Product Security Engineer

StackAI

Poland

On-site

PLN 235,848 - 321,612

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

StackAI is looking for a Senior Product Security Engineer in Poland to join our team and ensure the security of our AI assistant platform. You will take ownership of security-critical systems, implement encryption, and protect customer data, working closely with the Core engineering team. Your role will also involve threat modeling, improving tooling coverage, and establishing security as a key part of our development process.

We seek candidates with at least 4 years of experience in security-critical systems, strong coding skills, and a background in secure architecture. If you are eager to grow and tackle these challenges, we'd love to hear from you!

Qualifications

  • 4+ years building security-critical systems in production, implementing rather than just reviewing.
  • Practical experience in encryption, KMS, secrets handling, and signing.
  • Strong ability to design secure systems and collaborate as a technical peer.

Responsibilities

  • Own encryption and signing, manage KMS and key management.
  • Protect sensitive customer data and enhance data protection.
  • Lead threat modeling across systems using AI-assisted tooling.

Skills

Cryptography and key management
Secure architecture judgement
Secure coding in Python and TypeScript/Node.js
Multi-tenant SaaS isolation experience

Job description

About the role

At StackAI, security is how we earn the trust of the enterprises building AI assistants on our platform. We're hiring a hands‑on (Senior) Product Security Engineer to design, build, and harden the secure architecture at the core of the product, working as a technical partner to our Core engineering lead. This is a hands‑on engineering role. You'll write production code and own the security‑critical systems the whole platform depends on: encryption and key management, customer data protection, and how security is built into the way every team ships. If you want deep ownership of these systems and the chance to harden and scale them as the platform grows, we'd love to meet you.

What you’ll do
  • Own encryption and signing. Take ownership of our KMS, key management, BYOK, envelope encryption, and signing pipeline across both cloud and on‑prem deployments—operating, hardening, and evolving them as the platform scales.
  • Protect the most sensitive customer data. Extend our PHI/PII scrubbing and strengthen the data‑protection foundations that regulated enterprises already rely on.
  • Secure the storage layer. Own encryption at rest and tenant isolation.
  • Keep security the default in how we ship. Maintain and expand the secure‑by‑default templates and reference implementations embedded in our SDLC—the ones engineers actually want to adopt.
  • Threat‑model the platform. Lead threat modeling on the seams between systems (the execution engine, connector trust boundaries, and multi‑tenant isolation), using modern, AI‑assisted threat‑modeling tooling.
  • Raise the bar on tooling. Push our scanning further on coverage, signal, and CI enforcement, so critical findings never reach production.
  • Be the technical point of contact for security standards. Translate audit, compliance, and incident‑response requirements into real implementation in our codebase.
What we’re looking for
  • 4+ years building security‑critical systems in production, with significant time spent implementing, not only reviewing or assessing.
  • Practical depth in cryptography and key management: encryption, KMS, secrets handling, and signing in real systems.
  • Secure architecture judgment: you can design and reason about secure systems and hold your own as a technical peer with senior engineers.
  • Multi‑tenant SaaS isolation experience, including the data‑isolation guarantees regulated customers require.
  • Strong secure‑coding skills in our stack: Python on the backend, TypeScript/Node.js on the product surfaces.
  • Comfortable wiring security checks and gates into CI/CD so security is enforced automatically in the pipeline.

Security engineering is broad. If you're strong on most of this and excited to grow into the rest, we'd like to hear from you, even if you don't check every box.

Bonus points
  • Cloud and API security fundamentals on GCP, Azure, or AWS.
  • Securing on‑prem, self‑hosted, or air‑gapped deployments.
  • Experience in regulated domains (healthcare/PHI, finance, etc.).
  • Familiarity with AI/LLM platform security: agent execution, connector trust boundaries, prompt and tool‑call risk.
  • Startup or growth‑stage experience.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer
Product Security Engineer

StackAI • Warszawa

On-site
PLN 260,000 - 350,000
Software Engineer and Security Researcher
Software Engineer and Security Researcher

Commit • Warszawa

Hybrid
PLN 190,000 - 270,000
Senior Product Security Engineer - Encryption & Data Trust
Senior Product Security Engineer - Encryption & Data Trust

StackAI • Poland

On-site
PLN 235,000 - 322,000
Senior Product Security Engineer: Encryption & Data
Senior Product Security Engineer: Encryption & Data

StackAI • Warszawa

On-site
PLN 260,000 - 350,000
Director of Engineering
Director of Engineering

Internetwork Expert • Warszawa

Hybrid
PLN 682,000 - 1,062,000
Fully remote position
Global team
Flexible working hours
Application Security Engineer
Application Security Engineer

Solidgate • Województwo mazowieckie

On-site
30+ days off
Unlimited sick leave
Free office meals
+2
Lead Azure AI Security Engineer
Lead Azure AI Security Engineer

EPAM • Poland

On-site
PLN 85,000 - 110,000
AI Security Architect
AI Security Architect

Sapiens • Poland

On-site
PLN 180,000 - 240,000
Director, Security Engineering & Operations
Director, Security Engineering & Operations

Cognism • Województwo mazowieckie

On-site
PLN 350,000 - 520,000
Senior Product Owner ID71659
Senior Product Owner ID71659

AgileEngine, LLC. • Lublin

Hybrid
PLN 180,000 - 300,000
Professional growth
Competitive compensation
Exciting projects
+1