Unlock Full Resume Report

New offer - be the first one to apply!

September 21, 2026

Lead AI Security Engineer

Senior • Remote

Katowice, SL, Poland

Description

Lead the security of AI- and LLM-powered applications across the full development lifecycle by embedding secure-by-design practices, running threat modeling and security reviews, and conducting secure code reviews. Operate application security tooling integrated into CI/CD, drive remediation and supply-chain risk reduction, and secure secrets, configurations, APIs, and containers. Build AI-assisted automations for AppSec workflows and implement guardrails for AI/LLM features aligned to OWASP Top 10 for LLM Applications.

Responsibilities

  • Embed security into the full SDLC; drive shift-left and secure-by-design across engineering teams
  • Facilitate threat modeling, architecture security reviews, and design reviews for applications, services, and APIs
  • Perform secure code reviews (manual and AI-assisted) and advise developers on secure coding patterns and remediation
  • Implement, configure, tune, and operate AppSec tooling (SAST, DAST, IAST, SCA, secrets scanning, IaC scanning) integrated into CI/CD pipelines
  • Triage, validate, prioritize findings, and reduce false positives; partner with development teams through remediation
  • Define and maintain CI/CD security gates and policies that balance risk reduction with developer velocity
  • Secure the software supply chain: dependency/open-source risk management, SBOM generation, artifact integrity and signing, build pipeline hardening
  • Support and coordinate application penetration testing and validate vulnerability fixes
  • Drive secrets management, secure configuration, API security, container/image security, and microservice security practices
  • Run a security champions program and deliver secure-coding training, guidelines, and reusable security patterns
  • Maintain application security standards, baselines, and policy-as-code; contribute to vulnerability management and risk-acceptance processes
  • Build and operate AI-assisted automations/agentic workflows for AppSec (triage, deduplication, prioritization, false-positive reduction, assisted code review, threat modeling support, enrichment/root-cause, remediation PR drafting, compliance evidence, documentation/runbooks)
  • Integrate AI agents and LLM-backed automations into SDLC/CI/CD; connect models to scanners, code hosts, ticketing, and security tooling via function calling, REST, and webhooks
  • Develop prompts and structured-prompting patterns; tune for accuracy, signal quality, and safe behavior
  • Implement retrieval over codebases/standards/remediation guidance (e.g., RAG) to ensure answers rely on authoritative internal context
  • Add evaluation, validation, and human-in-the-loop checkpoints (guardrails and approval gates before actions)
  • Implement security and privacy controls for AppSec AI usage (least privilege, secure handling of source code and secrets, prompt-injection resistance, auditability)
  • Design AI/LLM security controls aligned to OWASP Top 10 for LLM Applications (input/output validation, jailbreak defenses, tool authorization, rate limiting, model/data governance)
  • Define and enforce guardrails for secure AI adoption and advise product engineering teams

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or equivalent practical experience
  • Hands-on application security experience across the software development lifecycle
  • Strong understanding of application vulnerability classes and mitigations, including OWASP Top 10
  • Practical experience with SAST, DAST, SCA, and secrets scanning; integrate into CI/CD
  • Working knowledge of at least one programming language (e.g., Python, Java, C#, JavaScript/TypeScript, or Go)
  • Experience with threat modeling and secure design review methodologies
  • Understanding of DevOps/DevSecOps practices, CI/CD pipelines, and secure-by-design principles
  • Familiarity with cloud application security on at least one of Azure, AWS, or GCP
  • Ability to work closely with and influence developers, architects, QA, DevOps, product, and security teams
  • Ability to follow, maintain, and improve defined security processes
  • Practical understanding of AI-assisted productivity and automation beyond basic chatbot usage (AI agents, LLM integrations, prompt engineering, secure AI tool usage)
  • Strong communication skills across technical and non-technical stakeholders

Benefits

  • Hybrid by design with opportunity to work remotely within Poland
  • Chance to work abroad for up to 60 days annually; business-driven relocation opportunities
  • Stable pay; Employee Stock Purchase Plan with 15% discount
  • Comprehensive benefits package (health insurance, multisport, shopping vouchers)
  • Referral bonuses up to $2,000
  • Career development programs, mentoring, soft skills and well-being programs
  • Certification support (Anthropic, Gemini, GCP, Azure, AWS) and English classes
  • Corporate social and well-being events; office amenities (entertainment zones, free snacks, coffee, and recreation)

Benefits apply to employees; contractors are also considered under individually agreed B2B terms.

Similar jobs you might like