Principal Security Engineer
Job description
About the role
We are seeking an experienced Principal Security Engineer to lead and shape our security initiatives across the organization. This on-site position is highly technical and requires a proactive approach to both offensive and defensive security measures. You will be responsible for ensuring the security and integrity of our applications, cloud infrastructure, and AI-driven technologies. Your work will involve identifying vulnerabilities, developing security strategies, and collaborating closely with engineering teams to implement effective security solutions. The role offers an exciting opportunity to work at the forefront of AI security, helping to safeguard our systems against emerging threats and ensuring compliance with industry standards.
Key facts
What you'll do
- Conduct detailed manual penetration testing on web applications, APIs, microservices, and cloud infrastructure to identify security vulnerabilities that automated tools might overlook.
- Develop Proof-of-Concept exploits to demonstrate potential business risks, providing concrete evidence of security gaps and helping prioritize remediation efforts.
- Perform secure code reviews in languages such as Go, Python, and Java, analyzing critical code paths to detect security flaws early in the development process.
- Collaborate with engineering teams to implement security fixes, ensuring vulnerabilities are properly addressed and mitigated before deployment.
- Design and implement security measures tailored to protect against threats targeting Large Language Models (LLMs), including Prompt Injection and Data Poisoning attacks, to maintain the integrity and confidentiality of AI systems.
- Conduct adversarial testing on internal AI systems and customer-facing LLM functionalities to assess robustness against malicious inputs and manipulation.
- Create comprehensive technical audit frameworks to evaluate AI model training data, outputs, and safety measures, ensuring compliance with security standards and best practices.
- Develop and maintain custom automation tools to facilitate security testing across web applications, APIs, AI pipelines, and vector databases, streamlining vulnerability detection processes.
- Secure cloud environments such as AWS, GCP, and Azure by enforcing best practices like least privilege access, network segmentation, and container security.
- Build automated policies and guardrails to prevent insecure infrastructure configurations, reducing the risk of misconfigurations that could lead to security breaches.
- Integrate application security signals with cloud logging and monitoring systems to create a unified security framework capable of early threat detection and rapid response.
- Serve as the primary security architect for cross-functional projects, providing guidance on security architecture and best practices.
- Mentor senior engineers and promote a security-aware culture within the organization, fostering continuous improvement in security posture.
- Stay current with emerging security threats, especially those related to AI and cloud environments, and recommend appropriate countermeasures.
- Participate in security incident response activities, including investigation, containment, and remediation of security incidents.
- Contribute to security documentation, policies, and training materials to enhance organizational security awareness.
Requirements
- Minimum of 5 years of experience in application security, cloud security, or related fields.
- Proven expertise in penetration testing, vulnerability assessment, and secure coding practices.
- Strong understanding of cloud security principles, especially with AWS, GCP, and Azure platforms.
- Hands-on experience with programming languages such as Go, Python, and Java, including secure coding and automation scripting.
- Familiarity with security tools, frameworks, and methodologies relevant to application security, cloud environments, and AI systems.
- Demonstrated ability to work collaboratively with engineering teams to design and implement security solutions.
- Experience with security automation, including developing custom tools and scripts for testing and monitoring.
- Knowledge of AI security threats, including Prompt Injection, Data Poisoning, and adversarial attacks, is highly desirable.
- Strong analytical and problem-solving skills, with the ability to think creatively about security challenges.
- Excellent communication skills, capable of explaining complex security concepts to technical and non-technical stakeholders.
- Relevant security certifications such as OSCP, OSWE, or AWS Certified Security are a plus.
Nice to have
- Contributions to open-source security projects or research related to AI security.
- Experience developing or implementing Security Orchestration, Automation, and Response (SOAR) workflows.
- Knowledge of regulatory standards and compliance frameworks relevant to security and AI.
- Familiarity with container orchestration tools like Kubernetes and security best practices for containerized environments.
- Experience working in fast-paced, agile development environments with continuous integration and deployment pipelines.
Skills & tools
- Proficiency with security testing tools such as Burp Suite, OWASP ZAP, and similar.
- Experience with cloud security tools and services, including AWS Security Hub, GCP Security Command Center, and Azure Security Center.
- Scripting skills in Python, Bash, or other languages to automate security tasks.
- Familiarity with infrastructure-as-code tools like Terraform or CloudFormation for secure environment provisioning.
- Knowledge of network security concepts, including firewalls, VPNs, and intrusion detection systems.
- Ability to analyze logs, alerts, and security signals to identify and respond to threats effectively.
Practical notes
- Candidates must be eligible to work in Portugal; visa sponsorship is not provided.
- The role is on-site at our Portugal office; remote work is not available unless explicitly stated.
- Occasional travel may be required for team meetings, conferences, or security assessments.
- Talkdesk offers a competitive benefits package, including health insurance, paid time off, and opportunities for professional development.
- The application deadline is [insert application deadline]; early applications are encouraged.
- Candidates should be prepared for a technical interview process that may include practical assessments and security scenario discussions.