Staff Security Engineer, AI & Application Security

Job not on LinkedIn

🔥 1 minute ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Marcura

Marcura

501 - 1000 employees

Founded 2001

📦 Logistics

💼 Consulting

🚗 Transport

Logistics • Consulting • Transport

Marcura is a leading provider of maritime services, focusing on managing port operations and simplifying crew payments within the shipping industry. With a diverse team operating across 53 countries, Marcura delivers expertise in voyage management, port call efficiency, and compliance services. The company processes millions of port calls annually and has established itself as a crucial partner for over 950 shipping companies worldwide, offering solutions that enhance financial management and operational transparency.

📋 Description

• Security Strategy, Roadmap and Prioritisation: Define and maintain a prioritised security roadmap for Marcura in order to ensure that finite capacity in a single security headcount is spent on the highest material risk, by assessing the current posture, setting a small number of clear objectives per period, making explicit decisions on what is done in house versus deferred or delivered via external partners, and building the evidence based case for further investment. • Secure Architecture and Design Review: Review the architecture and design of new and changing systems in order to prevent security weaknesses being built in rather than discovered later, by embedding lightweight threat modelling into the delivery lifecycle, defining reusable secure design patterns, and giving teams timely, pragmatic decisions rather than blocking gates. • AI and LLM Security Advisory: Act as the group's trusted AI security advisor in order to enable fast, safe adoption of AI across the business, by engaging early in design, defining secure by design patterns for LLM, RAG and agentic systems, and giving teams clear, proportionate guidance rather than blanket restrictions. • AI Security Framework and Standards: Build and maintain a practical AI security framework and set of engineering standards in order to make secure AI deployment repeatable and auditable as the estate grows, by aligning to OWASP LLM Top 10, MITRE ATLAS and NIST AI RMF and translating them into concrete controls, checklists and acceptance criteria, and by maintaining a live inventory of deployed models and their controls. • Internal Penetration Testing Programme: Establish and personally run Marcura's internal penetration testing capability in order to provide continuous, in depth assurance between and beyond scheduled external tests, by defining scope, methodology, tooling, reporting standards and a prioritised testing calendar covering applications, APIs, cloud infrastructure and internal services. • External Penetration Test Ownership: Own and direct Marcura's independent external penetration testing in order to preserve genuine independence of assurance over systems the role holder has helped design, by setting scope and objectives, selecting and managing testing partners, ensuring internal and external coverage are complementary rather than duplicative, challenging the technical quality of findings, and integrating results into a single prioritised remediation backlog. • Hands On Offensive Testing and Red Teaming: Execute technical penetration tests and red team exercises against production and pre production systems in order to find exploitable weaknesses before adversaries do, by combining manual testing, custom tooling and automation, and proving impact through demonstrable exploitation rather than theoretical findings. • AI Red Teaming and Adversarial Testing: Design and run AI red team exercises against every material AI and LLM deployment in order to ensure AI features cannot be abused to leak data, bypass controls or take unauthorised action, by systematically testing for prompt injection, jailbreaks, guardrail bypass, data exfiltration, insecure output handling and unsafe tool or agent behaviour. • Application and Cloud Security Hardening: Improve the baseline security of Marcura's applications and cloud estate in order to reduce the attack surface systemically rather than fixing issues one at a time, by defining hardening standards and secure defaults, driving posture management and configuration baselines, and embedding automated security testing into CI/CD pipelines. • Identity, Access and Data Protection: Strengthen identity, access and data protection controls in order to limit the blast radius of any single compromise, by reviewing and improving authentication and authorisation design, least privilege and privileged access, secrets and key management, encryption, and data classification and tenancy boundaries. • MDR Partnership Ownership (eSentire): Own the technical relationship with Marcura's Managed Detection and Response partner, eSentire, in order to get maximum protective value from the service rather than treating it as outsourced responsibility, by ensuring the right telemetry and log sources are onboarded, validating and tuning detection coverage against Marcura's actual threat model, testing the service through purple team style exercises, holding the provider to account on quality and response times, and closing the gaps the service does not cover. • Detection Engineering and Incident Response: Strengthen Marcura's ability to detect and respond to attacks beyond commodity coverage in order to reduce the time between compromise and containment, by defining logging and telemetry requirements, engineering high signal detections for Marcura specific and AI specific attack patterns that an MDR provider will not have, maintaining incident response runbooks, and providing hands on technical leadership and escalation ownership during security incidents. • Vulnerability Management and Remediation Ownership: Own the end to end vulnerability lifecycle in order to achieve measurable risk reduction rather than a growing backlog of findings, by triaging and prioritising by business impact, agreeing remediation plans and timelines with engineering owners, verifying fixes through retesting, and escalating unresolved material risk to leadership. • Security Tooling and Automation: Build and operate tooling and automation for continuous security testing and monitoring in order to scale the impact of a single hands on engineer, by automating repeatable assurance work, integrating scanning and AI specific testing into pipelines, and reducing manual effort in recurring security tasks. • Third Party, Vendor and Model Assurance: Assess third party software, AI models, platforms and service providers in order to protect Marcura and customer data when using external providers, by reviewing data handling, retention, training use, privacy, residency and access controls, and issuing clear recommendations within group guardrails. • Engineering Enablement and Security Culture: Uplift the security capability of engineering, product and data teams in order to reduce the rate at which new vulnerabilities are introduced, by delivering hands on guidance, secure coding and AI security reviews, targeted workshops and internal champions rather than relying on policy alone. • Documentation, Metrics and Leadership Reporting: Maintain clear documentation and report on security and AI trust posture in order to give leadership an accurate, decision ready view of risk and to ensure the function is auditable and not dependent on a single individual, by documenting methodology, findings, accepted risks, the AI system inventory and approved patterns, and by maintaining a concise set of meaningful security metrics.

🎯 Requirements

• No specific degree or certification is required for this role. A degree in Computer Science, Information Security or Engineering is welcome but is not a filter, and neither is any particular certification. • What we are looking for instead is **evidence of having found real vulnerabilities in real systems**. Candidates should be able to walk us through bugs they personally discovered, how they found them, why they mattered, and what was done about them. Any of the following are strong, credible signals: • Vulnerabilities found in production systems during professional testing engagements, described in technical depth. • Published CVEs, coordinated disclosures, or security advisories. • Bug bounty findings with a track record on recognised platforms or private programmes. • Original security research, technical writeups, conference talks, or open source security tooling. • Strong competitive CTF results, particularly in web, cloud, or AI categories. • Novel prompt injection, jailbreak or agent abuse findings against real LLM deployments. • Certifications such as OSCP, OSEP, OSWE, GXPN, CRTO, CISSP or cloud security specialties are a useful signal of structured knowledge and are welcome, but they are explicitly **not** a substitute for a demonstrable history of finding and proving real bugs, and their absence will not count against a candidate who can show that history. • 8+ years total experience in security engineering, spanning both offensive and defensive work rather than one exclusively. • At least 4 years hands on offensive experience: scoping, leading and personally executing penetration tests and red team exercises across web applications, APIs, cloud environments and internal networks. • Demonstrable defensive engineering experience: hardening cloud and application environments, building or tuning detections, and designing identity, access and data protection controls. • Proven experience assessing and securing LLM or AI systems in production, including prompt injection, jailbreaks, insecure output handling, data exfiltration and tool or agent abuse. • Experience as a first, sole or founding security hire, or otherwise building a security capability from a standing start with minimal supervision and constrained resources. • Track record of influencing architecture and design decisions across engineering and product teams, not only reporting findings. • Experience supporting or leading security incident response in a production environment. • Experience owning and getting value from an MDR or managed SOC provider — onboarding telemetry, validating and tuning detection coverage, and holding the provider to account — rather than only consuming its alerts. • Experience scoping, commissioning and challenging external penetration tests, and integrating third party findings into an internal remediation process. • Experience in a regulated B2B, fintech, maritime or logistics environment preferred.

🏖️ Benefits

• - **Competitive Salary and Bonus**: We reward your expertise and contributions. • - **Inclusive Onboarding Experience**: Our onboarding program is designed to set you up for success right from day one. • - **Marcura Wellness Zone**: We value your work-life balance and well-being. • - **Global Opportunities**: Be part of an ambitious, expanding company with a local touch. • - **Diverse, Supportive Work Culture**: We’re committed to inclusion, diversity, and a sense of belonging for all team members.

Apply Now

Similar Jobs

🔥 11 hours ago

ABB

10,000+ employees

💼 Consulting

📦 Logistics

🚗 Transport

Channel Applications Engineer providing technical sales execution for ABB's Low Voltage drives and products. Collaborating with customers and assisting Channel partners in tailored solutions and support.

🇺🇸 United States – Remote

💵 $100.5k - $160.8k / year

💰 $545.9M Post-IPO Debt - ABB on 2023-11

⏰ Full Time

🟠 Senior

🔴 Lead

💻 Application Engineer

🔥 12 hours ago

Onto Innovation

1001 - 5000

🏭 Manufacturing

Staff Application Engineer responsible for system qualification, process optimization, and customer engagement for semiconductor metrology solutions. Leading responsibilities in system matching, modeling, and data analysis while collaborating with customers and teams.

🔥 14 hours ago

Datadog

1001 - 5000

🔒 Cybersecurity

☁️ SaaS

🏢 Enterprise

Staff Application Security Engineer setting application security direction at Datadog. Define frameworks and methodologies for engineering teams and shape the AppSec roadmap.

🔥 22 hours ago

CINC Systems

201 - 500

☁️ SaaS

🏠 Real Estate

🤝 B2B

Senior Application Support Engineer designing automation systems for application support in CINC Systems. Collaborating across teams to improve operational efficiency and incident response capabilities.

🇺🇸 United States – Remote

💰 Private Equity Round - CINC Systems on 2023-12

⏰ Full Time

🔴 Lead

💻 Application Engineer

🔥 22 hours ago

HARMAN International

10,000+ employees

🚘 Automotive

🔧 Hardware

🤝 B2B

Principal Software Engineer developing high-performance desktop and mobile applications for HiFi audio enthusiasts across platforms. Leading a team and driving technical innovation in audio streaming solutions.