×
Hier anmelden um sich kostenlos auf Stellen zu bewerben oder Stellenanzeigen aufzugeben. X

Senior Product Security Engineer, AI ML

in 47608, Geldern, Nordrhein-Westfalen, Deutschland
Unternehmen: Norstella
Vollzeit, Saisonal/Temporär position
Verfasst am 2026-10-04
Berufliche Spezialisierung:
  • Software Entwicklung
    Künstliche Intelligenz Ingenieur
Gehalts-/Lohnspanne oder Branchenbenchmark: 133000 - 178000 EUR pro Jahr EUR 133000.00 178000.00 YEAR
Stellenbeschreibung
Location: Geldern

Senior Product Security Engineer, AI ML

Company:
Norstella

Location:

Remote, United States

Date Posted:
Sep 22, 2026

Employment Type:

Full Time

Job : R-2134

Description

About Norstella

Norstella is a premier and critical global life sciences data and AI solutions provider dedicated to improving patient access to life‑saving therapies. Norstella supports pharmaceutical and biotech companies across the full drug development lifecycle — from pipeline to patient. Our mission is simple: to help our clients bring therapies to market faster and more efficiently, ultimately impacting patient lives.

Norstella unites market‑leading brands
- Citeline, Evaluate, MMIT, Panalgo, Skipta and The Dedham Group and delivers must‑have answers and insights, leveraging AI, for critical strategic, clinical, and commercial decision‑making. We help our clients:

  • Accelerate the drug development cycle
  • Assess competition and bring the right drugs to market
  • Make data driven commercial and financial decisions
  • Match and recruit patients for clinical trials
  • Identify and address barriers to therapies
Job Description

Leads multi-product security efforts, develops the Prod Sec team and mentors engineers, coordinating incident response, and shaping Dev Sec Ops  practices, with primary focus on securing Norstella's agentic SDLC platform (Forge) and its supporting knowledge‑base ecosystem (Sage). This engineer owns the safety posture of the autonomous AI agent chain end‑to‑end: the platform itself, the prompts and orchestration layer, the proprietary domain data the agents consume, and — critically — the source code the agents produce.

Acts as the senior security partner to the Forge engineering team, embedding security guardrails into every phase of the autonomous SDLC (Intake → Architect → Threat‑Modeling → Dev‑Planning → Dev → QA) so that AI‑generated code meets the same compliance, audit, and resilience standards as human‑written code in HIPAA, GDPR, SOC 2, and FDA 21 CFR Part 11 environments.

Responsibilities
  • Leads threat modelling across complex architectures, including agent‑to‑agent communication graphs, tool‑use surfaces, MCP server boundaries, and prompt/RAG pipelines, and mentors engineers in risk analysis practices.
  • Leads secure development training across product groups — including AI‑assisted and AI‑generated coding workflows — and evolves standards based on industry trends, OWASP LLM Top 10, and emerging agentic‑AI threat research.
  • Leads vulnerability management for multiple products, setting priorities and ensuring timely resolution, and tunes the Forge Security Agent's SAST/SCA gating, severity thresholds, and triage‑LLM classification logic to keep auto‑remediation loops both effective and safe.
  • Leads supply chain risk assessments and drives API governance practices across product portfolios, with explicit ownership of the AI/ML supply chain — foundation model providers (Anthropic, others), Auth0, Snyk, Azure Dev Ops NPM feeds, vector databases, and the Sage KB seed data — including concentration‑risk monitoring and contingency planning.
  • Leads security integration across CI/CD and multi‑cloud platforms, mentoring engineers on automation, and ensures every agentic run produces a reconstructible audit trail sufficient to demonstrate reasonable judgment to SOC 2, HIPAA, GDPR, and Life Sciences auditors.
  • Technical IR lead overseeing cross‑product incidents, coordinates disclosure processes, and advises leadership, including incidents involving prompt injection, model jailbreak, agent privilege escalation, sensitive data leakage from KB stores, and compromised AI‑generated code reaching production.
  • Leads AI/ML model security practices across multiple teams and establishes safe design principles, including least‑privilege tool‑use,…
Stellen-Anforderungen
10+ Jahre Berufserfahrung
Um Jobs auf dieser Seite anzusehen und sich zu bewerben, die Bewerbungen aus Ihrem Standort oder Land akzeptieren, klicken Sie unten auf den Button, um eine Suche zu starten.
(Wenn dieser Job tatsächlich in Ihrem Zuständigkeitsbereich liegt, verwenden Sie möglicherweise einen Proxy oder VPN, um auf diese Seite zuzugreifen. Um weiterzukommen, sollten Sie Ihre Verbindung zu einem anderen Mobilgerät oder PC wechseln).
 
 
 
Suchen Sie hier nach weiteren Stellen:
(nach Beruf, Fähigkeit)
Standort
Suchradius erweitern (Meilen)
0
200
Filter
Mindest-Bildungsgrad für die Stelle
Mindest-Berufserfahrung für die Stelle
Veröffentlicht in den letzten:
Gehalt