About the Role
As a Senior AI Security Engineer, you will play a key role in ensuring the security of our AI ecosystem by design. You will help establish security foundations, governance frameworks, and technical controls to safely scale AI-powered applications, AI agents, and GenAI solutions.
Responsibilities
- Drive the security-by-design approach for AI solutions by defining and evolving security standards, controls, and guardrails for AI agents, LLM-driven applications, and Generative AI solutions.
- Partner with Data & AI, Engineering, and IT teams to ensure secure, scalable, and compliant development and deployment of AI-powered solutions.
- Support the design and development of AI agents using modern frameworks and tooling such as LangSmith and related orchestration, monitoring, and evaluation platforms.
- Assess AI solution architectures focusing on identity and access management, data protection, model security, secure integrations, vector database security, and infrastructure hardening.
- Establish and operationalize DevSecOps practices across the Secure Software Development Lifecycle (SSDLC), integrating automated security controls and testing capabilities into CI/CD pipelines and cloud-based AI environments.
- Conduct security reviews, threat modeling workshops, and risk assessments to identify and mitigate AI-specific risks.
- Advise project teams on secure patterns for integrating enterprise data, APIs, Retrieval-Augmented Generation (RAG) architectures, vector databases, and external services into AI applications.
- Act as a trusted advisor to product owners, architects, developers, and business stakeholders on secure AI adoption, AI governance, and compliance requirements.
Requirements
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Information Systems, Data Science, or a related field.
- 7+ years of experience in cybersecurity, application security, cloud security, security engineering, or a comparable role.
- Strong understanding of Application Security, Secure Software Development Lifecycle (SSDLC), secure coding practices, and DevSecOps methodologies.
- Hands-on experience with security testing capabilities such as SAST, DAST, and Software Composition Analysis (SCA).
- Experience securing cloud-native environments and modern infrastructure, including CI/CD pipelines, containerized workloads, Identity & Access Management (IAM), secrets management, and runtime security controls.
- Experience building, reviewing, or securing LLM-driven applications, AI agents, and Generative AI solutions using frameworks such as LangSmith or similar ecosystems.
- Knowledge of AI Security, AI threat modeling, enterprise AI security controls, and industry standards such as the OWASP Top 10 for LLM Applications.
- Fluent English communication skills (C1+) with the ability to translate complex security requirements into pragmatic guidance for technical and non-technical stakeholders.
Skills
- Application Security
- Secure Software Development Lifecycle (SSDLC)
- Secure coding practices
- DevSecOps methodologies
- SAST
- DAST
- Software Composition Analysis (SCA)
- Cloud-native environments
- CI/CD pipelines
- Containerized workloads
- Identity & Access Management (IAM)
- Secrets management
- Runtime security controls
- LLM-driven applications
- AI agents
- Generative AI solutions
- LangSmith
- AI Security
- AI threat modeling
- Enterprise AI security controls
- OWASP Top 10 for LLM Applications
Location
- Germany - Berlin
- Germany - Bonn
- Germany - Frankfurt/Main
- Germany - Hamburg
- Germany - Cologne
- Germany - Munich
Work Type
- Hybrid working
- Work from abroad (workation)
Experience Level
- Senior
Education Level
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Data Science, or a related field
- Master’s degree in Computer Science, Cybersecurity, Information Systems, Data Science, or a related field
Benefits
- Hybrid working
- Daycare allowance
- Corporate discounts
- Wellbeing support (e.g. Headspace)
- Healthy snacks and beverages provided in break areas
About the Company
- Simon-Kucher is a global consultancy with more than 2,200 employees in 30+ countries.
- We are a trusted commercial advisor focused on unlocking better growth, combining deep consulting expertise, growth specialization, and technology to scale lasting impact.
- We optimize every lever of commercial strategy – product, pricing, innovation, marketing, and sales – based on what customers want and value.
- With over 40 years of monetization experience, we are recognized as the world’s leading commercial growth and pricing specialist.
Equal Opportunity
- We believe in building a culture that embraces diversity, equity, and inclusion, creating an environment in which our people feel valued, are able to be themselves and feel their contribution matters.
