← Todas as vagas

Senior Product Security Engineer

Sobre a vaga

• Lead the design and implementation of secure, scalable, and trustworthy products across AlphaSense’s AI-native platform
• Work with architects, engineering, and product teams to embed security by design throughout the software development lifecycle
• Architect and enforce security controls for AI/ML systems, including model training, data pipelines, inference environments, and agentic workflows
• Identify and mitigate AI-specific attack vectors such as prompt injection, data poisoning, model inversion, and model theft
• Implement model provenance, integrity, and auditability controls
• Align AI security with governance and compliance teams against frameworks such as NIST AI RMF and the EU AI Act
• Define and maintain secure development standards, guidance, and best practices
• Lead threat modeling, secure design reviews, and risk assessments
• Build and maintain security automation and governance integrated into development workflows
• Produce customer-facing security assurance, including questionnaire responses, security whitepapers, and trust collateral
• Represent product security in customer, cross-functional, and leadership discussions
• Mentor teams on secure coding, AI risk management, and secure design
• Promote a security-first culture through advocacy, documentation, and training

• 5–7+ years in product, application, or cloud security engineering
• Deep understanding of secure SDLC, threat modeling, and secure architecture design
• Ability to read and review code to inform threat models and design reviews
• Experience securing AI/ML pipelines, data workflows, and model-serving infrastructure
• Working knowledge of AI/LLM security, including prompt injection, model integrity, and provenance
• Proven expertise with cloud security concepts and best practices across multi-cloud environments
• Familiarity with DevSecOps and CI/CD environments
• Familiarity with encryption fundamentals, including symmetric and asymmetric cryptography, TLS/mTLS, key management, and secrets handling
• Understanding of OAuth 2.0, OIDC, SAML, RBAC, and ABAC
• Ability to drive cross-functional security initiatives with engineering, product, and compliance teams
• Proficiency in Python, Java, and/or JavaScript for security automation and tooling (nice to have)
• Container and orchestration security, including Kubernetes runtime protection (nice to have)
• Software supply chain security and artifact integrity verification (nice to have)
• Experience with bug bounty programs (nice to have)
• Familiarity with SOC 2, ISO 27001, NIST 800-53, and NIST AI RMF (nice to have)
• Certifications such as CKS, CISSP, CSSLP, or AI/ML security credentials (nice to have)

• Performance-based bonus
• Equity
• Generous benefits program
• Competitive compensation
• Career growth opportunities
• Equal-opportunity employment
• Reasonable accommodation for qualified employees with protected disabilities