SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: GBP 90,000 - 122,000 / annual
AlphaSense is seeking a Senior Product Security Engineer to lead the design and implementation of secure, scalable, and trustworthy products across its AI-native platform. The company provides market intelligence and AI-driven search to over 6,000 enterprise customers, including a majority of the S&P 500. Founded in 2011 and headquartered in New York with 2,000+ employees globally, AlphaSense recently acquired Tegus to expand its content and product capabilities.
You will work at the intersection of AI/ML security, secure architecture, threat modeling, and customer-facing assurance. Your responsibilities span five key areas:
**AI Security & Enablement (30%):** Architect and enforce security controls for AI/ML systems including model training, data pipelines, inference environments, and agentic workflows. Identify and mitigate AI-specific attack vectors such as prompt injection, data poisoning, model inversion, and model theft. Implement model provenance, integrity, and auditability controls. Align AI security with governance and compliance teams against frameworks like NIST AI RMF and the EU AI Act.
**Secure Architecture & Development Lifecycle (30%):** Embed security throughout the software and AI development lifecycle by partnering with architects, engineering, and product teams across AlphaSense's application and cloud ecosystems. Ensure security, privacy, and compliance by design. Define and maintain secure development standards, guidance, and best practices.
**Threat Modeling & Security Review (20%):** Lead threat modeling, secure design reviews, and risk assessments across the software development lifecycle. Build and maintain security automation and governance that integrates into development workflows.
**Customer-Facing Security Assurance (10%):** Produce customer-facing security assurance including security questionnaire responses, security whitepapers, and trust collateral that unblock enterprise deals. Represent product security in customer, cross-functional, and leadership discussions.
**Leadership (10%):** Mentor teams on secure coding, AI risk management, and secure design. Promote a security-first culture through advocacy, documentation, and training.
**Requirements:**
- 5–7+ years in product, application, or cloud security engineering
- Deep understanding of secure SDLC, threat modeling, and secure architecture design
- Ability to read and review code to inform threat models and design reviews
- Experience securing AI/ML pipelines, data workflows, and model-serving infrastructure, with working knowledge of AI/LLM security (prompt injection, model integrity, provenance)
- Proven expertise with cloud security concepts and best practices across multi-cloud environments
- Familiarity with DevSecOps and CI/CD environments
- Familiarity with encryption fundamentals — symmetric and asymmetric cryptography, TLS/mTLS, key management, and secrets handling
- Understanding of authentication and authorization patterns in modern applications: OAuth 2.0, OIDC, SAML, RBAC, and ABAC
- Demonstrated ability to drive cross-functional security initiatives — partnering with engineering, product, and compliance to embed security into roadmaps, influence architectural decisions, and align stakeholders across boundaries
**Nice to Have:**
- Proficiency in Python, Java, and/or JavaScript for security automation and tooling
- Container and orchestration security (Kubernetes runtime protection)
- Software supply chain security and artifact integrity verification
- Experience with bug bounty programs — triaging findings, driving root-cause analysis, and turning results into systemic security improvements
- Familiarity with compliance and governance frameworks (SOC 2, ISO 27001, NIST 800-53, NIST AI RMF)
- Certifications such as CKS, CISSP, CSSLP, or AI/ML security credentials