Unlock Full Resume Report

New offer - be the first one to apply!

September 21, 2026

Lead AI Security Engineer

Senior • Remote

Lodz, Ldz, Poland

Quick Facts

  • Focus: shift-left, secure-by-design application security and AI/LLM security
  • Scope: SDLC security, AppSec tooling pipelines, AI-assisted automation, and AI guardrails

Description

Lead AI Security Engineer role focused on embedding security into the full SDLC and CI/CD pipeline, including threat modeling, secure code review, and security tooling (SAST/DAST/SCA/secrets/IaC scanning). You will also secure AI- and LLM-powered applications by building AI-assisted AppSec automations and enforcing guardrails for prompt security, tool/function authorization, and governance aligned to OWASP Top 10 for LLM Applications.

Responsibilities

  • Embed security across design, code, build, and release; drive shift-left and secure-by-design practices across engineering teams
  • Perform and facilitate threat modeling, architecture security reviews, and design reviews for applications, services, and APIs
  • Conduct secure code reviews (manual and AI-assisted) and advise developers on secure coding patterns and remediation
  • Implement, configure, tune, and operate application security tooling, integrated into CI/CD pipelines (SAST, DAST, IAST, SCA, secrets scanning, IaC scanning)
  • Triage and validate findings, reduce false positives, and partner with development teams to track issues through to remediation
  • Define and maintain security gates and policies in CI/CD pipelines balancing risk reduction with developer velocity
  • Secure the software supply chain: dependency/open-source risk management, SBOM generation, artifact integrity and signing, and build pipeline hardening
  • Support application penetration testing and validate fixes for identified vulnerabilities
  • Drive secrets management, secure configuration, API security, container and image security, and microservice security practices
  • Establish a security champions program; develop and deliver secure-coding training, guidelines, and reusable security patterns
  • Define and maintain application security standards/baselines and policy-as-code; contribute to vulnerability management and risk-acceptance processes
  • Build and maintain AI-assisted automations and agentic workflows for AppSec (triage, deduplication, prioritization, false-positive reduction, AI-assisted code review with remediation guidance, threat modeling support, enrichment/root-cause analysis, remediation-PR drafting, compliance evidence collection, secure-coding documentation/runbook automation)
  • Integrate AI agents and LLM-backed automations into SDLC/CI/CD pipelines via function calling, REST, and webhooks (connecting models to scanners, code hosts, ticketing, and security tooling)
  • Develop prompts and structured-prompting patterns/templates; tune for accuracy, signal quality, and safe behavior
  • Implement retrieval over codebases/standards/remediation guidance (e.g., RAG) so assistants use current authoritative internal context
  • Add evaluation, validation, and human-in-the-loop checkpoints with guardrails and approval gates before acting on findings/fixes/pipeline decisions
  • Implement security and privacy controls for AppSec AI usage (least-privilege agent access, source-code/secrets handling, prompt-injection resistance, auditability of actions)
  • Design and operate security controls for AI/LLM application features (input/output validation, prompt-injection/jailbreak defenses, tool/function-call authorization, rate limiting, model/data access governance) aligned to OWASP Top 10 for LLM Applications
  • Define and enforce AI adoption guardrails for secure product engineering; advise development teams on building AI features securely

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or equivalent practical experience
  • Hands-on application security experience across the software development lifecycle
  • Strong understanding of common application vulnerability classes and mitigations, including OWASP Top 10
  • Practical experience with application security tooling (SAST, DAST, SCA, secrets scanning) and integrating it into CI/CD
  • Working knowledge of at least one programming language (e.g., Python, Java, C#, JavaScript/TypeScript, Go) to read code and assess vulnerabilities
  • Experience with threat modeling and secure design review methodologies
  • Understanding of DevOps/DevSecOps practices, CI/CD pipelines, and secure-by-design principles
  • Familiarity with cloud application security on at least one major cloud platform (Azure, AWS, or GCP)
  • Experience participating in production projects or engineering teams
  • Ability to collaborate closely with developers, architects, QA engineers, DevOps, product, and security teams, and to influence without owning the codebase
  • Ability to follow, maintain, and improve defined security processes
  • Practical understanding of AI-assisted productivity/automation beyond chatbot usage (AI agents; LLM integrations; structured prompting; AI-assisted runbooks/scripts/queries/docs; secure AI usage with sensitive data awareness and access control)
  • Good communication skills to explain security risks, technical decisions, and remediation plans

Benefits

  • Stable pay; Employee Stock Purchase Plan with a 15% discount
  • Benefits package (health insurance, multisport, shopping vouchers)
  • Referral bonuses up to $2,000
  • Hybrid-by-design with opportunity to work remotely within Poland; chance to work abroad up to 60 days annually
  • Business-driven relocation opportunities
  • Career development programs, thought leadership, mentoring, soft skills and well-being programs
  • Certification support (Anthropic, Gemini, GCP, Azure, AWS) and English classes
  • Corporate, social and well-being events; office amenities (recreation zones, table tennis/football, free snacks and coffee)

Similar jobs you might like