Sr Engineer I, Product Security

NextGen
  • Georgia
    18 days ago

    Job Description

    Job Description:

    Senior Product Security Engineer will be responsible for conducting security assessments, implementing security best practices, and collaborating with product teams to ensure that our products meet the highest security standards. As AI becomes a core part of both our products and our engineering workflows, this role carries a dual mandate: securing the AI-powered features we ship and using AI to scale the reach and speed of our security program.

    Job Responsibilities:


    Core Product Security

    • Perform security reviews and threat modeling of product features and architectures.
    • Develop and maintain security tooling, guidelines, and standards for product development.
    • Provide security guidance and support to product teams throughout the software development lifecycle.
    • Research and evaluate new security technologies and solutions.
    • Integrate security tools into CI/CD and finetune rules to reduce false positives.
    • Write scripts to automate manual tasks.

    AI Security

    • Perform security reviews and threat modeling of AI/ML and LLM-backed features, including agentic systems, tool/function calling, retrieval-augmented generation (RAG) pipelines, and third-party model integrations.
    • Identify and help remediate AI-specific risks such as prompt injection (direct and indirect), insecure output handling, training and inference data leakage, excessive agency, model and plugin supply chain compromise, and jailbreak or guardrail bypass.
    • Define and maintain secure-by-default patterns for AI development: input/output validation, least-privilege tool and data access for agents, sandboxing of model-generated code, tenant isolation, human-in-the-loop checkpoints, and prompt and system-instruction hygiene.
    • Build and run adversarial testing and AI red-teaming exercises against model-backed features; translate findings into reusable regression tests, evals, and detection coverage.
    • Establish guardrails, abuse monitoring, rate limiting, and logging for AI endpoints, and partner with detection and response teams on AI-specific incident playbooks.
    • Review the security and privacy posture of AI vendors, models, and MCP or plugin-style extensions before adoption, including data handling, retention, and fine-tuning commitments.
    • Contribute to internal AI usage policy and governance and help map controls to frameworks such as the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework.
    • Partner with ML/AI engineering, data, legal, and privacy teams to secure the model lifecycle end to end: data sourcing, training, evaluation, deployment, and monitoring.

    AI-Assisted Security

    • Apply AI and LLM-based tooling to accelerate security work: triaging vulnerability and scanner findings, summarizing and prioritizing risk, drafting threat models, and reviewing code and configuration at scale.
    • Build and maintain AI-assisted automation and agentic workflows for repetitive security tasks such as intake and questionnaire triage, secure code review support, remediation guidance, detection rule authoring, and security documentation.
    • Reduce false positives by combining traditional static and dynamic analysis with AI-driven enrichment and correlation.
    • Establish guidance and guardrails for the secure use of AI coding assistants across engineering.
    • Measure and validate the accuracy of AI-assisted security tooling: build evals, track precision and recall, and keep a human review step where consequences are high.

    Education Required:

    • Bachelor's degree in Computer Science, Engineering, or related field.

    Experience Required:

    • 5+ years of experience in product security, application security, or software engineering.
    • Experience with security testing methodologies and tools (e.g., static analysis, dynamic analysis, penetration testing).
    • Experience threat modeling or penetration testing AI/ML or LLM-backed applications, or participating in AI red-team exercises.
    • Experience building internal tooling or agentic automation on top of LLM APIs.

    Knowledge of:

    • Proficient in at least one programming language (e.g., Python, Java, C#). Strong knowledge of web and mobile security, cloud security, and cryptography and AI security.  Working understanding of modern AI complex systems and how they are built and deployed: LLM APIs, prompting, embeddings and vector stores, RAG, agents and tool use, fine-tuning, and the security implications of each. Familiarity with AI security risks and reference frameworks such as the OWASP Top 10 for LLM Applications, MITRE ATLAS, or the NIST AI RMF.

    Skill in:

    • Excellent communication and interpersonal skills. Strong problem-solving skills.

    Ability to:

    • Work independently and manage multiple priorities in a fast-paced environment. Translate complex technical security concepts into clear recommendations for technical and non-technical audiences. Think critically and creatively to identify and mitigate security risks. Collaborate effectively with cross-functional teams, including engineering, product, and legal.

    NextGen Healthcare is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

    Numbers & Facts

    LocationGeorgia

    Skills

    • Application Programming Interface (API)unmatched
    • Applications Securityunmatched
    • Artificial Intelligence (AI)unmatched
    • Automationunmatched
    • Best Practicesunmatched
    • Cloud Computingunmatched
    • Code Reviewsunmatched
    • Communication Skillsunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Continuous Deployment/Deliveryunmatched
    • Continuous Integrationunmatched
    • Cross-Functionalunmatched
    • Cryptographyunmatched
    • Diversityunmatched
    • Dynamic Analysisunmatched
    • Establish Prioritiesunmatched
    • Healthcareunmatched
    • Injectionsunmatched
    • Input/Outputunmatched
    • Internet Securityunmatched
    • Interpersonal Skillsunmatched
    • Javaunmatched
    • Legalunmatched
    • MCP - Microsoft Certified Professionalunmatched
    • Machine Toolunmatched
    • Microsoft C# (C Sharp)unmatched
    • Model Reviewunmatched
    • Multitaskingunmatched
    • Penetration Testingunmatched
    • Privacy Controlsunmatched
    • Problem Solving Skillsunmatched
    • Product Developmentunmatched
    • Product Engineeringunmatched
    • Product Supportunmatched
    • Programming Languagesunmatched
    • Python Programming/Scripting Languageunmatched
    • Quality Assurance Methodologyunmatched
    • Regression Testingunmatched
    • Riskunmatched
    • Risk Managementunmatched
    • Risk Management Framework (RMF)unmatched
    • Scripting (Scripting Languages)unmatched
    • Security Analysisunmatched
    • Security Attacksunmatched
    • Software Development Lifecycle (SDLC)unmatched
    • Software Engineeringunmatched
    • Standards Developmentunmatched
    • Static Analysisunmatched
    • Supply Chainunmatched
    • Test Toolsunmatched
    • Testingunmatched
    • Threat Modelingunmatched
    • Traffic Shapingunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Vulnerability Scannersunmatched
    • Web Client Plug-insunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder