify fixes

  • Cover secrets management, secure configuration, API security, container/image security, and microservice security practices

  • Establish security champions and deliver secure-coding training, guidelines, and reusable patterns

  • Define and maintain AppSec standards/baselines and vulnerability management/risk-acceptance inputs; apply policy-as-code

  • Build and maintain AI-assisted automations/agentic workflows for AppSec tasks (triage/dedup/prioritization, enriched findings, root-cause analysis, remediation-PR drafting, compliance evidence)

  • Integrate AI agents and LLM-backed automations into SDLC/CI/CD using function calling, REST, and webhooks

  • Develop reusable prompts/templates and tune for accuracy, signal quality, and safe behavior

  • Implement retrieval over internal codebases/standards/remediation guidance (e.g., RAG)

  • Add evaluation/validation and human-in-the-loop checkpoints with guardrails and approval gates

  • Implement AI security and privacy controls (least privilege for agents, safe handling of code/secrets, prompt-injection resistance, auditability)

  • Implement AI/LLM application feature security controls aligned to OWASP Top 10 for LLM Applications

  • Define and enforce guardrails for secure AI adoption (prompt security, model/tool access control, output handling, data protection, auditability, approvals)

  • Advise product and engineering teams on building AI features securely

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or equivalent practical experience

  • Hands-on application security experience across the software development lifecycle

  • Strong understanding of application vulnerability classes and mitigations (including OWASP Top 10) and secure coding principles

  • Practical experience with application security tooling (SAST, DAST, SCA, secrets scanning) and integrating into CI/CD

  • Working knowledge of at least one programming language (e.g., Python, Java, C#, JavaScript/TypeScript, or Go)

  • Experience with threat modeling and secure design review methodologies

  • Understanding of DevOps/DevSecOps, CI/CD pipelines, and secure-by-design

  • Familiarity with cloud application security across at least one major cloud platform (Azure, AWS, or GCP)

  • Experience across at least several production projects/engineering teams

  • Ability to collaborate closely and influence without owning the codebase

  • Ability to follow, maintain, and improve defined security processes

  • Practical understanding of AI-assisted productivity/automation (AI agents, LLM integrations with tools/APIs/workflows, structured prompting, AI runbooks/scripts/queries/docs, and secure use with sensitive data awareness)

  • Good communication skills for technical and non-technical stakeholders

Benefits

  • Hybrid work model with remote opportunity within Poland

  • Ability to work abroad up to 60 days annually

  • Business-driven relocation opportunities

  • Career development programs, mentoring, soft skills, and well-being programs

  • Certification support (Anthropic, Gemini, GCP, Azure, AWS)

  • English classes

  • Stable pay and Employee Stock Purchase Plan (15% discount)

  • Benefits package (health insurance, multisport, shopping vouchers)

  • Referral bonuses up to $2,000

  • Office amenities and social/well-being events

Contractor (B2B) options are available under individually agreed terms.

Similar jobs you might like