Backend Staff Engineer
Our client is a global LegalTech organization delivering data-driven digital solutions that help businesses manage regulatory complexity, improve compliance processes, and make smarter decisions.
We usually respond within a day
Our client is the global leader in regulatory and sustainability intelligence, helping the world's largest companies navigate Environment, Health & Safety, Corporate Sustainability, and Product Compliance.
They serve a global customer base that includes many Fortune 500 companies, and they are moving fast on AI: AI-powered products, generative-AI tooling in the hands of every team, and managed cloud AI services running in production. Someone has to make all of that safe.
This is that seat. As Senior Security AI Engineer you own the security of AI and ML systems end to end: you set the standards for how the company adopts AI, you threat-model LLM and generative-AI architectures, you embed security into CI/CD and MLSecOps pipelines, and you lead the investigation when something targets AI infrastructure or inference endpoints. You work hand in hand with the AI, Application Engineering, and Cloud Platform teams, and you keep the classic security foundations solid while you do it.
🚀 Responsibilities:
AI security strategy & governance
Define, implement, and govern the security standards, policies, and frameworks for AI/ML adoption across all business units.
Monitor emerging cybersecurity trends, adversarial ML tactics, and global compliance regulations, and evolve the security posture ahead of new attack vectors.
Partnering with engineering & product
Act as the primary security partner for the Platform, Application Engineering, and Product teams, supporting the responsible development and deployment of AI-powered features.
Provide guidance on secure design patterns for AI workloads, and run security reviews of application code, cloud architectures, and managed AI services.
Champion security culture alongside Tech Leads, Engineering Managers, and the Security Champions network.
MLSecOps & secure SDLC
Architect and enforce security controls, automated testing, and vulnerability management inside CI/CD pipelines, DevSecOps, and MLSecOps workflows.
Make the secure path the easy path for engineers, so security scales without becoming a bottleneck.
AI risk & threat modelling
Run security architecture reviews and risk assessments on Large Language Models and generative-AI systems.
Mitigate AI-specific risks: prompt injection, insecure output handling, data poisoning, model inversion, and model supply-chain vulnerabilities (OWASP LLM Top 10).
Incident response
Lead investigation, mitigation, and recovery for complex security incidents, including threats targeting AI infrastructure, inference endpoints, and managed cloud AI services such as Azure OpenAI or AWS Bedrock.
Implement robust security controls and deploy new security solutions to close the gaps each incident reveals.
👤 Profile sought:
Experience
At least 3 years as a cybersecurity professional, with real hands-on exposure to AI/ML security, LLM security, or securing AI-driven systems.
Comfortable operating as a senior individual contributor: you set standards, influence engineering teams, and drive decisions without needing a team to manage.
Technical skills
Application Security and Secure SDLC: integrating security practices into CI/CD pipelines, code review, DevSecOps and MLSecOps workflows.
OWASP Top 10 and OWASP LLM Top 10: solid grasp of common web application vulnerabilities and of their AI/LLM equivalents (prompt injection, insecure output handling, model supply-chain risk).
AI/ML threat vectors: adversarial attacks, data poisoning, model inversion, and securing inference endpoints.
Cloud security across AWS, Azure, or GCP, including securing AI/ML workloads and managed AI services (Azure OpenAI, AWS Bedrock, GCP Vertex AI).
IAM, encryption in transit and at rest, shared-responsibility models, and securing virtual machines and containerized environments.
Networking fundamentals: TCP/IP, LAN/WAN, the OSI model, and the security implications of each layer.
Security protocols such as HTTPS, DNS, SMTP, FTP, and SSH; firewalls, IDS/IPS concepts.
Information security principles: confidentiality, integrity, availability.
Incident investigation and response processes.
Scripting and automation in Python and PowerShell; API security testing and secure coding practices in web application stacks.
Familiarity with Windows, Linux/Unix, and macOS.
Certifications
An AI security certification is a strong plus: AAISM (Advanced in AI Security Management) or CompTIA SecurityAI+ (SecAI+). If you do not hold one yet, a clear willingness to certify shortly after joining works too.
CISSP, CCSP, or CEH are also valued.
Bonus
Any additional core engineering skill you bring to the team: front-end development, cloud systems administration, serverless deployment, or deep Linux knowledge.
Languages
Fluent English required. Any additional language is an asset.
Soft skills
Excellent communicator: able to align security policies and procedures with business objectives and compliance requirements, and to explain risk to non-security audiences.
Strong teamwork, with colleagues and with external partners alike.
Creative, dynamic, and able to work independently while staying transparent with the team.
Both individual and collective problem-solving: you dig into the hard cases and you bring others with you.
🌍 Benefits & Culture:
Security scope: AI/ML and LLM security, MLSecOps, cloud security across AWS/Azure/GCP, managed AI services, AppSec and secure SDLC.
A rare mandate: define how a global company adopts AI safely, from strategy down to pipeline controls, rather than inheriting someone else's framework.
Real reach across the organisation: AI, Application Engineering, Cloud Platform, Product, and the Security Champions network.
A company that prioritizes its people, trusts them to deliver, and invests in their growth.
Competitive compensation, benefits, and flexibility.
Hybrid role.
💼 Department: IT & Security
📍 Location: Lisbon (Hybrid)
📆 Start date: ASAP
- Locations
- Lisboa
- Remote status
- Hybrid