Mirantis is the Kubernetes-native AI infrastructure company, enabling organizations to build and operate scalable, secure, and sovereign infrastructure for modern AI applications. The Senior AI Security Engineer will secure and enable Mirantis' portfolio of products and services, guiding the secure adoption and deployment of AI technologies across products and platforms.
Responsibilities:
- Secure Products, Infrastructure & AI Platforms
- Design, implement, and maintain security controls across applications, infrastructure, CI/CD pipelines, and AI enabled services
- Support engineering teams in the secure deployment and operation of AI capabilities, including LLM integrations, intelligent agents, and AI assisted development tooling
- Embed security requirements aligned with SOC 2, ISO 27001, and internal standards
- Drive adoption and operationalization of security tooling including SAST, DAST, container scanning, IaC security, and dependency analysis tooling
- Integrate automated security testing into the SDLC to enable secure-by-design development
- Partner with engineering and product teams to evaluate and support the adoption of new technologies, including AI platforms, LLM services, and automation frameworks
- Provide architectural guidance to ensure new systems and integrations meet security, reliability, and scalability requirements
- Help establish best practices for deploying AI driven services and automation systems within Mirantis infrastructure
- Lead application security reviews, threat modeling, vulnerability assessments, and penetration testing
- Validate and prioritize findings based on exploitability and business impact
- Partner with engineering teams to ensure timely, measurable remediation
- Proactively identify and demonstrate security weaknesses to improve overall product resilience
- Assess risks associated with AI enabled features, automation systems, and integrations with external services
- Support investigation of product and infrastructure security incidents
- Contribute to root cause analysis and durable remediation strategies
- Identify systemic control gaps and implement long-term risk mitigation measures
- Assist in evaluating risks associated with automated systems, AI integrations, and emerging technologies adopted across Mirantis products
- Support product level security reviews and audit activities
- Coordinate evidence collection and control validation for SOC 2, ISO 27001, and enterprise requirements
- Translate compliance requirements into actionable engineering controls
- Ensure that new technologies and AI enabled capabilities align with enterprise security and governance standards
- Develop and maintain security expertise across multiple Mirantis products
- Standardize security practices and tooling across teams
- Strengthen program scalability and reduce single-point-of-failure risk
- Contribute to the development of secure architecture patterns and technology standards for products and platforms across Mirantis
- Champion secure design principles and modern application security practices
- Provide actionable guidance during architecture and code reviews
- Drive continuous improvement and automation across the SDLC
- Support engineering teams adopting AI tools, LLM services, and modern development platforms, ensuring they are deployed securely and responsibly
Requirements:
- 5+ years of experience in product security, application security, or security engineering
- Strong knowledge of common vulnerabilities (OWASP Top 10, SANS Top 25) and secure development practices
- Demonstrated experience with manual penetration testing, threat modeling, and exploitation techniques
- Hands-on experience with security tooling and automation, including: SAST / DAST tooling and CI/CD integration, Container image scanning (e.g., Trivy, Grype, Anchore), IaC security (e.g., Terraform, Helm, KICS, Checkov), Dependency and software supply chain security tools
- Experience with vulnerability management platforms and remediation workflows
- Experience working with containerized environments, Kubernetes, and cloud platforms
- Proven ability to integrate and automate security controls within CI/CD pipelines
- Strong collaboration and communication skills across engineering and product teams
- Experience supporting SOC 2, ISO 27001, or similar compliance frameworks
- Familiarity with AI technologies, LLM services, or intelligent automation platforms is a plus
- Relevant certifications (OSCP, OSEP, OSWE, GPEN, GWEB, GWAPT, GCSA) strongly preferred
- Proficiency in scripting or programming (Go, Python, or similar) is a plus