Senior Security Engineer
You will manage security clause reviews, customer security engagements, secure development lifecycle processes, compliance control execution, self-audits, and technical input for insurance underwriting. You will build security clause libraries, assess customer redlines and questionnaires, explain AI Cloud architecture, implement threat modeling and security testing checkpoints, train engineering teams, and close audit findings.
Responsibilities
- Build and maintain a tiered AI Cloud security clause library
- Review customer security redlines and negotiate technical commitments with Legal and Sales
- Handle customer security questionnaires and participate in security reviews, audits, and assurance calls
- Explain AI data center architecture to customer security teams
- Establish SDLC security processes across AI Cloud product lines
- Conduct threat modeling, design reviews, security testing, and pre-release sign-offs
- Audit product team adherence to security processes and drive remediation
- Design and deliver engineering security training
- Execute SOC 2, ISO 27001, and ISO 42001 controls
- Collect compliance evidence and conduct internal self-audits
- Close findings before external audits
- Respond to cyber, technology errors and omissions, and property insurance underwriter questionnaires
- Update technical risk inputs during insurance renewals
Requirements
- 6+ years in security, including at least 3 years in AppSec, Product Security, DevSecOps, or security consulting
- Experience with B2B contract security clauses
- Experience with threat modeling using STRIDE or PASTA, secure code review, SAST, DAST, SCA, and vulnerability management
- Working knowledge of SOC 2, ISO 27001, and NIST CSF
- Architecture-level knowledge of AWS, GCP, or Azure
- Working proficiency in English and Chinese
- Experience executing compliance controls inside a business line preferred
- Customer-facing B2B security experience preferred
- Knowledge of DPA, SLA, right-to-audit, and breach notification terms preferred
- Knowledge of AI and LLM security preferred
- Knowledge of Kubernetes security, GPU or HPC, multi-tenant SaaS, or AIDC fabric preferred
- CISSP, CCSP, AWS Security Specialty, ISO 27001 LI, or similar preferred
Benefits
- Attractive welfare benefits