Unlock Full Resume Report

New offer - be the first one to apply!

September 21, 2026

Lead AI Security Engineer

Senior • Remote

Krakow, MA, Poland

Quick Facts

  • Role: Lead AI Security Engineer
  • Focus: Embed application security across the SDLC and secure AI/LLM-powered applications

Description

Lead end-to-end application security for AI- and LLM-powered products by embedding AppSec into design, code, build, and release, operating security tooling and CI/CD security gates, and driving remediation. Perform threat modeling, secure architecture reviews, and secure code reviews (manual and AI-assisted). Build AI-assisted automations for AppSec workflows (triage, deduplication, enrichment, remediation drafting) and implement AI security controls such as prompt security, guardrails, governance, and defenses aligned to OWASP Top 10 for LLM Applications.

Responsibilities

  • Shift-left and secure-by-design across engineering teams
  • Threat modeling and architecture security reviews; secure code review and guidance
  • Configure and run AppSec tooling (SAST, DAST, IAST, SCA, secrets and IaC scanning) in CI/CD
  • Triage, validate, and reduce false positives; track findings through remediation
  • Define and enforce security gates and policies in CI/CD
  • Secure the software supply chain (dependency/open-source risk, SBOM, signing, pipeline hardening)
  • Support penetration testing and validate fixes
  • Implement security practices for secrets, configuration, API, containers/images, and microservices
  • Run a security champions program and deliver secure-coding training and reusable patterns
  • Maintain AppSec standards/baselines and policy-as-code for risk and vulnerability management
  • Build and integrate AI-assisted automations and agentic workflows into SDLC/CI/CD
  • Connect LLM agents to scanners, code hosts, ticketing, and security tooling via function calling, REST, and webhooks
  • Use RAG so answers rely on current internal standards/remediation guidance
  • Add evaluation/validation and human-in-the-loop approval checkpoints with guardrails
  • Implement security/privacy controls for AI usage (least privilege, secrets handling, prompt-injection resistance, auditability)
  • Design controls for AI/LLM features (input/output validation, jailbreak and prompt-injection defenses, tool authorization, rate limiting, model/data governance)

Requirements

  • Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent practical experience
  • Hands-on application security experience across the software development lifecycle
  • Strong understanding of application vulnerabilities and mitigations (OWASP Top 10) and secure coding principles
  • Practical experience with SAST, DAST, SCA, and secrets scanning integrated into CI/CD
  • Working knowledge of at least one programming language (e.g., Python, Java, C#, JavaScript/TypeScript, Go)
  • Experience with threat modeling and secure design review methodologies
  • Understanding of DevOps/DevSecOps, CI/CD pipelines, and secure-by-design
  • Familiarity with cloud application security on at least one major cloud (Azure/AWS/GCP)
  • Experience participating in production projects/engineering teams
  • Ability to influence across development, architecture, QA, DevOps, product, and security teams
  • Ability to follow, maintain, and improve security processes
  • Practical understanding of AI-assisted automation/agents and integrating LLMs with tools/APIs/workflows, including prompt engineering and safe handling of sensitive data
  • Strong communication skills for explaining risks and remediation to technical and non-technical stakeholders

Benefits

  • Stable pay
  • Employee Stock Purchase Plan (15% discount)
  • Health insurance and multisport; shopping vouchers
  • Referral bonuses up to $2,000
  • Hybrid work with remote opportunities within Poland; chance to work abroad up to 60 days annually
  • Business-driven relocation opportunities
  • Career development programs and mentoring; soft skills and well-being programs
  • Certification support (Anthropic, Gemini, GCP, Azure, AWS)
  • English classes
  • Office amenities and corporate social/well-being events

Additional Notes

Contractor (B2B) collaboration is possible; terms are agreed individually.

Similar jobs you might like