- Company Name
- Rokt
- Job Title
- Senior Security Engineer
- Job Description
-
**Job Title**
Senior Security Engineer
**Role Summary**
Apply advanced application, cloud, and AI security expertise to design, develop, and scale automated security solutions that integrate with continuous delivery pipelines. Lead AI‑driven security assessment tools, threat modeling, and policy development, ensuring robust protection of APIs, cloud assets, and AI workflows.
**Expectations**
- 5+ years in application, cloud, or AI security engineering.
- Proven ability to secure AI‑powered applications beyond prompt‑injection threats.
- Hands‑on experience with AI automation platforms (Copilot, Cursor, N8N, Replit).
- Strong programming skills in Go or Python.
- Proficiency in AWS or GCP environments and supply‑chain security (SLSA).
- Familiarity with SAST, SCA, DAST tools and security‑by‑design principles.
- Builder mindset: autonomously identify vulnerabilities and architect scalable, context‑aware controls.
**Key Responsibilities**
- Develop AI‑driven security assessment and automation workflows (e.g., Copilot, Cursor, N8N, Replit).
- Reimagine and implement modern SAST, SCA, and DAST processes aligned to AI development paradigms.
- Build preventative security libraries and rule sets targeting emerging risk categories such as API security and LLM‑related vulnerabilities.
- Partner with software engineers, platform teams, and GRC to embed security throughout products and infrastructure.
- Lead security reviews, scalable threat modeling, and data‑privacy impact assessments.
- Shape security policies, standards, guidelines, and AI security education programs.
**Required Skills**
- Application, cloud, and AI security engineering.
- Secure design of API, cloud‑native, and CI/CD pipelines.
- AI workflow automation, coding, and debugging.
- Programming in Go or Python.
- Cloud platform expertise (AWS, GCP).
- Knowledge of SLSA supply‑chain frameworks.
- Experience with SAST, SCA, DAST tools (open‑source & commercial).
- Analytical threat‑modelling and risk‑assessment capabilities.
- Communication and collaboration with cross‑functional teams.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- GIAC Web Application Defender (GWEB), OSWE, or equivalent SANS certifications preferred.