OutSystems is a leading AI Development Platform built for the enterprise, and they are seeking a Senior Security Engineer to join their Application Security team. The role involves delivering security outcomes across their AI-powered low-code platform, managing security initiatives, and collaborating with various teams to enhance security practices.
Responsibilities:
- Independently drive security work across all phases of the SDLC, from early design and threat modeling through implementation, testing, and release
- Own delivery of moderately complex security projects or features, adjusting standard approaches as needed to achieve the intended outcome
- Partner with engineering and platform teams to secure AI-powered and agentic capabilities, ensuring security considerations are built in early rather than bolted on later
- Conduct focused security assessments of applications, APIs, internal services, and platform components using the appropriate depth and methodology for the risk
- Contribute to the development and adoption of secure-by-default patterns, guardrails, and paved roads that scale security without increasing friction
- Operate and improve security tooling by tuning signal quality, reducing noise, and identifying opportunities to improve effectiveness
- Build or extend security tooling and automation to eliminate manual or repetitive work
- Clearly communicate risks, tradeoffs, and recommendations to engineering partners in a way that supports informed decision-making
- Proactively identify gaps or inefficiencies in security processes and suggest practical improvements aligned with team goals
- Mentor junior engineers and new hires, helping them ramp up effectively and understand how Product Security operates at OutSystems
- Strengthen stakeholder relationships within your area of responsibility by being reliable, pragmatic, and outcome-oriented
Requirements:
- Proven experience in application security within modern, cloud-native environments
- Strong foundation in AppSec fundamentals, including secure design, threat modeling, vulnerability triage, and remediation
- Ability to independently deliver moderately complex security work end to end
- Comfortable working across application, cloud, and platform security within a defined scope
- Ability to write, understand, and review code, including building security automation and validating AI- or low-code-generated solutions
- Hands-on experience with AWS (required), Kubernetes, and microservices
- Clear understanding of penetration testing, red teaming, and purple teaming, and when to apply each
- Practical experience with AI-enabled and automated systems, including understanding how increased autonomy impacts security risk
- Hands-on use of AI-assisted development tools to speed up delivery while maintaining security and correctness
- Experience contributing to secure-by-default patterns, platform guardrails, and paved roads
- Proven ability to improve security tooling by reducing noise and increasing actionable findings
- Strong experience with AWS and exposure to Azure
- Background working on developer platforms, low-code platforms, or highly automated environments