Senior Product Security Engineer, AI – DevSecOps

🕒 September 23

🌪️ Kansas, Ohio, +1 more states – Remote

infoinfo

💵 $140.3k - $233.8k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of McKesson

McKesson

10,000+ employees

Founded 1833

💼 Consulting

📦 Logistics

🏥 Healthcare

Consulting • Logistics • Healthcare

McKesson is a diversified healthcare leader specializing in pharmaceutical distribution, medical supplies, and healthcare services. Their solutions facilitate patients' access to life-changing therapies, support efficient operations for pharmacies, health systems, and clinics, and address critical issues such as drug shortages through a resilient supply chain. McKesson provides comprehensive services such as pharmacy management software, consulting, and technology solutions for specialty practices, focusing on improving health outcomes and advancing the pharmaceutical industry. They work closely with biopharma companies to enhance medication access, adherence, and commercialization while supporting oncology and biopharma practices through data-driven insights and real-world evidence.

📋 Description

• Embed security throughout the software development lifecycle, focusing on AI-enabled products, cloud-native platforms, and DevSecOps practices • Partner with development teams across application design, development, testing, deployment, and operations • Conduct security architecture reviews, threat modeling, secure design reviews, and assessments of applications, APIs, cloud services, and AI-enabled systems • Write and review code to identify vulnerabilities, attack vectors, and opportunities to strengthen secure development practices • Develop reusable security patterns, shared services, and automated guardrails • Assess and secure AI, machine learning, generative AI, and large language model solutions, including AI-assisted development tools • Integrate automated security testing into CI/CD pipelines, including SAST, DAST, software composition analysis, secrets detection, container scanning, and infrastructure scanning • Design security controls for cloud-native applications, containers, Kubernetes, serverless platforms, and infrastructure-as-code deployments • Partner with engineering and cybersecurity teams to assess risk, remediate vulnerabilities, respond to security concerns, and promote a security-first engineering culture

🎯 Requirements

• Degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent professional experience • Typically requires 7 or more years of relevant experience in application security, product security, software development, security engineering, DevSecOps, or a related discipline • Hands-on experience writing, reviewing, and deploying application code using TypeScript, Java, Ruby, Python, or comparable languages • Strong understanding of application attack vectors, secure coding practices, software vulnerabilities, and modern application architectures • Experience conducting threat modeling, security architecture reviews, secure design reviews, and vulnerability remediation • Experience implementing DevSecOps practices and integrating automated security controls into CI/CD pipelines • Experience securing AI/ML platforms, generative AI solutions, large language model applications, or AI-assisted development workflows • Experience with cloud platforms, containers, Kubernetes, infrastructure-as-code, security automation, and application security testing tools • Knowledge of AI security frameworks and controls, including the OWASP Top 10 for LLM Applications and the NIST AI Risk Management Framework • Experience creating reusable security services, secure development patterns, engineering guardrails, or policy-as-code solutions • Experience with CI/CD and infrastructure technologies such as GitHub Actions, Azure DevOps, GitLab, Jenkins, or Terraform • Experience supporting frameworks such as SOC 2, HIPAA, SOX, NIST CSF, or ISO 27001 • Ability to translate complex security requirements and technical risks into practical guidance for development teams • Applicants must be currently authorized to work in the United States on a fulltime basis without the need for employer support or sponsorship now or in the future

🏖️ Benefits

• Competitive compensation package • Annual bonus or long-term incentive opportunities may be offered • Equal employment opportunities • Reasonable accommodation for job search or application

Apply Now

Similar Jobs

🕒 September 23

TD

10,000+ employees

🏦 Banking

💸 Finance

🛡️ Insurance

Information Security Specialist leading Fusion Incident Management for TD, a global financial institution. Developing security controls, assessing risk, and driving incidents through recovery and closure.

🇺🇸 United States – Remote

💵 $107.2k - $173.3k / year

💰 Grant on 2023-10

⏰ Full Time

🟠 Senior

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

infoinfo

🕒 September 22

Censys

51 - 200

🔒 Cybersecurity

🏢 Enterprise

Security Engineer owning cloud, identity, vulnerability, incident response, and AI security for Censys, which provides real-time Internet intelligence and threat insights. Building agentic automation and monitoring Censys’s external attack surface.

🕒 September 22

Templar Shield

51 - 200

💼 Consulting

🔒 Cybersecurity

📋 Compliance

Security Consulting Manager leading ServiceNow Security Operations and AI-enabled cybersecurity engagements for enterprise clients. Managing delivery, consulting teams, client outcomes, and practice growth at Templar Shield.

🕒 September 22

Guidehouse

10,000+ employees

🏥 Healthcare

🎖️ Defense

📦 Logistics

Information Security Systems Officer supporting NIST RMF, FISMA, and ATO activities for Guidehouse’s consulting services. Maintaining security documentation, controls, assessments, and remediation across authorization boundaries.

🇺🇸 United States – Remote

💵 $74k - $124k / year

💰 Grant on 2023-02

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

infoinfo

🕒 September 22

ATSG

501 - 1000

💼 Consulting

📦 Logistics

📣 Marketing

Security Manager overseeing XTIUM’s daily security operations, incident response, and vulnerability remediation. Coordinating SOC partners, audits, metrics, and operational security improvements.

🇺🇸 United States – Remote

💵 $100k - $130k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer