Staff Security Engineer, AI & Application Security

Marcura

United States

Hybrid

USD 150,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive salary and bonus
Inclusive onboarding experience
Marcura Wellness Zone
Global opportunities
Diverse, supportive work culture

Job summary

Marcura is seeking a Staff Security Engineer for AI & Application Security. You will own security engineering end-to-end, directly perform penetration testing and AI red team exercises, and define secure-by-design patterns for LLM and agentic systems.

You will govern architecture reviews, risk prioritisation, and collaboration with product, engineering, data and operations teams. You will manage external testing partnerships (MDR) and internal testing programs, ensuring security is integrated

Qualifications

  • 8+ years total experience in security engineering across offensive and defensive domains.
  • At least 4 years hands-on offensive experience: leading and executing tests across web, APIs, cloud, networks.
  • Defensive engineering experience: hardening cloud and application environments, building or tuning detections.
  • Proven experience securing LLM or AI systems in production, including prompt injection, jailbreaks, data exfiltration.
  • Experience as a first, sole or founding security hire, or building a security capability from a standing start.
  • Track record influencing architecture and design decisions across engineering and product teams, not only reporting findings.
  • Experience supporting or leading security incident response in a production environment.
  • Experience owning MDR or managed SOC provider — onboarding telemetry, validating and tuning detection coverage.
  • Experience scoping, commissioning external penetration tests, and integrating third party findings into remediation.
  • Experience in regulated B2B, fintech, maritime or logistics environment preferred.

Responsibilities

  • Define security strategy, roadmap and prioritisation for the company.
  • Lead secure architecture and design reviews across products and cloud.
  • Advise on AI and LLM security and build an enterprise-wide security framework.
  • Develop and maintain security standards for AI/LLM systems.
  • Manage internal penetration testing programmes and external pentest ownership.
  • Oversee AI red teaming, adversarial testing and defensive hardening.
  • Harden applications and cloud infrastructure; implement identity and data protection controls.
  • Coordinate MDR partnership (eSentire) and validate detections and response.
  • Drive detection engineering, incident response and remediation processes.
  • Ensure third-party, vendor and model assurance aligns with risk appetite.
  • Foster security culture and enable engineering teams through tooling and guidance.

Skills

Offensive testing
Defensive engineering
LLM security
Penetration testing
Red teaming
Cloud security
Data protection
Security governance
Threat modeling
Threat hunting

Job description

The Staff Security Engineer, AI & Application Security is the first and only dedicated security engineering hire at Marcura, and is accountable for establishing the company's security engineering capability end to end. Because this is currently the single role focused wholly on security, the mandate is deliberately broad and deliberately hands on: it spans offensive assurance, defensive engineering, secure architecture and technical governance across applications, APIs, cloud infrastructure and the group's growing and varied estate of large language models — commercial APIs, hosted models, and internally integrated AI features. The role exists to give Marcura an independent, evidence based and continuously improving view of its technical risk, and to make secure delivery the default rather than an afterthought. The role holder personally executes penetration testing and AI red team exercises, designs and hardens defensive controls, reviews architecture early in the delivery lifecycle, defines secure by design patterns for LLM and agentic systems, and acts as trusted advisor to product, engineering, data and operations teams adopting AI. The role operates within a hybrid model: Marcura retains eSentire as its Managed Detection and Response (MDR) partner and commissions independent external penetration testing, so the role holder is not expected to build a security operations centre or to be the sole source of assurance. Instead, the role holder owns these partnerships technically — directing them, tuning and validating their output, closing the gaps they do not cover, and ensuring internal and external testing are complementary rather than duplicative. Critically, the role owns prioritisation: with finite capacity in a single headcount, the role holder is expected to make explicit, defensible judgements about what Marcura tackles in house, what is deferred, and what is delivered through partners, and to build the case for further investment as the function matures.

Responsibilities:
1. Security Strategy, Roadmap and Prioritisation:
2. Secure Architecture and Design Review:
3. AI and LLM Security Advisory:
4. AI Security Framework and Standards:
5. Internal Penetration Testing Programme:
6. External Penetration Test Ownership:
7. Hands On Offensive Testing and Red Teaming:
8. AI Red Teaming and Adversarial Testing:
9. Application and Cloud Security Hardening:
10. Identity, Access and Data Protection:
11. MDR Partnership Ownership (eSentire):
12. Detection Engineering and Incident Response:
13. Vulnerability Management and Remediation Ownership:
14. Security Tooling and Automation:
15. Third Party, Vendor and Model Assurance:
16. Engineering Enablement and Security Culture:
17. Documentation, Metrics and Leadership Reporting:

No specific degree or certification is required for this role. A degree in Computer Science, Information Security or Engineering is welcome but is not a filter, and neither is any particular certification.

What we are looking for instead is evidence of having found real vulnerabilities in real systems. Candidates should be able to walk us through bugs they personally discovered, how they found them, why they mattered, and what was done about them. Any of the following are strong, credible signals:

  • Vulnerabilities found in production systems during professional testing engagements, described in technical depth.
  • Published CVEs, coordinated disclosures, or security advisories.
  • Bug bounty findings with a track record on recognised platforms or private programmes.
  • Original security research, technical writeups, conference talks, or open source security tooling.
  • Strong competitive CTF results, particularly in web, cloud, or AI categories.
  • Novel prompt injection, jailbreak or agent abuse findings against real LLM deployments.

Certifications such as OSCP, OSEP, OSWE, GXPN, CRTO, CISSP or cloud security specialties are a useful signal of structured knowledge and are welcome, but they are explicitly not a substitute for a demonstrable history of finding and proving real bugs, and their absence will not count against a candidate who can show that history.

  • 8+ years total experience in security engineering, spanning both offensive and defensive work rather than one exclusively.
  • At least 4 years hands on offensive experience: scoping, leading and personally executing penetration tests and red team exercises across web applications, APIs, cloud environments and internal networks.
  • Demonstrable defensive engineering experience: hardening cloud and application environments, building or tuning detections, and designing identity, access and data protection controls.
  • Proven experience assessing and securing LLM or AI systems in production, including prompt injection, jailbreaks, insecure output handling, data exfiltration and tool or agent abuse.
  • Experience as a first, sole or founding security hire, or otherwise building a security capability from a standing start with minimal supervision and constrained resources.
  • Track record of influencing architecture and design decisions across engineering and product teams, not only reporting findings.
  • Experience supporting or leading security incident response in a production environment.
  • Experience owning and getting value from an MDR or managed SOC provider — onboarding telemetry, validating and tuning detection coverage, and holding the provider to account — rather than only consuming its alerts.
  • Experience scoping, commissioning and challenging external penetration tests, and integrating third party findings into an internal remediation process.
  • Experience in a regulated B2B, fintech, maritime or logistics environment preferred.
  • Competitive Salary and Bonus: We reward your expertise and contributions.
  • Inclusive Onboarding Experience: Our onboarding program is designed to set you up for success right from day one.
  • Marcura Wellness Zone: We value your work-life balance and well-being.
  • Global Opportunities: Be part of an ambitious, expanding company with a local touch.
  • Diverse, Supportive Work Culture: We’re committed to inclusion, diversity, and a sense of belonging for all team members.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Security Engineer: AI & App Security Leader
Staff Security Engineer: AI & App Security Leader

Marcura • United States

Hybrid
USD 150,000 - 210,000
Competitive salary and bonus
Inclusive onboarding experience
Marcura Wellness Zone
+2
Security Engineer, Application Security
Security Engineer, Application Security

Mercor • New York (NY), San Francisco (CA)

On-site
USD 120,000 - 160,000
Security Engineer
Security Engineer

DataVisor • Mountain View (CA)

Hybrid
USD 120,000 - 150,000
Medical, dental, vision insurance
401(k) retirement savings plan
Discretionary PTO + holidays
+1
AI Security Engineer AI Security Unit
AI Security Engineer AI Security Unit

Check Point Software Technologies • Washington

On-site
USD 135,000 - 195,000
Product Security Engineer
Product Security Engineer

United States Digital Space LLC • United States

Hybrid
USD 120,000 - 160,000
Medical/Rx Insurance
401(k) Retirement Savings Plan
Employee Stock Participation Plan
+1
Senior Engineer, Application Security
Senior Engineer, Application Security

Namely • United States

Hybrid
USD 120,000 - 160,000
Bonus
Staff+ Security Engineer, Developer Tools
Staff+ Security Engineer, Developer Tools

United States Digital Space LLC • San Mateo (CA)

On-site
USD 200,000 - 300,000
Healthcare coverage
Mental health support
Parental leave
+3
Security Engineer
Security Engineer

METR • Berkeley (CA)

Hybrid
USD 285,000 - 504,000
Catered meals
Relocation stipend
Unlimited PTO
+5
Engineering Manager, Application Security
Engineering Manager, Application Security

Qualia • Austin (TX)

On-site
USD 180,000 - 240,000
Medical, Dental & Vision health plans
Competitive salary & equity
Flexible schedules
+3
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent • Tysons (VA)

Hybrid
USD 120,000 - 160,000
Bonus
Competitive benefits