Senior Security Engineer (AI)
Tech Stack / Keywords
Firma i stanowisko
Sopra Steria is one of the largest tech industry players in Europe, operating in nearly 30 countries with over 55,000 employees. The Polish branch in Katowice, functioning as the Global Delivery Center since 2007, employs around 1,000 specialists. Teams specialize in cloud, operating systems, virtualization, databases, backup, storage, networking, security, software development, data engineering, testing, CRM, ITSM and ERP platform integrations, serving clients across Scandinavia, Benelux, France, Germany, Switzerland, and the UK.
Wymagania
- Minimum 2 years of experience in Cyber Security.
- Hands-on experience in Application Security, Offensive Security, DevSecOps, or Security Testing.
- Experience assessing security of web applications, APIs, and modern application architectures.
- Basic or advanced understanding of AI security concepts.
- Knowledge of threats affecting LLM and Generative AI systems.
- Understanding of attack techniques targeting AI models and LLM-based systems.
- Knowledge of protection mechanisms for AI models, data, and AI agents.
- Interest in AI Governance and AI Risk Management.
- Application Security skills: Web Application Security (OWASP Top 10, API Security), Secure Software Development Lifecycle (SSDLC), Security Testing (manual testing, code reviews, SAST, DAST).
- Network Security skills: Network protocols and communication security, network segmentation, and access control.
- DevSecOps: CI/CD Security, Software Supply Chain Security, Dependency Management, Software Bill of Materials (SBOM).
- EU citizenship.
- Fluent English (B2/C1).
- Willingness to commute to Katowice or Gdańsk offices and occasional business trips abroad.
Nice to have:
- Experience with GenAI, LLMs, Agentic AI, RAG, or MCP.
- Experience in Penetration Testing.
- Experience in Red Teaming.
- Experience in Security Research.
- Security-related certifications (e.g., OSCP, OSWE, CISSP, GWAPT, GWEB, CARTA).
Obowiązki
AI Security Research and Knowledge Development:
- Monitor trends, emerging threats, and attack techniques targeting AI and LLM-based systems.
- Analyze new tools, frameworks, and solutions supporting AI security.
- Conduct technical research including proof-of-concept development, laboratory testing, and offensive security testing.
- Evaluate new AI Security technologies and recommend adoption.
AI Security Assessments:
- Analyze AI-powered system architectures.
- Identify risks from AI models, AI agents, LLMs, RAG, MCP, and other AI components.
- Assess resilience against attacks like Prompt Injection, Jailbreak, Data Exfiltration, Model Abuse, Tool Abuse, and Supply Chain Attacks.
- Recommend security controls and architectures for projects.
Standards and Documentation Development:
- Develop guidelines, standards, and best practices in AI Security.
- Support implementation of secure design patterns.
- Contribute to security recommendations for clients and teams.
- Create training and educational materials.
Knowledge Sharing:
-
Organize workshops, presentations, and knowledge-sharing sessions.
-
Support AI Security community development within the organization.
-
Provide consulting to Application Security, DevSecOps, and Architecture teams.
-
Promote awareness of AI technology risks.
Benefity
- Benefits (UoP): Luxmed, Medicover Sport, Worksmile, educational platforms, language learning platform, referral bonus, life insurance, company-paid certifications, conferences, Tech Lunches.
- Opportunity to join Communities (Project Management, Architecture, Security, Process Management, Leadership, AI, Cloud).
- Local kindergarten available.
- Development opportunities (B2B): Tech Lunches, Worksmile, Communities.
- Additional perks: free parking, fresh fruits, workation.
Inne informacje
Only candidates located in Poland with EU citizenship and willingness to commute to offices in Katowice or Gdańsk can be considered for cooperation.
Sopra Steria
30 aktywnych ofert