David Kennedy Recruitment

Security Engineer (AppSec / GRC / AI Security)

David Kennedy Recruitment Beijing, Beijing, China

Staffing and Recruiting · 11-50 employees

2 d ago
Remote security Mid (2-5 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Security Engineer will take end-to-end ownership of security operations, including application security, vulnerability management, and governance. They will also monitor threats, manage AI security risks, and oversee internal IT security controls.

What they look for

Application security Vulnerability management Governance, risk and compliance AI security Code review Git GitHub Penetration testing Python Bash Scripting Automation Security auditing Risk assessment Threat monitoring MDM

Requirements

Candidates must have 2-3+ years of hands-on security engineering experience with strong skills in application security and vulnerability remediation. Proficiency in coding, scripting, and security auditing is required, along with excellent English communication skills.

Benefits

Fully remote working Opportunity to own security for a large-scale AI platform Direct collaboration with engineering leadership

Full description

David Kennedy Recruitment is working with a rapidly growing technology company with over 50 million users worldwide that is seeking to onboard a Security Engineer to join their R&D team.

As the company's sole dedicated Security Engineer, the successful candidate will take end-to-end ownership of security operations, covering application security, vulnerability management, governance and risk, and emerging AI security challenges. The company's products include adult/NSFW content, so candidates must be fully comfortable working with this material.

Position: Security Engineer (AppSec / GRC / AI Security)

Location: Europe/ASIA, Remote

Employment type: B2B engagement preferred

DUTIES AND RESPONSIBILITIES:

  • Application security: review code, find and fix vulnerabilities, work with developers in Git/GitHub, and coordinate external pen tests and audits.
  • Governance, risk and compliance: build and maintain the security risk register, assess exposure across systems, support audit follow-up, and prioritise fixes by risk and business impact.
  • Monitoring and awareness: watch alerts and threats, run awareness programmes and phishing simulations, and provide occasional evening and weekend cover.
  • IT security and access: handle secure onboarding and offboarding, device security (MDM) and access permissions, and tighten internal controls.
  • AI security: track risks to generative AI platforms (prompt injection, jailbreaks, filter bypasses) and vulnerabilities in third-party AI providers.

REQUIREMENTS:

  • 2–3+ years of hands-on security engineering experience, with flexibility for exceptional scale-up experience
  • Strong application security experience, including code reviews and vulnerability remediation
  • Proven experience conducting or coordinating security audits and penetration tests
  • Comfortable coding and working directly with Git/GitHub
  • Practical scripting or automation skills, ideally Python or Bash
  • Previous experience within an AI company or a scale-up with 50+ employees
  • Sound understanding of security governance, risk assessment and prioritisation
  • Ability to independently identify, investigate and resolve security issues, and to take end-to-end ownership in a fast-paced environment
  • Excellent English communication skills
  • Based in Europe, with approximately 80% overlap with CET working hours
  • Comfortable with occasional evening/weekend security monitoring
  • Fully comfortable working with adult/NSFW content as part of daily responsibilities

BENEFITS:

  • Fully remote working from Europe
  • Opportunity to own security for a fast-growing AI platform with over 50 million users
  • Direct collaboration with engineering leadership
  • Hands-on, non-advisory role with real responsibility for security outcomes
  • And many more!!!

Similar roles