Posted today · Greenhouse · alphasense✓ Direct employer / ATS application
Senior Product Security Engineer
Alphasense
Role details
What you’ll be doing
About AlphaSense: The world’s most sophisticated companies rely on AlphaSense to remove uncertainty from decision-making. With market intelligence and search built on proven AI, AlphaSense delivers insights that matter from content you can trust. Our universe of public and private content includes equity research, company filings, event transcripts, expert calls, news, trade journals, and clients’ own research content. The acquisition of Tegus by AlphaSense in 2024 advances our shared mission to empower professionals to make smarter decisions through AI-driven market intelligence. Together, AlphaSense and Tegus will accelerate growth, innovation, and content expansion, with complementary product and content capabilities that enable users to unearth even more comprehensive insights from thousands of content sets. Our platform is trusted by over 6,000 enterprise customers, including a majority of the S&P 500. Founded in 2011, AlphaSense is headquartered in New York City with more than 2,000 employees across the globe and offices in the U.S., U.K., Finland, India, Singapore, Canada, and Ireland. Come join us! About the Role We're looking for a Senior Product Security Engineer to lead the design and implementation of secure, scalable, and trustworthy products across AlphaSense's AI-native platform. You'll work closely with architects, engineering, and product teams to embed security by design throughout the software development lifecycle. This role sits at the intersection of AI/ML security, secure architecture, threat modeling, and customer-facing assurance — defining the standards, automation, and frameworks that enable secure, intelligent products at scale. What You’ll Do: AI Security & Enablement (30%) Architect and enforce security controls for AI/ML systems — model training, data pipelines, inference environments, and agentic workflows. Identify and mitigate AI-specific attack vectors: prompt injection, data poisoning, model inversion, model theft. Implement model provenance, integrity, and auditability controls for responsible, secure AI operations. Align AI security with governance and compliance teams against frameworks like NIST AI RMF and the EU AI Act. Secure Architecture & Development Lifecycle (30%) Embed security throughout the software and AI development lifecycle, partnering with architects, engineering, and product across AlphaSense's application and cloud ecosystems. Ensure security, privacy, and compliance by design. Define and maintain secure development standards, guidance, and best practices. Threat Modeling & Security Review (20%) Lead threat modeling, secure design reviews, and risk assessments across the software development lifecycle. Build and maintain security automation and governance that integrates into development workflows. Customer-Facing Security Assurance (10%) Produce customer-facing security assurance — security questionnaire responses, security whitepapers, and trust collateral — that unblocks enterprise deals. Represent product security in customer, cross-functional, and leadership discussions. Leadership (10%) Mentor teams on secure coding, AI risk management, and secure design. Promote a security-first culture through advocacy, documentation, and training. What We Are Looking For: 5–7+ years in product, application, or cloud security engineering. Deep understanding of secure SDLC, threat modeling, and secure architecture design. Ability to read and review code to inform threat models and design reviews. Experience securing AI/ML pipelines, data workflows, and model-serving infrastructure, with working knowledge of AI/LLM security (prompt injection, model integrity, provenance). Proven expertise with cloud security concepts and best practices across multi-cloud environments. Familiarity with DevSecOps and CI/CD environments. Familiarity with encryption fundamentals — symmetric and asymmetric cryptography, TLS/mTLS, key management, and secrets handling. Understanding of authentication and authorization patterns in modern applications: OAuth 2.0, OIDC, SAML, RBAC, and ABAC. Demonstrated ability to drive cross-functional security initiatives — partnering with engineering, product, and compliance to embed security into roadmaps, influence architectural decisions, and align stakeholders across boundaries. Nice to Have Proficiency in Python, Java, and/or JavaScript for security automation and tooling. Container and orchestration security (Kubernetes runtime protection). Software supply