SlipstreamJobsFresh Startup & VC-Backed Jobs

AI Product Security Engineer

Forescout - United States - In-office

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Forescout is seeking an experienced Product Security Engineer to design, build, and scale security capabilities at the intersection of AI and cybersecurity. This is a highly technical, hands-on role focused on operating AI-assisted vulnerability management, product security automation, and secure-by-design engineering practices. You will act as a force multiplier across Product Management, Engineering, Platform Engineering, Cloud Operations, Compliance, and Security teams by embedding security directly into the software development lifecycle and leveraging AI to increase both security coverage and engineering velocity. Key responsibilities include: **AI-Powered Vulnerability Management for Secure SDLC**: Partner with architects to define secure architecture patterns. Build AI-driven solutions into CI/CD pipelines to accelerate vulnerability discovery, triage, prioritization, root cause analysis, remediation recommendations, and validation testing. Develop exploitability-aware prioritization models using business context, reachability, threat intelligence, and customer impact. Implement automated workflows for CVE, KEV, SBOM, SAST, DAST, Dependency Management, and SCA findings. **Product Security Operations**: Conduct threat modeling, design reviews, security assessments, and architecture reviews. Partner with development teams to identify and remediate security weaknesses. Participate in vulnerability and incident response activities. Develop dashboards and metrics measuring risk reduction, security maturity, and remediation performance. **Compliance & Regulatory Support**: Ensure security controls align with customer, certification, and government requirements including NIST SSDF, FedRAMP, ISO 27001, SOC 2, Common Criteria, and CRA/NIS2. Required qualifications: 5+ years in product security, application security, cloud security, DevSecOps, or security engineering. Demonstrated experience securing enterprise-scale software products and cloud services. Technical expertise in threat modeling, secure design reviews, vulnerability assessment, penetration testing, secure coding, incident response, and software supply chain security. Strong proficiency in Python, Java, Go, C/C++, or JavaScript/TypeScript. Hands-on experience with security tooling (Snyk, Wiz, Burp Suite, Tenable, GitHub Advanced Security, Veracode, Semgrep, SonarQube). Cloud infrastructure knowledge (Azure, AWS, Kubernetes, Containers, Terraform, IAM, API security). Hands-on experience using AI/LLM technologies in engineering or security workflows with understanding of prompt injection attacks, RAG security risks, AI model abuse, data poisoning, and AI governance controls. Preferred: CISSP, CSSLP, OSCP, or GIAC certification. Experience with AI red teaming, developer security platforms, SaaS/API security, and FedRAMP/government cloud environments.

Similar roles