[Remote] Sr Product Security Engineer, AI & DevSecOps
Note: The job is a remote job and is open to candidates in USA. McKesson is an impact-driven healthcare company focused on making quality care more accessible and affordable. The Senior Product Security Engineer will embed security across the software development lifecycle, focusing on AI-enabled products, cloud-native platforms, and DevSecOps practices. The role partners with engineering, platform, architecture, and product teams to design secure solutions, automate security controls, and strengthen application and AI system security.
Responsibilities
- Conduct security architecture reviews, threat modeling, and security assessments for applications, APIs, cloud services, and AI-enabled systems
- Define and implement security requirements, standards, reusable design patterns, and security guardrails across the software development lifecycle
- Identify, assess, and help mitigate security risks while partnering with engineering teams to remediate vulnerabilities and strengthen secure coding practices
- Assess and secure AI, machine learning, and generative AI solutions, including controls for model governance, secure access, data protection, and AI risk management
- Design and implement security controls for cloud-native applications, containers, Kubernetes, serverless platforms, and infrastructure-as-code deployments
- Integrate security controls and automated testing into CI/CD pipelines, including SAST, DAST, software composition analysis, secrets detection, container scanning, and infrastructure scanning
- Develop security automation using scripting, infrastructure-as-code, policy-as-code, and compliance-as-code technologies
- Support identity and access management, secrets management, cloud security monitoring, vulnerability management, and incident response activities
- Contribute to compliance initiatives, security metrics, risk reporting, and continuous improvement efforts
- Provide technical guidance on secure development practices and champion a security-first engineering culture
Skills
- Degree in Computer Science, Information Security, Engineering, or related technical field, or equivalent experience
- Typically requires 7+ years of relevant experience in application security, product security, security engineering, or a related cybersecurity discipline
- Experience conducting security architecture reviews, threat modeling, secure design reviews, and vulnerability remediation
- Experience implementing DevSecOps practices and integrating security controls into CI/CD pipelines
- Experience securing AI/ML platforms, generative AI solutions, large language model applications, or data science workflows
- Experience with secure software development lifecycle practices, vulnerability management, and Agile development methodologies
- Experience with cloud platforms such as Microsoft Azure, AWS, or Google Cloud Platform and cloud-native technologies including containers and Kubernetes
- Experience with infrastructure-as-code and CI/CD technologies such as Terraform, GitHub Actions, Azure DevOps, GitLab, Jenkins, or similar tools
- Proficiency in scripting and automation using Python, PowerShell, Bash, or comparable languages
- Experience with security tooling including SAST, DAST, software composition analysis (SCA), container security, secrets detection, and infrastructure scanning
- Knowledge of AI security frameworks and controls, including the OWASP Top 10 for LLM Applications and the NIST AI Risk Management Framework
- Experience implementing policy-as-code, compliance-as-code, or security automation solutions
- Experience supporting regulatory and control frameworks such as SOC 2, HIPAA, SOX, NIST Cybersecurity Framework (CSF), or ISO 27001
- Experience with Security Orchestration, Automation, and Response (SOAR) platforms
- Ability to communicate complex technical risks and tradeoffs to both technical and non-technical stakeholders
- Ability to influence across teams, contribute to technical standards, and promote secure engineering practices
Benefits
- Fully Remote
- An annual bonus may be offered.
- Long-term incentive opportunities may be offered.
Company Overview
Company H1B Sponsorship