Application & AI Cyber Security Engineer
Own the security posture of hosted applications, container platforms, and AI environments by building automated guardrails and real-time visibility. The role combines application security, container security, and AI security, with responsibility for technical controls, observability, governance, and secure enablement of AI-assisted development.
Responsibilities
- Design and deploy automated controls for container platforms and application deployments, including admission controllers, policy-as-code, and pre-configured scanning.
- Enable citizen development by making AI coding tools usable without requiring manual security review.
- Curate internal security tooling, automation, and AI skills for cost, reliability, and security posture.
- Own container security standards including image scanning policy, runtime baselines, and registry governance.
- Manage software supply chain risk through dependency scanning and composition analysis.
- Build application security observability and actionable dashboards for engineering leadership and the CISO function.
- Own AI platform security configuration, including hardening, access controls, data flow governance, and defenses against prompt injection and data exfiltration.
- Assess MCP connector risk and evaluate new AI tools for security approval decisions.
- Define behavioral baselines for agentic execution environments and address AI-specific insider threat gaps.
- Collaborate with detection, identity, and cloud security engineers on telemetry, workload access, service identity, and secrets management.
Requirements
- Hands-on container security experience with Kubernetes, image scanning, admission control, runtime protection, and policy-as-code.
- Experience building automated security controls that scale.
- Application security fundamentals including OWASP Top 10, secure development lifecycle, and software supply chain risk.
- Experience building security visibility through instrumentation, runtime analysis, or operational dashboards.
- Active use of AI-assisted development tools such as Claude Code or GitHub Copilot.
- Early or growing experience in AI and LLM security, including prompt injection, data exfiltration, model API security, or agentic system controls.
- Ability to communicate complex technical findings clearly to senior stakeholders.
- Nice-to-have experience with security tools, MCP, agentic frameworks, AI platform administration, financial services, security-control cost optimization, or local open-source LLMs.
Benefits
- Paid time off
- Parental leave
- Wellbeing and wellness support
- Flexible working arrangements
- Learning and development opportunities