Staff Security Engineer, AI & Application Security

4 weeks, 2 days ago
Full-time
Lead
Cybersecurity
Marcura

Marcura

Marcura specializes in providing innovative solutions that streamline processes in the maritime industry, focusing on the automation of disbursement accounts, crew and supplier payments, and optimizing time spent in port.

Internet Software & Services
251-1K
Founded 2001

Description

  • Define and maintain a prioritized security roadmap and make clear build-versus-buy decisions.
  • Review system architecture and designs early to embed threat modelling and secure-by-design patterns.
  • Advise product, engineering, data, and operations teams on secure AI adoption and LLM/agentic system design.
  • Build and maintain AI security standards, controls, checklists, and a live inventory of deployed models.
  • Establish and run internal penetration testing and AI red team exercises across applications, APIs, cloud, and internal services.
  • Own and coordinate external penetration testing, partner management, and remediation tracking.
  • Perform hands-on offensive testing against production and pre-production systems.
  • Improve application, cloud, identity, access, and data protection controls through hardening and automation.
  • Own the technical relationship with the MDR provider, including telemetry, detection tuning, and validation.
  • Lead vulnerability management, incident response support, security tooling, reporting, and engineering enablement.

Requirements

  • 8+ years of total experience in security engineering across offensive and defensive work.
  • At least 4 years of hands-on offensive experience leading and executing penetration tests and red team exercises.
  • Demonstrable experience hardening cloud and application environments and building or tuning detections.
  • Proven experience securing LLM or AI systems in production, including prompt injection, jailbreaks, and agent abuse.
  • Experience as a first, sole, or founding security hire, or building security capability with minimal supervision and constrained resources.
  • Track record of influencing architecture and design decisions across engineering and product teams.
  • Experience supporting or leading incident response in a production environment.
  • Experience owning and getting value from an MDR or managed SOC provider.
  • Experience scoping and challenging external penetration tests and turning findings into remediation.
  • Evidence of finding real vulnerabilities in real systems, such as CVEs, bug bounty results, security research, or high-level CTF results.
  • Certifications such as OSCP, OSEP, OSWE, GXPN, CRTO, CISSP, or cloud security specialties are welcome but not required.
  • A degree in Computer Science, Information Security, or Engineering is welcome but not required.
  • Experience in a regulated B2B, fintech, maritime, or logistics environment is preferred.

Benefits

  • Competitive salary and bonus.
  • Inclusive onboarding experience.
  • Wellness support through the Marcura Wellness Zone.
  • Global opportunities within an expanding company.
  • Diverse and supportive work culture with a focus on inclusion and belonging.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Quantum Computing / Cryptography Engineer

MKS2 Technologies 51-250 Internet Software & Services

MKS2 Technologies is seeking a remote Quantum Computing / Cryptography Engineer to support a federal program by advancing cryptographic modernization, quantum readiness, and post-quantum security migration planning.

C++ Cybersecurity Encryption Java Python
8 hours, 37 minutes ago

Cybersecurity Research Assistant

Axle Informatics 51-250 Pharmaceuticals

Axle is seeking a remote Cybersecurity Research Assistant in the United States to support rare disease research at NIH by implementing and monitoring security controls across Kubernetes, Linux, database, and high-performance computing environments.

Ansible Bash Cybersecurity DNS Elasticsearch Git Grafana Kubernetes Linux LLM Prometheus Python RHEL Secrets Management TCP/IP Terraform TLS Ubuntu
8 hours, 52 minutes ago

Cyber Security Engineer (R-00206)

True Zero Technologies 11-50 Internet Software & Services

True Zero Technologies is seeking Cybersecurity Engineers to support enterprise Zero Trust implementation by integrating security capabilities, validating controls, and producing technical evidence for authorization activities.

Cybersecurity Network Security
9 hours, 22 minutes ago

Zero Trust Engineer (R-00205)

True Zero Technologies 11-50 Internet Software & Services

True Zero Technologies is seeking Zero Trust Engineers to implement enterprise Zero Trust use cases across prioritized Department of Veterans Affairs information systems and guide them through planning, validation, testing, and operational transition.

Azure Cybersecurity
1 day, 8 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers