Security AI Engineer
- Location: Lisbon, Porto (Portugal)
- Work arrangement: hybrid
- Employment type: Full Time
- Seniority: senior
- Posted:
Job description
ABOUT THE OPPORTUNITY
We are looking for a Security AI Engineer to join a large, highly regulated organization undergoing significant transformation in the adoption of Artificial Intelligence and Generative AI.
This is a security governance and engineering role focused on enabling AI adoption safely rather than slowing innovation down. You will work as part of the second line of defense, defining security requirements, challenging technical designs, assessing AI-related risks, and helping technology and development teams implement appropriate controls.
The organization is expanding AI across two major areas: business use cases involving platforms, APIs, AI agents, integrations and self-hosted/open-source models; and AI-assisted software development, including IDE assistants, code generation, refactoring and automated testing.
The role is Hybrid, with 3 days per week in the office and 2 days remote, and can be based in Lisbon or Porto, Portugal.
PROJECT & CONTEXT
Your mission will be to help establish a consistent security and governance model for the adoption of AI, GenAI and Large Language Models (LLMs).
You will define and maintain technical security guardrails, standards and requirements covering areas such as:
- AI/GenAI platforms, APIs, agents and integrations.
- Open-source and self-hosted LLMs.
- AI-assisted software development and coding assistants.
- Runtime controls, including content filtering and input/output validation.
- AI agent permissions, tool access and privilege limitation.
- Secure AI-generated code through SAST and SCA controls.
- Data Loss Prevention (DLP), data redaction and tokenization.
- Secrets management and prevention of sensitive information exposure.
- Threat modeling and security reviews for AI architectures.
- Risk assessments by AI tool, model, data classification and use case.
- Monitoring security controls, risk metrics, deviations and remediation actions.
You will regularly review and challenge technical proposals from engineering teams, helping ensure that AI solutions meet the required security standards before and after implementation.
WHAT WE'RE LOOKING FOR (Required)
- Strong cybersecurity foundation in at least one of the following areas:
- Application Security
- Cloud Security
- DevSecOps
- Practical understanding of Microsoft Azure security concepts, including:
- Managed Identities
- IAM / RBAC
- Secrets management
- Network segmentation
- Cloud security architecture
- Hands-on exposure to LLMs, Generative AI or AI-enabled applications.
- Ability to assess technical architectures and identify security risks related to AI platforms, APIs, agents and integrations.
- Understanding of secure software development practices and security controls such as SAST and SCA.
- Understanding of data protection controls, including DLP, redaction, tokenization and secrets management.
- Ability to translate technical security risks into clear and pragmatic requirements for engineering and business stakeholders.
- An enablement-oriented security mindset: helping teams adopt technology safely rather than simply blocking initiatives.
- Strong communication, analytical and stakeholder-management skills.
- Interest in continuously developing expertise in the emerging AI security landscape.
- Portuguese: fluent/professional proficiency required.
- English: C1 level or higher required.
- Availability to work 3 days per week from the Lisbon or Porto office.
NICE TO HAVE (Preferred)
- Knowledge of established AI security and governance frameworks, particularly:
- OWASP Top 10 for LLM Applications 2025.
- NIST AI Risk Management Framework (AI RMF 1.0) and its Generative AI guidance.
- MITRE ATLAS, including its current AI adversary tactics, techniques and mitigations knowledge base.
- Google Secure AI Framework (SAIF / SAIF 2.0), including security considerations for AI agents.
- Hands-on security experience with APIs, containers, Kubernetes, Infrastructure as Code (IaC) or cloud-native environments.
- Experience performing LLM or AI agent red teaming, adversarial testing, prompt-injection testing or evaluating guardrail technologies.
- Familiarity with MLOps/LLMOps, machine-learning pipelines and data pipeline security.
- Knowledge of European regulatory and governance requirements such as the EU AI Act, GDPR/RGPD, DORA or EIOPA frameworks.
- Previous experience in financial services, insurance, banking or another highly regulated industry.
- Relevant cybersecurity certifications such as OSCP or CEH.
- Microsoft certifications such as AZ-500: Azure Security Engineer Associate or AI-102: Azure AI Engineer Associate.
- AI security or governance certifications and standards exposure, including ISO/IEC 42001 or relevant ISACA AI security/governance credentials.
Skills
- apis
- containers
- devsecops
- gdpr
- iam
- infrastructure_as_code
- kubernetes
- llm
- microsoft azure
- mlops
- sast
Languages
EN, PT
Apply
Open this job in our interactive board to apply, save it, or sign up for matched alerts on similar roles.
View & apply