Product Security Engineer, AI Applications

Insight Global
Naperville, IL, United States
4 days ago
Apply on www.techcareers.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Software System Penetration Testing Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Continuous Integration
+49 more
Data Integration Data Integrity Software Design Patterns Github Infrastructure as a Service (IaaS) Identity and Access Management Intrusion Detection Systems Mobile Application Software OSI Models Information Systems Security Architecture Professional Python (Programming Language) Key Management Network Security Log Analysis Machine Learning Network Segmentation OAuth OpenID Open Web Application Security Platform as a Service (PAAS) Proprietary Software Cloud Services Tensorflow Secure Coding Shell Script Security Information and Event Management Single Sign-On Software Engineering Data Streaming TCP/IP Software Vulnerability Management Data Logging Google Cloud Cloud Platform System Pytorch Retrieval-Augmented Generation Large Language Models Software Security Generative AI Cyber Threat Analysis Firewalls (Computer Science) Information Technology Data Lineage Data Pipelines Devsecops Service Stack Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

Insight Global has a unique opportunity for a Product Security Engineer, AI Applications to join a leading staffing, consulting, and managed services organization in a role that allows for a direct impact on securing innovative digital solutions and AI-enabled technologies that support clients across a wide range of industries.

The Product Security Engineer, AI Applications will serve as a technical member of the Product Security Team and support highly technical security reviews across the organization’s digital product portfolio. This role reviews the full product lifecycle and technology stack, including AI-enabled applications, web and mobile applications, APIs, cloud IaaS/PaaS architectures, SaaS platforms, IoT-connected solutions, data integrations, third-party software, and customer-facing product components.

The Product Security Engineer, AI Applications will combine application/product security expertise with AI-specific security skills to perform risk assessments, threat modeling, secure architecture reviews, application security testing, secure code/dependency review, and SSDLC standards development. The role will evaluate AI risks such as prompt injection, adversarial ML, data/model leakage, model theft, data integrity, bias-related risk indicators, AI supply chain exposure, and secure use of copilots, agents, plugins, and automation workflows.

What You’ll Do:

  • Support and perform product security risk assessments across the organization’s digital products and client-facing technology solutions, including AI-enabled applications, web/mobile applications, APIs, SaaS platforms, cloud services, containers, IoT solutions, endpoints, network-connected components, and third-party software.
  • Develop, maintain, and support SSDLC standards, secure design patterns, application security requirements, AI security requirements, and product security procedures aligned to practical engineering workflows.
  • Perform hands-on threat modeling for applications, APIs, cloud architectures, data flows, AI/ML integrations, LLM-enabled features, copilots, agents, automation workflows, and external service integrations.
  • Assess AI/ML models and AI-enabled workflows for vulnerabilities, adversarial ML risks, evasion, poisoning, model extraction/theft, prompt injection, insecure output handling, data/model leakage, data integrity weaknesses, bias-related risk indicators, and control effectiveness.
  • Evaluate AI governance, ethical use, privacy, data lineage, training/evaluation dataset controls, production monitoring, vendor/model risk, and secure AI data pipeline practices in partnership with product, privacy, risk, and compliance teams.
  • Conduct technical security reviews using SAST, SCA, SBOM, DAST, secrets scanning, API security, container security, cloud security posture, vulnerability management, and AI security evaluation tools.
  • Use and help operationalize platforms such as Snyk, Wiz, GitHub Advanced Security, DAST tooling, threat modeling tools, SBOM/SCA tooling, CI/CD security tooling, native Azure/AWS security services, SIEM/log analysis tools such as Elastic, and AI security evaluation tools.
  • Partner with software engineering and DevSecOps teams to integrate security controls, test gates, evidence collection, automated response workflows, and remediation tracking into CI/CD pipelines and product release processes.
  • Review identity, access, and secure communication architectures, including IAM, OAuth 2.0, OIDC, SSO, B2C/B2B identity patterns, service principals, workload identities, Azure Managed Identity, privileged access, encryption, secure APIs, secrets management, logging/monitoring, and service-to-service communication.
  • Analyze application, cloud, API, container, endpoint, and AI security telemetry to support threat detection, anomalous behavior investigation, incident triage, containment support, product risk decisions, and prioritized remediation plans.
  • Translate technical findings into concise remediation guidance, risk inputs, standards updates, metrics, and stakeholder-ready summaries for product, engineering, security, customer-facing, risk, and compliance stakeholders.
  • Support customer-facing cybersecurity discussions, questionnaires, audits, and technical documentation related to the organization’s product security program, AI security controls, product architecture, and SSDLC practices.
  • Stay current on application security, AI security, adversarial ML, cloud security, DevSecOps, vulnerability management, secure coding, threat intelligence, and relevant frameworks and standards including NIST, OWASP, CIS, ISO 27001, SOC 2, and ISO/IEC 5338.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global’s Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Requirements

Bachelor’s Degree in Cybersecurity, Computer Science, Software Engineering, IT Technology, or related technology-driven field.

  • 5+ years of hands-on experience in cybersecurity, application security, product security, software engineering, cloud security, or related technology roles.

  • 5+ years of hands-on experience as a software developer, senior developer, application security engineer, product security engineer, or similar technical role supporting modern application architectures.

  • 3+ years of experience performing application security assessments, secure architecture reviews, threat modeling, vulnerability assessments, penetration test coordination, or technical product security reviews.

  • Hands-on experience with SSDLC, DevSecOps, SAST, DAST, SCA, SBOM, API security, container security, secrets scanning, secure CI/CD pipeline controls, and remediation workflows.

  • Hands-on experience with Microsoft Azure and AWS cloud security, including native cloud security services, IaaS/PaaS security patterns, cloud posture management, and secure workload configuration.

  • Strong understanding of IAM across Azure and AWS, including OAuth 2.0, OIDC, SSO, B2C/B2B identity patterns, service principals, workload identities, Azure Managed Identity, and privileged access patterns.

  • Hands-on scripting and automation experience with Python and shell scripting for security testing, data/log analysis, automation, and security tool integration.

  • Experience assessing AI/ML or generative AI-enabled capabilities, including LLM integrations, prompt injection, data/model leakage, model abuse, model extraction/theft, vendor/model risk, AI threat modeling, and secure AI design patterns.

  • Understanding of adversarial machine learning concepts, including evasion, poisoning, insecure model inputs/outputs, model extraction, model leakage, and abuse of AI agents, tools, or plugins.

  • Working knowledge of network security fundamentals, including TCP/IP, OSI model, firewalls, IDS/IPS, network segmentation, web/application protocols, and secure service-to-service communication.

  • Knowledge of identity and access management, encryption, secure API design, secrets management, secure SDLC practices, vulnerability management, logging/monitoring, privacy/security-by-design, and cloud security architecture.

  • Demonstrated ability to identify, explain, prioritize, and drive remediation of complex application, cloud, AI, identity, and product security risks with engineering and product teams.

  • Demonstrate strong interpersonal communications, analytical, problem solving, organizational, and written/verbal communication skills.

  • Ability to accommodate a flexible work schedule for supporting global product teams and activities. - One or more relevant security certifications preferred, such as CISSP, CSSLP, CCSP, cloud security certification, AWS/Azure security certification, AI governance/responsible AI training, or secure software/coding certification.

  • Experience developing or implementing SSDLC standards, secure coding standards, application security design patterns, AI security requirements, risk assessment methodologies, or product security governance processes.

  • Familiarity with ML frameworks such as TensorFlow, PyTorch, or similar libraries.

  • Experience with AI integrations and architecture, including generative AI, LLM-enabled applications, copilots, agents, retrieval-augmented generation, AI data pipelines, training/evaluation datasets, or AI-enabled automation workflows.

  • Familiarity with AI governance, responsible AI, ethical AI use, production monitoring expectations, and AI lifecycle standards such as ISO/IEC 5338.

  • Experience supporting incident response triage, containment, and integration with automated response or security orchestration tools.

  • Experience with Google Cloud security and Google Cloud IAM.

  • Experience supporting complex technical projects, remediation initiatives, standards adoption, security tooling implementation, or product security maturity improvement programs.

  • Experience working with global product, software engineering, DevSecOps, cloud architecture, legal/privacy, risk, compliance, and customer-facing teams.

  • Experience presenting technical findings to non-technical stakeholders at multiple levels of the organization.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.techcareers.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all