> Markdown version of [/jobs/ext/347169-senior-ai-security-engineer](https://www.wearedevelopers.com/jobs/ext/347169-senior-ai-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior AI Security Engineer - **Company:** Obsidian Security - **Location:** Cheltenham, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Artificial Intelligence, Big Data, Software as a Service, Cloud Computing Security, Cyber Security, Software Debugging, Data Intelligence, Python (Programming Language), Salesforce.Com, SQL Databases, Okta, Large Language Models, Software Security, AI Platforms, Gsuite, Vertica, GPT, Databricks - **Published:** June 18, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=21bc2df0310a77d8 ## About the Role * 4+ years in cybersecurity, with a focus on SaaS platforms, cloud security, identity systems, or application security. * A track record of original thinking - you've found things other people missed, whether in research, red teaming, bug bounty, or product security work. * Strong understanding of how SaaS platforms (Google Workspace, Microsoft 365, Salesforce, Okta, or similar) work under the hood: API structures, permission models, authentication flows. * Solid SQL and Python skills - you won't be the one building the pipelines, but you need to be able to query large datasets, write detection logic, and prototype ideas end-to-end without leaning on the data engineers to do it for you. * Ability to communicate complex security concepts clearly to an engineering audience. Nice to Have * Experience with AI/LLM platforms (ChatGPT Enterprise, Copilot, Gemini, Claude, etc.) from a security perspective. * Familiarity with dbt, Clickhouse, or Databricks. * Experience working in a product security or security research function at a security vendor. * Published research, CVEs, conference talks, or bug bounty work demonstrating independent security thinking. ## Description * This is a security-depth role on our Manchester engineering team. We collect rich telemetry from hundreds of SaaS and AI platforms - and we're looking for someone who can look at that data and ask questions no one has asked before. * Your core contribution is security insight: understanding how SaaS and AI platforms are built, how they're abused, and how the signals we collect can be used in novel ways to solve real customer security problems. You'll work alongside a team of data engineers, advising on what's worth detecting and building prototype approaches to prove it out. * You need to be a competent engineer - comfortable writing SQL, Python, and working with large datasets - not at the level of a dedicated data engineer, but independently capable. Your edge is security knowledge and creative thinking; the data skills are the table stakes that let you exercise it. What you'll do * Develop deep expertise in how major SaaS and AI platforms are structured, how they handle identity and access, and where security risk concentrates - then translate that into detection and posture logic for our product. * Look across the telemetry we collect and identify novel ways to use it: new signals, new correlations, new approaches to catching misconfigurations or risky behaviour that existing tools miss. * Advise the engineering team on what security controls matter and why - acting as the security compass that helps the team prioritise what to build. * Prototype new detection approaches in SQL and Python to validate ideas before they're productised. * Stay close to the attacker perspective - tracking how threats against SaaS and AI platforms evolve and ensuring our coverage stays ahead of them. * Debug security-related issues in customer environments, bringing both data fluency and security judgment to ambiguous problems. ## Related Videos - [ Evaluating AI models for code comprehension](https://www.wearedevelopers.com/videos/1462-evaluating-ai-models-for-code-comprehension) - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [Streaming AI Responses in Real-Time with SSE in Next.js & NestJS](https://www.wearedevelopers.com/videos/1630-streaming-ai-responses-in-real-time-with-sse-in-next-js-nestjs) - [The transformative impact of GenAI for software development and its implications for cybersecurity](https://www.wearedevelopers.com/videos/952-the-transformative-impact-of-genai-for-software-development-and-its-implications-for-cybersecurity) - [Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) - [Speak, Code, Deploy: Transforming Developer Experience with Voice Commands](https://www.wearedevelopers.com/videos/1159-speak-code-deploy-transforming-developer-experience-with-voice-commands) ## Related Articles - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity](https://www.wearedevelopers.com/magazine/709-dev-digest-210-ai-agents-are-go-is-mcp-dead-llms-crack-anonymity)