Sr Engineer I, Product Security

NextGen Healthcare, Inc.

Atlanta (GA)

On-site

USD 150,000 - 230,000

Full time

10 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

NextGen Healthcare, Inc. is seeking a Senior Product Security Engineer to secure AI-powered features and scale the security program across product teams.

You will conduct security reviews, threat modeling, and build security tooling to integrate into CI/CD while collaborating with engineering, product, and legal teams. The role requires 5+ years in product or application security, strong knowledge of security testing methodologies, and experience with AI/LLM security considerations.

Qualifications

  • 5+ years of experience in product security, application security, or software engineering.
  • Experience with security testing methodologies and tools (static analysis, dynamic analysis, penetration testing).
  • Experience threat modeling or penetration testing AI/ML or LLM-backed applications, or participating in AI red-team exercises.
  • Experience building internal tooling or agentic automation on top of LLM APIs.

Responsibilities

  • Perform security reviews and threat modeling of product features and architectures.
  • Develop and maintain security tooling, guidelines, and standards for product development.
  • Provide security guidance and support to product teams throughout the software development lifecycle.
  • Research and evaluate new security technologies and solutions.
  • Integrate security tools into CI/CD and finetune rules to reduce false positives.
  • Write scripts to automate manual tasks.
  • Perform security reviews and threat modeling of AI/ML and LLM-backed features, including agentic systems, tool/function calling, retrieval-augmented generation (RAG) pipelines, and third-party model integrations.
  • Identify and help remediate AI-specific risks such as prompt injection, insecure output handling, training and inference data leakage, excessive agency, model and plugin supply chain compromise, and jailbreak or guardrail bypass.
  • Define and maintain secure-by-default patterns for AI development: input/output validation, least-privilege tool and data access for agents, sandboxing of model-generated code, tenant isolation, human-in-the-loop checkpoints, and prompt and system-instruction hygiene.
  • Build and run adversarial testing and AI red-teaming exercises against model-backed features; translate findings into reusable regression tests, evals, and detection coverage.
  • Establish guardrails, abuse monitoring, rate limiting, and logging for AI endpoints, and partner with detection and response teams on AI-specific incident playbooks.
  • Review the security and privacy posture of AI vendors, models, and MCP or plugin-style extensions before adoption, including data handling, retention, and fine-tuning commitments.
  • Contribute to internal AI usage policy and governance and help map controls to frameworks such as the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework.
  • Partner with ML/AI engineering, data, legal, and privacy teams to secure the model lifecycle end to end: data sourcing, training, evaluation, deployment, and monitoring.

Skills

Communication
Problem-solving
Independence
Cross-functional collaboration

Education

Bachelor's degree in Computer Science or related field

Tools

Static analysis tools
Dynamic analysis tools
Penetration testing tools

Job description

Job Description:

Senior Product Security Engineer will be responsible for conducting security assessments, implementing security best practices, and collaborating with product teams to ensure that our products meet the highest security standards. As AI becomes a core part of both our products and our engineering workflows, this role carries a dual mandate: securing the AI-powered features we ship and using AI to scale the reach and speed of our security program.

Job Responsibilities:

Core Product Security

  • Perform security reviews and threat modeling of product features and architectures.
  • Develop and maintain security tooling, guidelines, and standards for product development.
  • Provide security guidance and support to product teams throughout the software development lifecycle.
  • Research and evaluate new security technologies and solutions.
  • Integrate security tools into CI/CD and finetune rules to reduce false positives.
  • Write scripts to automate manual tasks.

AI Security

  • Perform security reviews and threat modeling of AI/ML and LLM-backed features, including agentic systems, tool/function calling, retrieval-augmented generation (RAG) pipelines, and third-party model integrations.
  • Identify and help remediate AI-specific risks such as prompt injection (direct and indirect), insecure output handling, training and inference data leakage, excessive agency, model and plugin supply chain compromise, and jailbreak or guardrail bypass.
  • Define and maintain secure-by-default patterns for AI development: input/output validation, least-privilege tool and data access for agents, sandboxing of model-generated code, tenant isolation, human-in-the-loop checkpoints, and prompt and system-instruction hygiene.
  • Build and run adversarial testing and AI red-teaming exercises against model-backed features; translate findings into reusable regression tests, evals, and detection coverage.
  • Establish guardrails, abuse monitoring, rate limiting, and logging for AI endpoints, and partner with detection and response teams on AI-specific incident playbooks.
  • Review the security and privacy posture of AI vendors, models, and MCP or plugin-style extensions before adoption, including data handling, retention, and fine-tuning commitments.
  • Contribute to internal AI usage policy and governance and help map controls to frameworks such as the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework.
  • Partner with ML/AI engineering, data, legal, and privacy teams to secure the model lifecycle end to end: data sourcing, training, evaluation, deployment, and monitoring.

AI-Assisted Security

  • Apply AI and LLM-based tooling to accelerate security work: triaging vulnerability and scanner findings, summarizing and prioritizing risk, drafting threat models, and reviewing code and configuration at scale.
  • Build and maintain AI-assisted automation and agentic workflows for repetitive security tasks such as intake and questionnaire triage, secure code review support, remediation guidance, detection rule authoring, and security documentation.
  • Reduce false positives by combining traditional static and dynamic analysis with AI-driven enrichment and correlation.
  • Establish guidance and guardrails for the secure use of AI coding assistants across engineering.
  • Measure and validate the accuracy of AI-assisted security tooling: build evals, track precision and recall, and keep a human review step where consequences are high.

Education Required:

  • Bachelor's degree in Computer Science, Engineering, or related field.

Experience Required:

  • 5+ years of experience in product security, application security, or software engineering.
  • Experience with security testing methodologies and tools (e.g., static analysis, dynamic analysis, penetration testing).
  • Experience threat modeling or penetration testing AI/ML or LLM-backed applications, or participating in AI red-team exercises.
  • Experience building internal tooling or agentic automation on top of LLM APIs.

Knowledge of:

  • Proficient in at least one programming language (e.g., Python, Java, C#). Strong knowledge of web and mobile security, cloud security, and cryptography and AI security. Working understanding of modern AI complex systems and how they are built and deployed: LLM APIs, prompting, embeddings and vector stores, RAG, agents and tool use, fine-tuning, and the security implications of each. Familiarity with AI security risks and reference frameworks such as the OWASP Top 10 for LLM Applications, MITRE ATLAS, or the NIST AI RMF.

Skill in:

  • Excellent communication and interpersonal skills. Strong problem-solving skills.

Ability to:

  • Work independently and manage multiple priorities in a fast-paced environment. Translate complex technical security concepts into clear recommendations for technical and non-technical audiences. Think critically and creatively to identify and mitigate security risks. Collaborate effectively with cross-functional teams, including engineering, product, and legal.

NextGen Healthcare is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Engineer - AI Focus
Senior Security Engineer - AI Focus

Euna Solutions • Atlanta (GA)

On-site
USD 140,000 - 210,000
Product Security Engineer - Team Lead
Product Security Engineer - Team Lead

Meta • Bellevue (WA)

On-site
USD 180,000 - 260,000
Sr Engineer I, Product Security
Sr Engineer I, Product Security

NextGen Healthcare, Inc. • Georgia

On-site
USD 110,000 - 150,000
Senior Lead AI Security Engineer
Senior Lead AI Security Engineer

JPMorganChase • Columbus (OH)

On-site
USD 125,000 - 160,000
Senior AI Product Security Engineer
Senior AI Product Security Engineer

NextGen Healthcare, Inc. • Atlanta (GA)

On-site
USD 150,000 - 230,000
AI-Application Security Engineer
AI-Application Security Engineer

Stifel Financial Corp. • St. Louis (MO)

On-site
USD 90,000 - 120,000
IT Security Analyst
IT Security Analyst

Fortegra • Jacksonville (FL)

On-site
USD 85,000 - 120,000
Senior Lead Security Engineer, AI
Senior Lead Security Engineer, AI

TwinThread • Columbus (OH)

On-site
USD 120,000 - 150,000
Information Technology Security Analyst
Information Technology Security Analyst

Brooksource • Allentown

On-site
USD 75,000 - 95,000
Senior Security Engineer, Product Security
Senior Security Engineer, Product Security

United States Digital Space LLC • United States

Remote
USD 140,000 - 190,000