AI Product Security Engineer
United States
- Posted 2mo ago
- From Forescout’s careers page
- Location
- United States
- Experience
- 5+ years
- Department
- Product Management
Opens the listing on jobs.jobvite.com
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
What You Will Do
We are seeking an experienced Product Security Engineer to design, build, and scale security capabilities at the scale of AI. This is a highly technical, hands-on role focused on operating AI-assisted vulnerability management, product security automation, and secure-by-design engineering practices.
The ideal candidate combines deep expertise in application security, cloud security, DevSecOps, and AI technologies. This position focuses on building security into the SDLC and working with engineering teams develop, deploy, and operate secure products at scale. You will act as a force multiplier across Product Management, Engineering, Platform Engineering, Cloud Operations, Compliance, and Security teams by embedding security directly into the software development lifecycle and leveraging AI to increase both security coverage and engineering velocity.
AI-Powered Vulnerability Management for Secure SDLC
- Partner with Architects to define secure architecture patterns for Development, and Operate Product Security systems
- Build AI-driven solutions into CI/CD to accelerate
- Vulnerability discovery
- Triage and prioritization
- Root cause analysis
- Remediation recommendations
- Validation testing
- Penetration testing
- Security documentation
- Develop exploitability-aware prioritization models using business context, reachability, threat intelligence, and customer impact.
- Reduce false positives and improve signal-to-noise ratios across Development tooling.
- Implement automated workflows for CVE, KEV, SBOM, SAST, DAST, Dependency Management, EoL and SCA findings.
Product Security Operations
- Conduct threat modeling, design reviews, security assessments, and architecture reviews.
- Partner with development teams to identify and remediate security weaknesses.
- Participate in vulnerability response and incident response activities.
- Work with engineering teams to reduce critical vulnerability exposure and accelerate remediation timelines.
- Develop dashboards and metrics that measure risk reduction, security maturity, and remediation performance.
Compliance & Regulatory Support
- Ensure security controls remain updated and align with customer, certification, and government requirements, ex.
- NIST Secure Software Development Framework (SSDF)
- FedRAMP
- ISO 27001
- SOC 2
- Common Criteria
- CRA/NIS2
- Other regulatory requirements
What You Bring to Forescout
Security
- 5+ years of experience in:
- Product Security
- Application Security
- Cloud Security
- DevSecOps
- Security Engineering
- Demonstrated experience securing enterprise-scale software products and cloud services.
- Experience integrating security into modern SDLC pipelines.
Technical Skills
- Threat modeling
- Secure design reviews
- Vulnerability assessment
- Penetration testing
- Secure coding practices
- Incident response
- Software supply chain security
- Penetration Testing
Security Tooling
Experience with several of the following:
- Snyk
- Wiz
- Burp Suite
- Tenable
- GitHub Advanced Security
- Claude Security
- OpenAI SCT
- Open Source AI tooling / harnesses
- Veracode
- Semgrep
- SonarQube
Cloud & Infrastructure
- Azure
- AWS
- Kubernetes
- Containers
- Infrastructure-as-Code (Terraform)
- Identity and access management
- API security
Programming
Strong proficiency in one or more:
- Python
- Java
- Go
- C/C++
- JavaScript/TypeScript
AI-Specific Qualifications
- Hands-on experience using AI/LLM technologies in engineering or security workflows.
- Understanding of:
- Prompt injection attacks
- RAG security risks
- AI model abuse
- Data poisoning
- Tool misuse
- Agent security
- AI governance controls
- Experience building or integrating AI-assisted automation solutions.
- Familiarity with AI coding agents, copilots, and autonomous security workflows.
Preferred Qualifications
- CISSP, CSSLP, OSCP, GIAC, or equivalent certification.
- Experience with AI red teaming and adversarial testing.
- Experience building developer security platforms.
- Experience securing SaaS products, APIs, and distributed systems.
- Familiarity with enterprise-scale software delivery organizations.
- Experience supporting FedRAMP or government cloud environments.
Skills they ask for
Pick one to see other roles that ask for it.
About Forescout
Cybersecurity for connected assetsForescout provides cybersecurity software for discovering and securing connected assets, including IoT, operational technology, medical devices, networks, and cloud environments.
See all 10 roles at ForescoutMore roles at Forescout
See all 10- Director, Product ManagementUnited States · DirectorProduct Management · DirectorUnited States1w
- Azure DevOps EngineerDallas · HybridEngineering · HybridDallas, United States1w
- Commercial Account ManagerDallas · Entry Level · On-siteSales · Entry Level · On-siteDallas, United States3w
- DevOps EngineerPune · SeniorInformation Technology · SeniorPune, India1mo
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.