> Markdown version of [/jobs/ext/2267089-ai-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/2267089-ai-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # AI Product Security Engineer - **Company:** Forescout Technologies Inc. - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Burp Suite, C++ (Programming Language), Software as a Service, Cloud Computing, Cloud Computing Security, Computer Programming, Continuous Integration, Distributed Systems, Github, Identity and Access Management, Information Systems Security Architecture Professional, Python (Programming Language), Systems Development Life Cycle, Cloud Services, Secure Coding, Software Engineering, SonarQube, Systems Integration, TypeScript, Software Vulnerability Management, Large Language Models, Software Security, Veracode, Forescout, Kubernetes, Terraform, Devsecops, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 27, 2026 - **Apply:** https://jobs.jobvite.com/forescout/job/oXqDAfwk/apply ## About the Role * 5+ years of experience in: * Product Security * Application Security * Cloud Security * DevSecOps * Security Engineering Demonstrated experience securing enterprise-scale software products and cloud services. Experience integrating security into modern SDLC pipelines. Technical Skills * Threat modeling * Secure design reviews * Vulnerability assessment * Penetration testing * Secure coding practices * Incident response * Software supply chain security * Penetration Testing Security Tooling Experience with several of the following: * Snyk * Wiz * Burp Suite * Tenable * GitHub Advanced Security * Claude Security * OpenAI SCT * Open Source AI tooling / harnesses * Veracode * Semgrep * SonarQube Cloud & Infrastructure * Azure * AWS * Kubernetes * Containers * Infrastructure-as-Code (Terraform) * Identity and access management * API security Programming Strong proficiency in one or more: * Python * Java * Go * C/C++ * JavaScript/TypeScript AI-Specific Qualifications * Hands-on experience using AI/LLM technologies in engineering or security workflows. * Understanding of: * Prompt injection attacks * RAG security risks * AI model abuse * Data poisoning * Tool misuse * Agent security * AI governance controls Experience building or integrating AI-assisted automation solutions. Familiarity with AI coding agents, copilots, and autonomous security workflows., * CISSP, CSSLP, OSCP, GIAC, or equivalent certification. * Experience with AI red teaming and adversarial testing. * Experience building developer security platforms. * Experience securing SaaS products, APIs, and distributed systems. * Familiarity with enterprise-scale software delivery organizations. * Experience supporting FedRAMP or government cloud environments. ## Description The ideal candidate combines deep expertise in application security, cloud security, DevSecOps, and AI technologies. This position focuses on building security into the SDLC and working with engineering teams develop, deploy, and operate secure products at scale. You will act as a force multiplier across Product Management, Engineering, Platform Engineering, Cloud Operations, Compliance, and Security teams by embedding security directly into the software development lifecycle and leveraging AI to increase both security coverage and engineering velocity. AI-Powered Vulnerability Management for Secure SDLC * Partner with Architects to define secure architecture patterns for Development, and Operate Product Security systems * Build AI-driven solutions into CI/CD to accelerate * + Vulnerability discovery + Triage and prioritization + Root cause analysis + Remediation recommendations + Validation testing + Penetration testing + Security documentation * Develop exploitability-aware prioritization models using business context, reachability, threat intelligence, and customer impact. * Reduce false positives and improve signal-to-noise ratios across Development tooling. * Implement automated workflows for CVE, KEV, SBOM, SAST, DAST, Dependency Management, EoL and SCA findings. Product Security Operations * Conduct threat modeling, design reviews, security assessments, and architecture reviews. * Partner with development teams to identify and remediate security weaknesses. * Participate in vulnerability response and incident response activities. * Work with engineering teams to reduce critical vulnerability exposure and accelerate remediation timelines. * Develop dashboards and metrics that measure risk reduction, security maturity, and remediation performance. Compliance & Regulatory Support * Ensure security controls remain updated and align with customer, certification, and government requirements, ex., At Forescout, we are "Cyber Obsessed". We are committed to maintaining a secure environment for our customers, employees, and business operations. To support these efforts, candidates may be asked to complete job-related pre-employment screening and verification processes, to the extent permitted by applicable law. Depending on the role and location, these measures may include identity verification, employment verification, background screening, work authorization verification, and other lawful security-related checks. Forescout conducts these processes in accordance with applicable laws and regulations, including privacy and data protection requirements, and obtains any required notices, authorizations, or consent before conducting such screenings. Notice Regarding the Use of Artificial Intelligence in Recruitment As part of our recruitment process, we may use artificial intelligence ("AI") or automated decision-support tools to assist with reviewing applications, assessing job-related qualifications, matching candidates to role requirements, scheduling interviews, and supporting candidate evaluation. These tools are designed to assist our recruiters and hiring managers and are not the sole basis for hiring decisions. Qualified personnel review relevant candidate information and exercise human judgment throughout the recruitment process. We are committed to the responsible use of AI and seek to deploy and use AI-enabled recruiting tools in accordance with applicable laws, regulations, and our internal governance standards. NOTE TO EMPLOYMENT AGENCIES: We value the partnerships we have built with our preferred vendors. Forescout does not accept unsolicited resumes from employment agencies. ## Related Videos - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [From Prototype to Production: Build AI Agents with This Free 4-Course Learning Path](https://www.wearedevelopers.com/magazine/655-from-prototype-to-production-build-ai-agents-with-this-free-4-course-learning-path) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere)