Jobgether
Senior Product Security Engineer
- Compensation
- £90K–£122K / yr
- From job posting
- Location
- US
- Arrangement
- Remote
- Employment type
- Full-time
- Level
- Senior
- Posted
- 24 September 2026 (6 days ago)
Checked 6 days agoApplications go to the employer, never to RoleSprint
About this role
Accountabilities: • Architect and implement security controls for AI/ML systems, including model training, data pipelines, inference environments, and agentic workflows.
• Identify and mitigate AI-specific threats such as prompt injection, data poisoning, model inversion, and model theft.
• Establish controls for model provenance, integrity, auditability, and responsible AI security practices.
• Align AI security initiatives with governance and compliance frameworks such as NIST AI RMF and the EU AI Act.
• Embed security, privacy, and compliance requirements into application, cloud, software, and AI development lifecycles.
• Define and maintain secure development standards, architectural guidance, and security best practices.
• Lead threat modeling, secure design reviews, and risk assessments across the software development lifecycle.
• Build security automation and governance capabilities that integrate naturally into engineering workflows.
• Prepare customer-facing security assurance materials, including questionnaire responses, security whitepapers, and trust documentation.
• Represent product security in customer, leadership, and cross-functional discussions, helping communicate security requirements and risk decisions.
• Mentor engineering teams on secure coding, AI risk management, threat modeling, and secure design.
• Promote a security-first culture through documentation, training, advocacy, and continuous improvement.
Requirements
• 5–7+ years of experience in product, application, or cloud security engineering.
• Strong knowledge of secure SDLC practices, threat modeling, and secure architecture design.
• Ability to read and review code to support security assessments, threat models, and architectural reviews.
• Experience securing AI/ML pipelines, data workflows, and model-serving infrastructure, with practical knowledge of LLM and AI security risks such as prompt injection, model integrity, and provenance.
• Strong understanding of cloud security principles and best practices across multi-cloud environments.
• Familiarity with DevSecOps practices and CI/CD environments.
• Knowledge of encryption fundamentals, including symmetric and asymmetric cryptography, TLS/mTLS, key management, and secrets handling.
• Understanding of modern authentication and authorization patterns, including OAuth 2.0, OIDC, SAML, RBAC, and ABAC.
• Demonstrated ability to lead cross-functional security initiatives and collaborate with engineering, product, and compliance teams.
• Strong communication, stakeholder management, analytical thinking, and influencing skills.
• Experience with Python, Java, and/or JavaScript for security automation and tooling is an advantage.
• Experience with Kubernetes and container security, software supply chain security, artifact integrity, or bug bounty programs is a plus.
• Familiarity with security and compliance frameworks such as SOC 2, ISO 27001, NIST 800-53, and NIST AI RMF is desirable.
• Certifications such as CKS, CISSP, CSSLP, or AI/ML security credentials are considered a plus.
Benefits
• Base compensation range of £90,000–£122,000 GBP.
• Potential performance-based bonus and equity.
• Generous benefits program.
• Opportunity to work on advanced AI/ML security, cloud security, secure architecture, and product security challenges.
• Ability to shape and influence product security strategy and security-by-design practices.
• Collaboration with engineering, architecture, product, compliance, and customer-facing teams.
• Opportunities to mentor teams and contribute to security culture, standards, and training.
• Career growth within a fast-moving technology environment.
• Commitment to an inclusive workplace and reasonable accommodations for qualified employees with disabilities.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Work location
- US
Related jobs
Ready to make a decision?
This role is either worth your time or it isn’t.
Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.
Nothing is submitted automatically. You choose what happens next.
About this listing
Published on Lever under the board identifier Jobgether, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.
RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.
Published 24 September 2026, last checked 6 days ago. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.