Senior Application & AI Security Engineer
RingCentral Bulgaria
Software Development · 5,001-10,000 employees
About the role
The engineer will perform security design reviews, threat modeling, and penetration testing to secure applications and AI-enabled products. They will also collaborate with engineering teams to implement security controls, remediate vulnerabilities, and integrate AI-assisted security workflows.
What they look for
Requirements
Candidates must have strong technical experience in application security, including vulnerability detection, exploitation, and remediation techniques. Proficiency in security testing tools and the ability to communicate complex security risks to diverse stakeholders are essential.
Benefits
Full description
Say hello to opportunities.
If you’re looking to be part of what’s next in communication, you’re in the right place.
At RingCentral, we believe the best customer experiences happen when humans and AI work together. Our agentic voice AI portfolio—AIR, AVA, and ACE—brings together automation, assistance, and insights across the entire conversation lifecycle. The result? More seamless, intelligent experiences for businesses everywhere.
With $2.5B+ in ARR and $250M invested in R&D annually, we’re building the future of AI-powered business communications.
About the Application Security Team
The Application Security team, part of RingCentral's CISO organization, partners with engineering teams to secure their applications — practically and early.
We combine automation, tooling, expert guidance, and targeted assessments to raise the security baseline, engaging early in the SDLC and focusing deeper expertise where risk is highest. We help teams understand risk and design effective mitigations, while ownership of security stays with the teams building the product.
About the Role
We are looking for a Senior Application & AI Security Engineer with a strong understanding of application vulnerabilities and how they can be detected, exploited, and remediated. You will apply established application-security practices—including security design review, threat modeling, code review, penetration testing, and automated security testing—to RingCentral applications throughout the development lifecycle.
As a complementary part of the role, you will extend these practices to AI-enabled products and AI-native development workflows. This includes assessing AI-based features in RingCentral products, AI tools, coding agents, MCP servers, and agentic integrations, as well as evaluating how AI can responsibly improve activities such as vulnerability detection, code review, threat modeling, penetration testing, triage, and remediation.
You will partner with Product Management, Engineering, Site Reliability Engineering, Operations, and architecture teams to identify security risks, translate them into actionable guidance, and help teams implement effective mitigations. Your goal is to strengthen application security while helping RingCentral adopt AI technologies safely and use them to improve the scale and effectiveness of its security practices.
This role requires on-site presence at our office 4 days a week to support effective collaboration and teamwork.
Key responsibilities:
- Collaborate with Product Management, Engineering, Site Reliability Engineering, Operations, and architecture teams to align products and applications with security architecture and secure development standards.
- Perform security design reviews, threat modeling, security requirements analysis, targeted code reviews, and penetration testing for new applications and significant product changes.
- Identify gaps in existing security architecture and work with engineering teams to design, review, and approve appropriate changes.
- Advise engineering teams on vulnerability remediation and validate fixes for significant findings.
- Help engineering teams use automated security testing tools (SAST, DAST, SCA), review results, and distinguish actionable findings from false positives or non-exploitable conditions.
- Support external penetration-testing consultants in scope of annual application penetration tests.
- Triage bug bounty reports and coordinate validated findings with the responsible engineering teams.
- Contribute to security policies, standards, procedures, requirements, and guardrails for secure software development and secure AI adoption.
- Assess AI-enabled applications, AI tools, coding assistants, agents, MCP servers, and integrations for security risks.
- Help engineering teams apply appropriate controls to AI-assisted development environments and workflows.
- Design and test AI-assisted approaches to code review, threat modeling, penetration testing, vulnerability triage, and remediation.
- Evaluate security products and internal prototypes through structured PoCs, document results, and make evidence-based adoption recommendations.
Key requirements:
- Technical experience with software or product architecture, design, and implementation.
- Strong knowledge of web application vulnerabilities, exploitation techniques, and remediation approaches.
- Experience with application security design reviews, threat modeling, and risk assessments.
- Experience with application security testing, including SAST, DAST, software composition analysis, code review, and penetration testing.
- Ability to design practical security controls and advise engineering teams on secure implementation.
- Ability to communicate complex technical scenarios as clear, risk-based assessments for engineers, product stakeholders, and senior leaders.
- Strong organization and time-management skills, with the ability to manage multiple assessments and stakeholder relationships.
- A collaborative approach that helps engineering teams improve security while continuing to deliver products effectively.
- Understanding of the security risks introduced by AI-enabled applications, coding assistants, agents, tool integrations, or similar systems.
- Experience evaluating unfamiliar technologies through technical testing, structured PoCs, and translating PoC results into production recommendations.
- Practical scripting or software-development ability for building testing workflows, integrations, or security prototypes.
Preferred qualifications:
- Experience securing WebRTC, video, or audio-streaming products.
- Familiarity with video codecs and related media technologies.
- Experience assessing LLM applications, RAG systems, AI agents, MCP servers, or AI development tools.
- Experience with AI-assisted code review, penetration testing, threat modeling, or vulnerability remediation.
- Bachelor's degree or equivalent practical experience in Computer Science, Electrical Engineering, cybersecurity, or a related field.
What we offer:
- Well-coordinated professional team.
- Cutting edge technologies, interesting and challenging tasks, dynamic project, great opportunities for self-realization, professional and career growth.
- Additional Health and Life Insurance Package.
- Employee Assistance Program.
- 25 vacation days.
- 102,26 EUR/200 BGN Digital Food Vouchers via EdenRed and their application
- 61,36 EUR/120 BGN Gross as part of the salary for Working Expenses Allowance
About RingCentral
RingCentral is a global leader in agentic voice AI–powered business communications, delivering an integrated platform for business phone, SMS, contact center, workforce engagement management, video collaboration, and messaging. As the communications layer connecting businesses and customers, RingCentral is the front door of business communication and is in the advantageous position to apply AI at every phase of the conversation journey — before, during, and after each interaction. Our agentic AI portfolio includes autonomous voice-first AI agents that automate calls, assist in the moment, and analyze every interaction – enabling businesses to work smarter, respond faster, and connect more meaningfully with their customers. Visit ringcentral.com to learn more.
RingCentral is an equal opportunity employer that truly values diversity. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
#LI-JW1
Similar roles
-
IT Risk and Security Engineer - Governance & Administration
DTCC Hyderabad, Telangana, India
-
Business Development Manager, Cybersecurity & Security Operations (SOC)
Gruve Singapore
-
Senior Security Engineer
Smartstream Limited Bengaluru, Karnataka, India
-
Senior Product Security Engineer
Endor Labs Bengaluru, Karnataka, India
-
Cloud Security Engineer
The Access Group Timișoara, Romania
-
Principal Network Security Engineer
Autodesk Bengaluru, Karnataka, India