Mobilunity logo

Application & AI Cyber Security Engineer

Mobilunity

RemotemidPosted 1h ago

Job description

On behalf of our Client, Mobilunity is looking for an Application & AI Cyber Security Engineer.

You will join a small, high-trust Cyber Security Engineering team responsible for strengthening the security posture of a modern, globally distributed technology environment.

This is a hands-on engineering role focused on application security, container security, and AI security. You will build automated security controls, guardrails, and real-time visibility that make the secure path the easiest path for engineering teams.

You’ll work closely with platform engineering, cloud infrastructure, identity, technology assurance, and security leadership teams. The role offers significant ownership and the opportunity to influence not only technical controls, but also security standards and governance decisions across the organization.

This is not a role focused on manually reviewing individual applications. You’ll be expected to build automated, scalable security solutions that enforce standards at the point of deployment and provide clear visibility into security risks across running environments.

What we’re looking for:

We need a technically strong security engineer who understands that security and developer experience should work together.

The ideal candidate:

  • thinks in terms of automation, scalability, and enforceable controls rather than manual reviews;

  • has strong hands-on experience with Kubernetes and container security;

  • understands application security, software supply chain risks, and secure development practices;

  • enjoys building security tooling, observability, and policy-as-code solutions;

  • is actively using AI-assisted development tools in their own engineering workflow;

  • has practical or growing experience with AI and LLM security;

  • can communicate complex technical findings clearly to senior technical and security stakeholders;

  • is comfortable working in a small, collaborative, high-trust environment;

  • approaches security friction as an engineering problem to solve.

Responsibilities:

  • Design and deploy automated security controls for Kubernetes and application deployments.

  • Implement admission controllers, policy-as-code, and automated security scanning.

  • Define and enforce container security standards, including image scanning, runtime baselines, and registry governance.

  • Manage software supply chain security, including dependency scanning, SBOMs, build-time and runtime analysis.

  • Build application security observability and dashboards that provide real-time visibility into deployed and running systems.

  • Develop automated guardrails that enable teams to use AI coding tools securely without requiring manual security review for every use case.

  • Own security configuration and controls for AI platforms, including access controls, data flows, hardening, and protection against prompt injection and data exfiltration.

  • Assess security risks associated with AI tools, MCP connectors, APIs, and agentic systems.

  • Define security and behavioural baselines for agentic execution environments.

  • Collaborate with security and engineering teams on container runtime telemetry and monitoring.

  • Work with identity and cloud security teams on workload access, service identity, and secrets management.

  • Curate and automate internal security tooling with a focus on reliability, security, and operational efficiency.

  • Contribute to security standards, technical controls, and governance decisions.

  • Communicate security findings and recommendations to senior stakeholders.

Requirements:

  • Proven hands-on experience with Kubernetes and container security.

  • Experience with container image scanning, admission control, runtime protection, and policy-as-code.

  • Experience building automated security controls that can scale across complex environments.

  • Strong understanding of application security fundamentals, including OWASP Top 10 and secure software development practices.

  • Experience with software supply chain security and dependency management.

  • Experience building security visibility through instrumentation, runtime analysis, monitoring, or operational dashboards.

  • Experience with CI/CD security and automated security checks.

  • Active experience using AI-assisted development tools such as Claude Code, GitHub Copilot, or equivalent.

  • Practical or growing knowledge of AI/LLM security, including prompt injection, data exfiltration, model/API security, or agentic system controls.

  • Strong analytical and problem-solving skills.

  • Ability to communicate complex technical security topics clearly and concisely to senior stakeholders.

  • Advanced English.

Nice to have:

  • Experience with security tools such as Aikido, CrowdStrike, Bold Security, Nightfall, Zscaler, or Lakera Guard.

  • Experience with MCP (Model Context Protocol), agentic frameworks, or AI platform administration.

  • Experience in private equity, FinTech, financial services, or other environments where protection of sensitive information is critical.

  • Experience measuring and optimizing the operational cost of security controls.

  • Experience working with local or open-source LLMs for automation and security use cases.

  • Experience with Datadog or similar observability platforms.

  • Experience with SBOM tooling and software composition analysis.

  • Experience with cloud security and workload identity.

  • Experience working with policy-as-code frameworks.

Tools you’ll work with:

Kubernetes, CI/CD platforms, SBOM tooling, Aikido, Claude Enterprise, Claude Code, MCP, CoWork, DTEX, Datadog, and policy-as-code frameworks.

In return we offer:

  • The friendliest community of like-minded IT-people

  • Open knowledge-sharing environment – exclusive access to a rich pool of colleagues willing to share their endless insights into the broadest variety of modern technologies

  • Mobilunity Medical Insurance program designed to attend our teams’ needs

  • Paid vacations and sick leaves, including 5 paid days per year that don’t require a sick note

  • Perfect office location in the city-center (900m from Lukyanivska metro station with a green and spacious neighborhood) or remote mode engagement: you can choose a convenient one for you, with a possibility to fit together both

  • No open-spaces setup – separate rooms for every team’s comfort and multiple lounge and gaming zones

  • English classes in 1-to-1 & group modes with elements of gamification

  • Neverending fun: sports events, tournaments, music band, multiple affinity groups

Come on board, and let’s grow together!