> Markdown version of [/jobs/ext/956422-telecommute-staff-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/956422-telecommute-staff-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # TELECOMMUTE Staff Product Security Engineer - **Company:** AlphaSense, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $184,000.0 - $252,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Public-Key Cryptography, Microsoft Azure, Cloud Computing, Code Review, Continuous Integration, DevOps, Information Systems Security Architecture Professional, Python (Programming Language), Key Management, OAuth, OpenID, Systems Development Life Cycle, Role-Based Access Control, Security Assertion Markup Language (SAML), Secure Coding, Software Vulnerability Management, Google Cloud, Software Security, Machine Learning Operations, Data Pipelines, Devsecops, Security Orchestration, Automation & Response, Vulnerability Analysis, Microservices - **Published:** June 9, 2026 - **Apply:** https://www.dice.com/job-detail/7e9fd245-25b2-4c01-979f-da612fae8959 ## About the Role * 7+ years of experience in product or application security engineering. * Deep understanding of secure SDLC, threat modeling, and secure architecture design. * Proven expertise with AWS cloud security concepts and best practices. * Strong experience with container security, orchestration, and runtime protection. * Proficiency in Python, Java, and/or JavaScript for security automation, code review, and tooling. * Experience securing AI/ML pipelines, data workflows, or model-serving infrastructure. * Familiarity with DevSecOps and continuous integration/deployment environments. * Familiarity with encryption fundamentals, including symmetric and asymmetric cryptography, TLS/mTLS, key management, and secrets handling best practices. * Demonstrated ability to drive cross-functional security initiatives, partnering with engineering, product, and legal teams to embed security requirements into roadmaps, influence architectural decisions, and align stakeholders across organizational boundaries. Nice to Have: * Experience with Google Cloud Platform or Azure cloud platforms. * Knowledge of AI and LLM security. * Experience with software supply chain security and artifact integrity verification. * Familiarity with compliance and governance frameworks (SOC 2, ISO 27001, NIST 800-53, NIST AI RMF). * Understanding of authentication and authorization patterns in modern applications, including OAuth 2.0, OIDC, SAML, RBAC, and ABAC. * Certifications such as CKS (Certified Kubernetes Security Specialist), CISSP, CSSLP, or AI/ML-focused security credentials. ## Description We're looking for a Staff Product Security Engineer to lead the design and implementation of secure, scalable, and trustworthy products spanning AI, data, and cloud-native systems. You'll work closely with engineering, data science, and infrastructure teams to embed security by design throughout the product lifecycle. This role sits at the intersection of AI/ML security, secure product development, and container/cloud-native protection, helping define the architecture, automation, and frameworks that enable secure, intelligent products at scale. What You'll Do * Embed robust security practices throughout the software and AI development lifecycle (SDLC). * Lead secure design reviews, threat modeling, and risk assessments for AI-driven products, APIs, and backend services. * Partner with engineering and product teams to ensure security, privacy, and compliance by design. * Build and maintain security automation and governance frameworks that integrate seamlessly into development workflows. * Architect and enforce security controls for AI/ML systems, including model training, data pipelines, and inference environments. * Identify and mitigate AI-specific attack vectors such as data poisoning, model inversion, prompt injection, and model theft. * Collaborate with governance and compliance teams to align with ethical AI principles and frameworks like NIST AI RMF and the EU AI Act. * Implement model provenance, integrity, and auditability controls to ensure responsible and secure AI operations. * Partner with DevOps and SRE teams to secure service meshes, container networking, and secrets management. * Drive software supply chain security, including artifact integrity, dependency management, and vulnerability reduction. * Build internal frameworks for continuous assurance and real-time vulnerability management. * Define and maintain reference security architectures for microservices, APIs, and AI-powered systems deployed in the cloud. * Mentor teams on secure coding, containerization best practices, and AI risk management. * Promote a security-first culture through advocacy, documentation, and training. * Represent product security in cross-functional initiatives and leadership discussions. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)