Get more replies from employers
Send a job-specific resume in minutes.
Marcura is seeking a Staff Security Engineer for AI & Application Security. You will own security engineering end-to-end, directly perform penetration testing and AI red team exercises, and define secure-by-design patterns for LLM and agentic systems.
You will govern architecture reviews, risk prioritisation, and collaboration with product, engineering, data and operations teams. You will manage external testing partnerships (MDR) and internal testing programs, ensuring security is integrated
The Staff Security Engineer, AI & Application Security is the first and only dedicated security engineering hire at Marcura, and is accountable for establishing the company's security engineering capability end to end. Because this is currently the single role focused wholly on security, the mandate is deliberately broad and deliberately hands on: it spans offensive assurance, defensive engineering, secure architecture and technical governance across applications, APIs, cloud infrastructure and the group's growing and varied estate of large language models — commercial APIs, hosted models, and internally integrated AI features. The role exists to give Marcura an independent, evidence based and continuously improving view of its technical risk, and to make secure delivery the default rather than an afterthought. The role holder personally executes penetration testing and AI red team exercises, designs and hardens defensive controls, reviews architecture early in the delivery lifecycle, defines secure by design patterns for LLM and agentic systems, and acts as trusted advisor to product, engineering, data and operations teams adopting AI. The role operates within a hybrid model: Marcura retains eSentire as its Managed Detection and Response (MDR) partner and commissions independent external penetration testing, so the role holder is not expected to build a security operations centre or to be the sole source of assurance. Instead, the role holder owns these partnerships technically — directing them, tuning and validating their output, closing the gaps they do not cover, and ensuring internal and external testing are complementary rather than duplicative. Critically, the role owns prioritisation: with finite capacity in a single headcount, the role holder is expected to make explicit, defensible judgements about what Marcura tackles in house, what is deferred, and what is delivered through partners, and to build the case for further investment as the function matures.
No specific degree or certification is required for this role. A degree in Computer Science, Information Security or Engineering is welcome but is not a filter, and neither is any particular certification.
What we are looking for instead is evidence of having found real vulnerabilities in real systems. Candidates should be able to walk us through bugs they personally discovered, how they found them, why they mattered, and what was done about them. Any of the following are strong, credible signals:
Certifications such as OSCP, OSEP, OSWE, GXPN, CRTO, CISSP or cloud security specialties are a useful signal of structured knowledge and are welcome, but they are explicitly not a substitute for a demonstrable history of finding and proving real bugs, and their absence will not count against a candidate who can show that history.