We are growing. And we are looking for talented people.
At Decskill, we believe that technological excellence is driven by human talent.
We are an IT consulting company with more than 10 years of consolidated experience in the market, focused on building long-term relationships with both our clients and our people. Today, we are a community of over 800 professionals, working from Lisbon, Porto, and Madrid, contributing to impactful technology initiatives.
As part of the Astek Group, we combine a strong local culture with a global presence, being active in around 23 countries across 4 continents. This allows us to offer an international context, diverse challenges, and long-term career opportunities, while staying close to our teams.
We would like to meet an AI Security Engineer for a hybrid working model.
What You’ll Do:
- Embed Security by Design into AI use cases, AI agents, and platform integrations, ensuring secure implementation throughout the AI lifecycle.
- Define and implement security controls covering access management, secrets, logging, monitoring, sandboxing, tool restrictions, APIs, and external integrations.
- Translate security policies, standards, and architecture principles into practical security controls, reusable patterns, and implementation guidelines for AI engineering teams.
- Work closely with AI Product, Engineering, AI Platform, Security, Data Protection, IT, and business teams to ensure secure delivery of AI initiatives.
- Assess AI solutions and identify security gaps, control weaknesses, deviations, and delivery risks.
- Prepare security evidence, support remediation activities, and elevate unresolved control gaps and risks when required.
- Address AI-specific security risks, including prompt injection, data leakage, unsafe tool usage, excessive permissions, insecure integrations, and insufficient auditability.
- Design and promote secure deployment patterns for AI agents, models, orchestration components, APIs, and supporting platform services.
- Support security due diligence and secure implementation of external AI vendors, models, third‑party components, and AI services.
- Ensure appropriate data protection, isolation, access control, and segregation when integrating external AI technologies.
- Strengthen AI incident readiness through security monitoring, logging, detection scenarios, incident response playbooks, exercises, and lessons learned.
- Collaborate with SOC and central security teams to improve detection, response, and investigation capabilities for AI-related incidents.
- Develop reusable security standards, patterns, and controls that can be adopted across different countries, teams, and AI environments.
- Contribute security lessons and best practices to continuously improve the organization’s AI security framework.
- Stay up to date with emerging AI security threats, Agentic AI risks, security frameworks, and industry best practices.
What We’re Looking For:
- Bachelor’s degree in Computer Science, Cybersecurity, Information Security, Engineering, or a related field.
- Professional experience in Cybersecurity, Application Security, Cloud Security, Product Security, or a related security engineering role.
- Hands‑on understanding of AI/ML security and emerging Agentic AI security risks.
- Strong knowledge of IAM, access controls, secrets management, API security, logging, monitoring, and secure software development practices.
- Experience implementing Security by Design principles across technology products or platforms.
- Good understanding of AI-specific threats such as prompt injection, data exfiltration, insecure tool use, excessive agent permissions, and model/API abuse.
- Experience with cloud environments, APIs, integrations, and modern application architectures.
- Understanding of security architecture, risk management, security controls, and technical security standards.
- Experience conducting security assessments, identifying control gaps, and supporting risk remediation.
- Familiarity with data protection and privacy requirements relevant to AI solutions.
- Strong analytical and problem-solving skills, with the ability to translate security requirements into practical technical controls.
- Ability to work collaboratively with engineering, product, platform, security, and business stakeholders.
- Excellent communication skills and a proactive, pragmatic mindset.
- Fluency in English is mandatory.
Nice to Have:
- Experience securing AI Agents, LLM applications, RAG architectures, AI orchestration platforms, or AI APIs.
- Knowledge of OWASP Top 10 for LLM Applications and emerging AI security guidance.
- Familiarity with MITRE ATLAS or other AI/ML threat modelling frameworks.
- Experience with cloud security across AWS, Azure, or GCP.
- Knowledge of DevSecOps, CI/CD security, container security, and infrastructure-as-code security.
- Experience with SIEM, SOC operations, security monitoring, and incident response.
- Familiarity with Zero Trust, least privilege, network segmentation, and workload isolation.
- Experience with third‑party risk management and vendor security assessments.
- Knowledge of AI governance, model risk management, privacy, and regulatory requirements.
- Security certifications such as CISSP, CCSP, CISM, Security+, or cloud/security certifications.
- Experience working in Agile environments and distributed international teams.
- Strong curiosity and motivation to stay ahead of the rapidly evolving AI security landscape.
Are you looking for an environment that values curiosity and commitment? Here, your contribution has real impact and individual growth is taken seriously.
Find with us the right opportunity to grow!
What you can expect from us
- Long‑term projects with national and international context.
- Opportunities to grow technically and professionally in AI and Cybersecurity domains.
- A people‑first culture, focused on transparency and trust.
- Teams that value ownership, collaboration, and stability.
- The opportunity to work on cutting‑edge AI security challenges with international teams.
Your next challenge might start here!
At Decskill, we are committed to equal opportunities and non-discrimination. We promote a culture of diversity and inclusion, where recruitment and career progression are based exclusively on talent, regardless of age, gender, ethnicity, race, nationality, or any other form of discrimination incompatible with human dignity.