Senior Security AI Engineer
at Enhesa
- Seniority
- Senior
- Location
- Lisbon, Portugal
- Posted
- 10d ago
at Enhesa
<div class="content-intro"><p><strong>Who We Are:</strong></p> <p>Enhesa is the leading provider of regulatory and sustainability intelligence worldwide. As a trusted partner, we empower the global business community with the insight to act today and prepare for tomorrow to create a more sustainable future - positively impacting our environment, our health, our safety, and our future. Navigating the fast-changing compliance and sustainability landscapes, we help them understand not just what they should do (first) but also how to do it. Both in their unique business and anywhere in the world. Now and in the future.</p> <p style="line-height: 1;"><strong>Our Mission:</strong></p> <ul> <li>Identify EHS requirements for the industry</li> <li>Provide EHS compliance tools to companies</li> <li>Advise companies in developing and implementing corporate EHS strategies</li> </ul> <p style="line-height: 1;">Enhesa’s core clients include Fortune 500 multinational companies. For more information, visit <a href="https://www.enhesa.com">www.enhesa.com</a></p> <p style="line-height: 1;">As part of our highly dynamic team, we offer:</p> <ul> <li>A competitive salary package & benefits with a flexible home-working policy</li> <li>Work/life balance and a fast-paced and driven environment</li> <li>Accountability and pride for your projects</li> </ul></div><p><strong>Overview of the position</strong></p> <p>Support the Enhesa’s cybersecurity infrastructure by implementing robust security controls, deploying innovative security solutions, and investigating security incidents. A key focus of this role is securing AI/ML systems and pipelines, assessing risks introduced by large language models and generative AI tools, and defining security standards for AI adoption across the organization. This role is pivotal in maintaining the security posture through meticulous incident analysis and effective mitigation strategies. Beyond technical responsibilities, the position requires excellent collaboration and communication with various departments to align security policies and procedures with overall business objectives and compliance regulations. The role works closely with AI, Application Engineering, and Cloud Platform teams to embed security throughout the software development lifecycle and cloud infrastructure environments. The successful candidate will provide guidance on secure design patterns, conduct comprehensive security reviews of application code, cloud architectures, and managed AI services, and support the responsible development, deployment, and operation of AI-powered features and products.</p> <p><strong>Main tasks and responsibilities</strong></p> <ul> <li>Drive Corporate AI Security Strategy: Define, implement, and govern the security standards, policies, and frameworks for AI/ML adoption across all business units.</li> <li>Lead Cross-Functional AI Initiatives: Act as the primary security partner for Platform, Application Engineering, and Product teams to support the responsible development and deployment of AI-powered features.</li> <li>Coordinate and Mentor Security Teams: Champion security culture by coordinating activities with Tech Leads, Engineering Managers, and the Security Champions network, providing guidance on secure design patterns for AI workloads.</li> <li>Oversee MLSecOps and SSDLC Integration: Architect and enforce the integration of advanced security controls, automated testing, and vulnerability management within CI/CD pipelines, DevSecOps, and MLSecOps workflows.</li> <li>Manage AI Risk and Threat Modeling: Conduct comprehensive security architecture reviews and risk assessments focusing on Large Language Models (LLMs) and Generative AI, mitigating risks like prompt injection, data poisoning, and model supply chain vulnerabilities (OWASP LLM Top 10).</li> <li>Incident Response Leadership: Lead investigation, mitigation, and recovery efforts for complex security incidents, with a specialized focus on threats targeting AI infrastructure, inference endpoints, and managed cloud AI services (e.g., Azure OpenAI, AWS Bedrock)</li> <li>Continuous Security Evolution: Monitor emerging cybersecurity trends, adversarial ML tactics, and global compliance regulations to preemptively evolve Enhesa’s security infrastructure against future vectors.</li> </ul> <p><strong>Key requirements</strong></p> <p><span style="text-decoration: underline;">Education Level</span></p> <p>Bachelor’s or advanced degree in computer science, artificial intelligence, mathematics, or related field or professional cybersecurity certifications in lieu of a formal degree.</p> <p><span style="text-decoration: underline;">Experience</span></p> <p>At least 3 years of experience as cybersecurity professional, with at least 3 year in AI/ML security, LLM security, or security for AI-driven systems</p> <p><span style="text-decoration: underline;">Technical Skills:</span></p> <ul> <li>Application Security (AppSec) and Secure Software Development Lifecycle (SSDLC): familiarity with integrating security practices into CI/CD pipelines, code review processes, DevSecOps and MLSecOps workflows.</li> <li>OWASP Top 10 and OWASP LLM Top 10: solid understanding of common web application vulnerabilities and their AI/LLM-specific equivalents (e.g. prompt injection, insecure output handling, model supply chain risks).</li> <li>AI/ML Security: understanding of threat vectors specific to AI systems, including adversarial attacks, data poisoning, model inversion, and securing inference endpoints.</li> <li>Knowledge of networks (TCP/IP, LAN/WAN) Must possess a solid understanding of networking basics, including TCP/IP protocols, and the configuration and operation of both Local Area Networks (LAN) and wide Area Networks (WAN). Awareness of how these networks facilitate communication and the potential security implications is essential.</li> <li>Basic familiarity with the OSI (Open Systems Interconnection) model, including the underst