About the Role
Provide hands-on cloud security engineering capability while enabling the secure and effective use of AI across Information Security and product engineering teams. This role bridges Security Architecture, BISO/Application Security, Cloud/Platform Engineering, and GRC, aiming to reduce manual workload by creating reusable cloud guardrails, automated controls, AI-assisted workflows, secure design patterns, and developer enablement materials.
Responsibilities
- Build and maintain reusable cloud security guardrails for identity, logging, encryption, network segmentation, secrets management, storage, workloads, containers, serverless services, and data protection.
- Translate security architecture standards into deployable cloud patterns, reference implementations, templates, and engineering-ready requirements.
- Partner with cloud, platform, DevOps, and product engineering teams to embed security controls into cloud landing zones, CI/CD pipelines, infrastructure-as-code workflows, and operational processes.
- Support the implementation and tuning of CSPM, CNAPP, cloud workload protection, IaC scanning, secrets scanning, and related cloud security tooling.
- Develop policy-as-code and control-as-code mechanisms to prevent, detect, and report common cloud misconfigurations.
- Support cloud-native vulnerability and misconfiguration remediation by providing prioritization logic, remediation guidance, and reusable fix patterns.
- Establish cloud security metrics and dashboards covering control adoption, misconfiguration trends, remediation progress, recurring issues, and exception patterns.
- Design and maintain AI-assisted workflows for security intake triage, threat model drafting, architecture review summaries, control mapping, remediation guidance, and risk statement generation.
- Build prompt libraries, review rubrics, validation steps, and human-in-the-loop processes for approved AI use within Information Security.
- Identify repetitive BISO, AppSec, and Security Architecture tasks that can be safely accelerated through AI-assisted processes.
- Partner with GRC, Legal, Privacy, and security leadership to ensure AI-assisted security workflows are auditable, explainable, and aligned with internal risk expectations.
- Measure the effectiveness of AI-assisted workflows, including time saved, consistency improvements, review quality, and reduction in repeat manual work.
- Define secure design patterns for AI-enabled applications, including LLM-based features, retrieval-augmented generation, AI agents, AI APIs, copilots, and automation workflows.
- Establish cloud security requirements for AI workloads, including identity, secrets, data storage, network access, observability, workload isolation, and third-party AI service integrations.
- Support AI application threat modelling and risk reviews.
- Create developer-facing guidance for safe use of AI coding assistants, AI APIs, data ingestion, vector stores, model outputs, and AI-generated code.
- Convert recurring BISO/AppSec and Security Architecture questions into reusable guidance, decision trees, approved patterns, checklists, and self-service workflows.
- Build lightweight intake and routing mechanisms that help determine when a request needs BISO review, AppSec review, architecture review, GRC input, or engineering remediation.
- Create and maintain a library of approved cloud and AI security patterns that product and engineering teams can reuse.
- Help reduce one-off security consultations by embedding approved security decisions into tooling, templates, and standard delivery workflows.
Requirements
- Experience in machine learning engineering.
- Strong experience in cloud security engineering, application security, security architecture, DevSecOps, or security automation.
- Hands-on experience with at least one major cloud platform such as AWS or Azure.
- Practical knowledge of IAM, logging, encryption, secrets management, network security, storage security, vulnerability management, and secure CI/CD.
- Experience with infrastructure-as-code and cloud security tooling such as CSPM, CNAPP, IaC scanning, SAST, SCA, secrets scanning, or policy-as-code.
- Ability to translate security standards and architecture requirements into practical implementation patterns.
- Familiarity with generative AI, LLM-enabled applications, AI-assisted development, or AI security risks.
- Strong scripting, automation, workflow design, or tooling integration experience.
- Excellent written and verbal communication skills, with the ability to create clear security guidance for engineering teams.
- Experience building cloud security guardrails, landing zone controls, reusable modules, or automated remediation workflows.
- Experience supporting regulated environments or environments with strict customer, contractual, or compliance obligations.
- Familiarity with AI security frameworks and guidance such as the NIST AI Risk Management Framework, NIST Generative AI Profile, OWASP Top 10 for LLM Applications, or Cloud Security Alliance AI security guidance.
- Experience with RAG architecture, AI agents, vector databases, AI APIs, prompt engineering, or AI application threat modelling.
- Experience building security knowledge assistants, prompt libraries, AI-assisted review workflows, or security automation.
Skills
- Cloud Security Engineering
- AI Security Enablement
- Identity and Access Management (IAM)
- Logging
- Encryption
- Network Security
- Secrets Management
- Storage Security
- Vulnerability Management
- Secure CI/CD
- Infrastructure-as-Code (IaC)
- CSPM
- CNAPP
- IaC Scanning
- SAST
- SCA
- Secrets Scanning
- Policy-as-Code
- Generative AI
- LLM-enabled applications
- AI-assisted development
- AI Security Risks
- Scripting
- Automation
- Workflow Design
- Tooling Integration
- RAG architecture
- AI agents
- Vector databases
- AI APIs
- Prompt Engineering
- AI application threat modelling
- Security knowledge assistants
- Prompt libraries
- AI-assisted review workflows
- Security automation
Location
- USA
Work Type
- Flexible working hours
Experience Level
- Senior
Benefits
- Generous holiday allowance with the option to buy additional days.
- Life assurance
- Access to a competitive contributory pension scheme
- Save As You Earn share option scheme.
- Optional Dental Insurance
- Maternity, paternity, and shared parental leave
- Employee Assistance Programme
- Access to employee resource groups with dedicated time to volunteer.
- Access to extensive learning and development resources
- Access to employee discounts scheme via Perks at Work
About the Company
- LexisNexis Intellectual Property Solutions (LNIP) is the global leader in patent intelligence, bringing clarity to innovation for businesses, law firms, universities, and government agencies worldwide.
- Our mission is to help the innovation community make better decisions faster, with greater confidence, combining the world’s most trusted patent data with sophisticated analytics, AI-powered insights, and purpose-built workflows.
- Protégé in PatentSight is LNIP’s next-generation agentic AI assistant, purpose-built for strategic patent analysis. Protégé replaces complex filter-based workflows with natural language questions, surfacing structured, decision-ready insights grounded in trusted data and established metrics.
Equal Opportunity
- We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact 1-855-833-5120.
- We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.
- USA Job Seekers: EEO Know Your Rights.
