Confirmed on the employer's own hiring board on Sep 30, 2026. First seen by Alion on Sep 4, 2026.
Aduna's Security Area of Focus exists to protect the company, our CSP partners, and the data flowing through our APIs, while enabling the rest of the engineering organization to move fast and adopt AI safely. As a Senior Security Engineer in this group, you will be an Individual Contributor accountable for implementing security solutions across Aduna's platform and integration estate, and for operationalizing the standards, policies, and risk decisions issued by the Security governance function.
You will work hands-on, in collaboration with engineering teams across the company, to turn governance into engineered controls and guardrails that scale, including the controls needed to secure how we build with, and expose, AI capabilities.
This is a hands-on technical role focused on owning security outcomes. While it does not include people management, it requires strong accountability, the ability to drive and influence engineers across teams toward the right security decisions, and rigorous attention to standards and applicable telecom security guidelines.
What you will be focused on
Risk Ownership and Cross-Team Leadership
Operate with ownership and accountability for one or more security risks at Aduna, including risks introduced by AI and LLM-based features, driving and influencing engineering teams to comprehensively address those risks while enabling the company to move fast.
Lead cross-organizational technical efforts to solve challenging security problems that span the Platform, Integration, SRE, and Product teams.
Disambiguate and decompose security problems and solutions, and create clarity for engineering and product partners.
Security Implementation and Engineered Controls
Design and implement security controls across application, infrastructure, and AI layers, including identity, authentication, authorization, encryption, secret management, and model and prompt safety controls.
Operate and evolve Aduna's secret management platform built on HashiCorp Vault, including secrets engines, dynamic credentials, policies, namespaces, and integration with workloads, CI/CD, and AI/agent toolchains.
Harden Kubernetes clusters, cloud accounts (AWS, Azure), CI/CD pipelines, and AI runtime environments against internal standards and industry best practices.
Build and maintain security tooling and automation for vulnerability management, dependency scanning, SAST/DAST, container and image scanning, infrastructure-as-code policy enforcement, and emerging categories such as model and prompt scanning.
Apply AI to security itself: use LLMs, agents, and ML-based tooling to scale triage, code review, threat detection, and evidence collection, with appropriate human oversight.
Governance and Policy Operationalization
Translate policies, standards, and risk decisions issued by the Security governance function into concrete technical controls, automated checks, and developer-facing guidance, including standards for the responsible and ethical use of AI.
Support audits and assessments by providing technical evidence, walkthroughs, and remediation plans.
What You Bring
Education
Bachelor's degree in Computer Science, Engineering, Cybersecurity, or equivalent practical experience.
Experience
8+ years of experience in security engineering, application security, cloud security, or a closely related discipline.
Proven track record of managing security risk and navigating the tradeoff between security and friction in an engineering organization.
Experience driving cross-team engineering and security initiatives end to end.
Experience with system design, threat modeling, and risk assessment, ideally including AI or ML-enabled systems.
Technical Skills
Strong working knowledge of security standards and frameworks (ISO 27001, SOC 2, NIST CSF, OWASP ASVS, CIS Benchmarks), plus growing familiarity with AI-specific frameworks (OWASP LLM Top 10, NIST AI RMF, MITRE ATLAS).
Knowledge of current threat tactics, techniques, and procedures, including AI-specific threats such as prompt injection, model and data poisoning, jailbreaks, and unsafe autonomous actions.
Solid knowledge of identity and access management, including OAuth 2.0, OIDC, SAML, mTLS, and PKI.
Experience with cloud security on AWS and/or Azure (IAM, KMS, network security, logging, posture management).
Experience with Kubernetes security (RBAC, network policies, admission control, image signing, runtime security).
Working knowledge of infrastructure as code and GitOps (Terraform, FluxCD, GitLab CI or similar) and how to embed security controls into them

