Lead AI Security Engineer-APS
Responsibilities
About the Role-
We are seeking a Lead AI Security Engineer to drive the security of next-generation AI systems, GenAI platforms, LLM-powered applications, and AI-enabled enterprise solutions. The role combines Artificial Intelligence, secure software engineering, and offensive application security to identify, assess, and mitigate risks across AI applications and modern software ecosystems.
The ideal candidate is a hands-on AI/software engineer who can build and secure AI systems, apply AI for vulnerability discovery and code analysis, and use offensive security techniques to validate real-world risk. This role is focused on securing AI-led applications and platforms rather than performing traditional infrastructure penetration testing.
Key ResponsibilitiesAI Security & AI Red Teaming· Lead AI security assessments for GenAI applications, LLM integrations, AI agents, RAG architectures, and AI-powered enterprise platforms.
· Perform AI red teaming to identify prompt injection, jailbreaks, indirect prompt attacks, data leakage, insecure tool use, agent abuse, RAG poisoning, and model interaction risks.
· Design adversarial test cases and evaluation methods to validate AI system resilience, trust boundaries, and guardrail effectiveness.
· Assess AI application flows, model input/output handling, retrieval layers, plugins/tools, orchestration components, and data exposure risks.
· Define practical mitigation patterns for AI risks, including secure prompt design, policy controls, input/output validation, grounding checks, logging, monitoring, and abuse prevention.
AI Engineering & Security Automation· Build AI-powered security automation for vulnerability discovery, source code analysis, threat analysis, test generation, and remediation acceleration.
· Develop reusable frameworks, evaluation harnesses, guardrail testing utilities, and workflow automation for secure AI development.
· Integrate AI security validations into SDLC, DevSecOps, CI/CD, SAST, DAST, and code review pipelines.
· Experiment with frontier AI models and emerging AI frameworks to create scalable security assessment capabilities.
· Partner with product engineering teams to embed secure AI engineering practices from design through production.
Application Security & Offensive Validation· Conduct secure design reviews, threat modeling, code reviews, and vulnerability assessments for AI-led applications, APIs, microservices, and cloud-native platforms.
· Use offensive security techniques to validate exploitability, business impact, and remediation effectiveness.
· Apply knowledge of OWASP Top 10, OWASP API Security, CWE, CVE, CVSS, MITRE ATT&CK, and application security testing methodologies.
· Use tools such as Burp Suite, OWASP ZAP, Nmap, Wireshark, Metasploit, Nessus, Kali Linux, and relevant AI security testing utilities where applicable.
· Collaborate with engineering and architecture teams to prioritize fixes and strengthen secure coding practices.
Technical Leadership· Lead AI security initiatives across multiple engineering and cybersecurity stakeholders.
· Define standards, playbooks, testing methodologies, and secure AI development guidelines.
· Mentor engineers and security practitioners on AI security, secure coding, and practical AppSec techniques.
· Contribute to security strategy for responsible, secure, and scalable AI adoption across enterprise systems.
Profile required
· Strong hands-on experience with GenAI, LLMs, AI agents, RAG architectures, embeddings, vector databases, and AI application patterns.
· Experience developing AI-powered applications, AI workflows, agents, copilots, or automation solutions using modern AI frameworks and APIs.
· Good understanding of AI security risks such as prompt injection, jailbreaks, data leakage, malicious retrieval, insecure tool execution, model abuse, and adversarial testing.
· Experience with LLM evaluation, guardrail testing, responsible AI controls, model interaction security, and AI governance concepts.
· Ability to translate AI security research into practical engineering controls and testing approaches.
Software Engineering· 8+ years of experience across software engineering, AI engineering, cybersecurity engineering, or application security.
· Strong development experience in Python, Java, Go, JavaScript/TypeScript, C#, or similar languages.
· Experience building APIs, microservices, cloud-native applications, automation frameworks, and enterprise-grade software solutions.
· Strong understanding of secure SDLC, DevSecOps, CI/CD, automated testing, Git workflows, and engineering best practices.
Offensive Security / Application Security· Practical knowledge of penetration testing, SAST, DAST, secure code review, threat modeling, and vulnerability validation.
· Understanding of web application security, API security, authentication, authorization, HTTP, TCP/IP networking, and common exploitation techniques.
· Hands-on exposure to tools such as Burp Suite, OWASP ZAP, Nmap, Metasploit, Nessus, Wireshark, Kali Linux, or equivalent platforms.
· Ability to assess vulnerabilities, explain real-world impact, and work with engineering teams to implement effective remediation.
Cloud, Platform & Enterprise Security· Experience securing AI workloads or applications on Azure, AWS, or GCP.
· Knowledge of Kubernetes, OpenShift, Docker/container security, secrets management, identity security, and cloud security controls.
· Exposure to configuration reviews against CIS benchmarks and relevant enterprise security standards.
Preferred Qualifications· Experience securing GenAI platforms, AI agents, copilots, LLM applications, or AI-driven cybersecurity products.
· Experience building AI-assisted security tooling, AI-based code analysis systems, or automated security testing platforms.
· Certifications such as AI security/red teaming certifications, OSCP, OSWE, GWAPT, CISSP, CSSLP, GIAC, or equivalent practical experience.
· Background in vulnerability research, AI red teaming, application security research, or secure AI architecture.
Ideal Candidate Profile· AI-first engineer who understands how to build, test, and secure AI systems.
· Strong software developer with the ability to create scalable tools, automation, and secure engineering patterns.
· Practical AppSec/offensive security mindset with enough hands-on depth to validate vulnerabilities and guide remediation.
· Comfortable working with architects, developers, cybersecurity experts, and leadership stakeholders.
· Curious, experimental, self-driven, and comfortable operating in fast-evolving AI and cybersecurity domains.
Why join us
We are committed to creating a diverse environment and are proud to be an equal opportunity employer. All qualified applicants receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.
Business insight
At Société Générale, we are convinced that people are drivers of change, and that the world of tomorrow will be shaped by all their initiatives, from the smallest to the most ambitious. Whether you’re joining us for a period of months, years or your entire career, together we can have a positive impact on the future. Creating, daring, innovating, and taking action are part of our DNA. If you too want to be directly involved, grow in a stimulating and caring environment, feel useful on a daily basis and develop or strengthen your expertise, you will feel right at home with us!
Still hesitating?
You should know that our employees can dedicate several days per year to solidarity actions during their working hours, including sponsoring people struggling with their orientation or professional integration, participating in the financial education of young apprentices, and sharing their skills with charities. There are many ways to get involved.
We are committed to support accelerating our Group’s ESG strategy by implementing ESG principles in all our activities and policies. They are translated in our business activity (ESG assessment, reporting, project management or IT activities), our work environment and in our responsible practices for environment protection.