Senior Product Security Engineer, AI ML

Norstella

Columbia (SC)

Remote

USD 180,000 - 240,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical benefits
HSA/FSA
Dental & Vision
Life & AD&D
401k with match
Disability coverage
Parental leave
Paid time off

Job summary

Norstella is seeking a Senior Product Security Engineer focused on AI/ML security to lead multi‑product security initiatives and mentor the Forge engineering team. You will shape DevSecOps practices, secure the autonomous SDLC, and govern the agentic security footprint across the platform and Sage KB ecosystem.

The role requires hands‑on experience with LLMs, agent orchestration tools, and regulatory compliance in life sciences, including HIPAA, GDPR, SOC 2, and FDA guidelines.

Qualifications

  • BA/BS degree or equivalent experience; AI/ML security focus preferred.
  • Typically 4+ years leading multi-product security programs with 1–2 years in AI/ML in production.
  • Strong knowledge of SDLC risk management and secure design for agentic AI systems.
  • Proficient in enterprise vulnerability management and automation strategies, including auto-remediation.

Responsibilities

  • Lead threat modeling across agent architectures, prompts pipelines, and security risk practices.
  • Lead secure development training across product groups with evolving standards.
  • Oversee vulnerability management, triage, and gating for multiple products.
  • Drive AI/ML supply chain risk assessments, including model providers and KB data governance.
  • Integrate security across CI/CD and multi-cloud platforms with auditable trails.
  • Act as IR lead for cross-product incidents and disclosure processes.
  • Lead AI/ML model security practices and safe design principles.
  • Govern SSDLC and embed controls for agentic development workflows.
  • Instrument observability and traceability for auditable agent decisions.

Skills

Threat modeling
CI/CD security
LLM security
SAST/SCA
Python
TypeScript
DevSecOps
Access control

Education

BA/BS degree
CISSP
OSWE
MLSecOps / AI Security Institute

Tools

LangGraph
CrewAI
Autogen
Semantic Kernel
Pinecone
Weaviate
Qdrant

Job description

Senior Product Security Engineer, AI ML

Company: Norstella

Location: Remote, United States

Date Posted: Sep 22, 2026

Employment Type: Full Time

Job ID: R-2134

Description
About Norstella:

Norstella is a premier and critical global life sciences data and AI solutions provider dedicated to improving patient access to life‑saving therapies. Norstella supports pharmaceutical and biotech companies across the full drug development lifecycle — from pipeline to patient. Our mission is simple: to help our clients bring therapies to market faster and more efficiently, ultimately impacting patient lives.

Norstella unites market‑leading brands - Citeline, Evaluate, MMIT, Panalgo, Skipta and The Dedham Group and delivers must‑have answers and insights, leveraging AI, for critical strategic, clinical, and commercial decision‑making. We help our clients:

  • Accelerate the drug development cycle
  • Assess competition and bring the right drugs to market
  • Make data driven commercial and financial decisions
  • Match and recruit patients for clinical trials
  • Identify and address barriers to therapies

Norstella serves most pharmaceutical and biotech companies around the world, along with regulators like the FDA, and payers. By providing critical proprietary data supporting AI‑driven workflows, Norstella helps clients make decisions faster and with greater confidence. Norstella’s investments in AI are transforming how data is consumed and decisions are made, disrupting inefficient legacy workflows and helping the industry become more efficient, innovative, and responsive to patient needs.

Job Description:

Leads multi‑product security efforts, develops the ProdSec team and mentors engineers, coordinating incident response, and shaping DevSecOps practices, with primary focus on securing Norstella's agentic SDLC platform (Forge) and its supporting knowledge‑base ecosystem (Sage). This engineer owns the security posture of the autonomous AI agent chain end‑to‑end: the platform itself, the prompts and orchestration layer, the proprietary domain data the agents consume, and — critically — the source code the agents produce. Acts as the senior security partner to the Forge engineering team, embedding security guardrails into every phase of the autonomous SDLC (Intake → Architect → Threat‑Modeling → Dev‑Planning → Dev → QA) so that AI‑generated code meets the same compliance, audit, and resilience standards as human‑written code in HIPAA, GDPR, SOC 2, and FDA 21 CFR Part 11 environments.

Responsibilities:
  • Leads threat modeling across complex architectures, including agent‑to‑agent communication graphs, tool‑use surfaces, MCP server boundaries, and prompt/RAG pipelines, and mentors engineers in risk analysis practices.
  • Leads secure development training across product groups — including AI‑assisted and AI‑generated coding workflows — and evolves standards based on industry trends, OWASP LLM Top 10, and emerging agentic‑AI threat research.
  • Leads vulnerability management for multiple products, setting priorities and ensuring timely resolution, and tunes the Forge Security Agent's SAST/SCA gating, severity thresholds, and triage‑LLM classification logic to keep auto‑remediation loops both effective and safe.
  • Leads supply chain risk assessments and drives API governance practices across product portfolios, with explicit ownership of the AI/ML supply chain — foundation model providers (Anthropic, others), Auth0, Snyk, Azure DevOps NPM feeds, vector databases, and the Sage KB seed data — including concentration‑risk monitoring and contingency planning.
  • Leads security integration across CI/CD and multi‑cloud platforms, mentoring engineers on automation, and ensures every agentic run produces a reconstructible audit trail sufficient to demonstrate reasonable judgment to SOC 2, HIPAA, GDPR, and Life Sciences auditors.
  • Technical IR lead overseeing cross‑product incidents, coordinates disclosure processes, and advises leadership, including incidents involving prompt injection, model jailbreak, agent privilege escalation, sensitive data leakage from KB stores, and compromised AI‑generated code reaching production.
  • Leads AI/ML model security practices across multiple teams and establishes safe design principles, including least‑privilege tool‑use, secrets handling for agent runtimes, PII/PHI sanitization in prompts and outputs, model‑output validation, and red‑team / adversarial‑input programs targeting the Forge agent chain.
  • Leads SSDLC governance initiatives, mentors teams on embedding controls, and validates adherence across product lines, with explicit accountability for the agentic SSDLC: ensuring the Threat Model Production Agent's output is consumed downstream, that the Forge Security Agent's fail‑open posture is risk‑tiered appropriately, and that human‑in‑the‑loop checkpoints are placed where judgment is genuinely required.
  • Designs and operates continuous security evaluation pipelines that benchmark agent runs across safety, compliance, and code‑quality dimensions, surfacing regressions in real time.
  • Defines acceptance criteria and security guardrails for AI‑generated code and agent outputs, ensuring policy compliance and alignment with business intent before production promotion.
  • Partners with Agentic Engineering to instrument observability, logging, and tracing across the full agent execution graph so every decision an agent makes is auditable, explainable, and defensible to regulators.
Qualifications:
  • Holds a BA/BS degree or equivalent experience; certifications such as CISSP, OSWE, or cloud security specialties preferred. AI/ML security credentials (e.g., AI Security Institute, MLSecOps, or equivalent) a strong plus.
  • Typically 4+ years of experience or equivalent leadership across multi‑product security programs, with at least 1–2 of those years applied to AI/ML or LLM‑powered systems in production.
  • Strong knowledge of managing SDLC risks across multiple teams and mentoring others in secure design, including agentic and AI‑assisted SDLC patterns where code authorship is partially delegated to LLM agents.
  • Proficient in enterprise vulnerability management, guiding priorities and automation strategies, including LLM‑mediated triage and auto‑remediation loops.
  • Strong knowledge of integrating security into complex CI/CD and cloud environments, including containerized agent runtimes, GPU‑accelerated inference endpoints, and serverless agent orchestration on AWS, GCP, or Azure.
  • Strong knowledge of secure development practices and setting engineering‑wide standards.
  • Proficient in designing and reviewing encryption and data protection strategies.
  • Proficient in automation in product pipelines and mentoring teams on efficiency.
  • Proficient in AI/ML security governance across multiple teams, including OWASP LLM Top 10, prompt injection / jailbreak defense, RAG poisoning, model‑output sanitization, and adversarial testing of agent chains.
  • Proficient in SSDLC governance, leading implementation and mentoring peers on embedding security into development processes, with demonstrated ability to apply SSDLC controls to non‑deterministic, agent‑driven development workflows.
  • Hands‑on experience with LLM‑powered applications (Claude, GPT‑4, Gemini, Llama, or equivalent), including prompt engineering, function/tool calling, and chain‑of‑thought orchestration — sufficient to security‑review them, not just consume them.
  • Working familiarity with at least one agentic framework or orchestration toolkit (LangGraph, CrewAI, Autogen, Semantic Kernel, MCP, or comparable), and the threat surface each one introduces.
  • Working knowledge of vector databases (Pinecone, Weaviate, Qdrant, pgvector) and retrieval‑augmented generation patterns, with an eye to KB poisoning, retrieval leakage, and access‑control failures.
  • Understanding of LLM evaluation methodologies — behavioral testing, hallucination detection, output grading, drift detection — applied to security and compliance properties of agent outputs.
  • Strong software engineering fundamentals in Python and/or TypeScript; able to read and contribute to production agent code, not just review it from a distance.
  • Compliance fluency in SOC 2, HIPAA, GDPR, and ideally FDA 21 CFR Part 11 — and the judgment to translate those frameworks into concrete controls for AI/ML and agentic systems.
  • Pharma, life sciences, or healthcare data experience (RWD/RWE, clinical trials, market access) is a strong plus given the Norstella product portfolio.
Benefits:
  • Medical and Prescription Drug Benefits
  • Health Savings Accounts (HSA) or Flexible Spending Accounts (FSA)
  • Dental & Vision Benefits
  • Basic Life and AD&D Benefits
  • 401k Retirement Plan with Company Match
  • Company Paid Short & Long‑Term Disability
  • Paid Parental Leave
  • Paid Time Off & Company Holidays
Our Guiding Principles for success at Norstella:
  • 01: Bold, Passionate, and Mission-First
  • 02: Integrity, Truth, and Reality
  • 03: Kindness, Empathy, and Grace
  • 04: Resilience, Mettle, and Perseverance
  • 05: Humility, Gratitude, and Learning

Please Note - All candidates must be authorized to work in the United States. We do not provide visa sponsorship or transfers. We are not currently accepting candidates who are on an OPT visa.

Sometimes the best opportunities are hidden by self-doubt. We disqualify ourselves before we have the opportunity to be considered. Regardless of where you came from, how you identify, or the path that led you here- you are welcome. If you read this job description and feel passion and excitement, we’re just as excited about you.

Norstella is an equal opportunity employer. All job applicants will receive equal treatment regardless of race, creed, color, religion, alienage or national origin, ancestry, citizenship status, age, physical or mental disability or handicap, medical condition, sex (including pregnancy and pregnancy‑related conditions), marital or domestic partner status, military or veteran status, gender, gender identity or expression, sexual orientation, genetic information, reproductive health decision making, or any other protected characteristic as established by federal, state, or local law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Product Security Engineer, AI ML
Senior Product Security Engineer, AI ML

Norstella • Baton Rouge (LA)

Remote
USD 180,000 - 230,000
Medical and Prescription Drug Benefits
HSA or FSA
Dental & Vision Benefits
+4
Senior Product Security Engineer, AI ML
Senior Product Security Engineer, AI ML

Norstella • Harrisburg

Remote
USD 140,000 - 205,000
Medical & prescription benefits
HSA or FSA
Dental & Vision benefits
+4
Senior Product Security Engineer, AI ML
Senior Product Security Engineer, AI ML

Norstella • Boston (MA)

Remote
USD 170,000 - 250,000
Medical benefits
HSA/FSA
Dental & Vision
+4
Senior Product Security Engineer, AI ML
Senior Product Security Engineer, AI ML

Norstella • Bismarck (ND)

Remote
USD 150,000 - 210,000
Medical benefits
401k match
Paid time off
Senior Product Security Engineer, AI ML
Senior Product Security Engineer, AI ML

Norstella • Nashville (TN)

Remote
USD 160,000 - 210,000
Medical and Prescription Benefits
HSA or FSA
401k with Company Match
+2
Senior Product Security Engineer, AI ML
Senior Product Security Engineer, AI ML

Norstella • Pierre (SD)

Remote
USD 140,000 - 180,000
Medical benefits
HSA/FSA
Dental & Vision
+4
Senior Product Security Engineer, AI ML
Senior Product Security Engineer, AI ML

Norstella • Montgomery (AL)

Remote
USD 140,000 - 180,000
Medical benefits
Dental & Vision
401k with match
+2
Senior Product Security Engineer, AI ML
Senior Product Security Engineer, AI ML

Norstella • Des Moines (IA)

Remote
USD 150,000 - 190,000
Medical benefits
401k with match
Paid time off
Senior Product Security Engineer, AI ML
Senior Product Security Engineer, AI ML

Norstella Group • United States

Remote
USD 180,000 - 260,000
Medical and Prescription Benefits
HSA / FSA
Dental & Vision Benefits
+4
Senior Forge AI Engineer
Senior Forge AI Engineer

Norstella • Saint Paul (MN)

Remote
USD 180,000 - 240,000