Senior Security Engineer (AI)
Company Description
Sopra Steria is one of the largest players in the tech industry in Europe, known for its consulting, digital services and software development. We operate in nearly 30 countries in the world, hiring more than 55,000 employees.
The Polish branch, as the Global Delivery Center, operates in Katowice since 2007 and has been growing ever since. Currently, our team consists of around 1,000 specialists.
Within the Digital Platform Services department, our teams specialize in areas such as cloud, operating systems, virtualization, databases, backup or storage, as well as networking and security. We also have 1st line support consultants who speak French and English, but also Italian, Spanish, Portuguese and German.
The Application Services department is responsible for areas such as software development, data engineering, testing services, CRM, ITSM and ERP platform integrations, as well as application management for customers in Scandinavia, Benelux, France, Germany, Switzerland and the UK.
Job Description
We are looking for Senior Security Engineer (AI) to join Sopra Steria Polska a team that works for the internal team supporting Sopra Steria France, we are looking for a professional who will be responsible for developing the organization's AI Security capabilities across Sopra Steria Group. You will actively analyze security threats related to artificial intelligence, investigate emerging security solutions, assess your effectiveness through testing, and recommend best practices and security controls for projects delivered by the company.
The person in this position will monitor market trends, conduct independent technical research, produce documentation, and share knowledge with project teams and the wider security community.
Note that we can only offer cooperation to people who are located in Poland, have EU citizenship and are willing to commute to our office in Katowice or Gdańsk, Poland.
Responsibilities:
- AI Security Research and Knowledge Development
- Monitor trends, emerging threats, and attack techniques targeting AI and LLM-based systems.
- Analyze new tools, frameworks, and solutions that support AI security.
- Conduct technical research activities, including proof-of-concept development, laboratory testing, and offensive security testing.
- Evaluate new AI Security technologies and recommend their adoption where appropriate.
- AI Security Assessments
- Analyze the architecture of AI-powered systems.
- Identify risks associated with the use of AI models, AI agents, LLMs, RAG, MCP, and other modern AI components.
- Assess the resilience of solutions against attack techniques such as Prompt Injection, Jailbreak, Data Exfiltration, Model Abuse, Tool Abuse, and Supply Chain Attacks.
- Recommend security controls and security architectures for both existing and new projects.
- Standards and Documentation Development
- Develop guidelines, standards, and best practices in the field of AI Security.
- Support project teams in implementing secure design patterns.
- Contribute to security recommendations for clients and project teams.
- Create training and educational materials.
- Knowledge Sharing
- Organize workshops, presentations, and knowledge-sharing sessions.
- Support the development of the AI Security community within the organization.
- Provide consulting and guidance to Application Security, DevSecOps, and Architecture teams.
- Promote awareness of risks associated with the use of AI technologies.
Qualifications
Must have requirements:
- Minimum of 2 years of experience in Cyber Security.
- Hands-on experience in Application Security, Offensive Security, DevSecOps, or Security Testing.
- Experience in the security assessment of web applications, APIs, and modern application architecturs.
- Basic or advanced understanding of AI security concepts.
- Knowledge of threats affecting LLM and Generative AI systems.
- Understanding of attack techniques targeting AI models and LLM-based systems.
- Knowledge of protection mechanisms for AI models, data, and AI agents.
- Interest in AI Governance and AI Risk Management topics.
- Application Security: Web Application Security (OWASP Top 10, API Security), Secure Software Development Lifecycle (SSDLC), Security Testing (manual security testing, code reviews, SAST, DAST).
- Network Security: Network protocols and communication security, Network segmentation and access control.
- DevSecOps: CI/CD Security, Software Supply Chain Security..Dependency Management and Software Bill of Materials (SBOM, experience in cooperating with clients
- EU citizenship.
- Fluent English B2/C1
- Being open to occasional business trips abroad and visits in our office in Katowice or Gdańsk
- We are particularly interested in candidates who:
- Demonstrate a strong willingness to learn and continuously expand their knowledge independently.
- Have a genuine interest in emerging technologies and actively follow the latest trends in cybersecurity.
- Are proactive, self-motivated, and comfortable working in a fast-paced environment driven by rapidly evolving technologies.
Nice to have requirements:
- Experience with GenAI, LLMs, Agentic AI, RAG, or MCP.
- Experience in Penetration Testing.
- Experience in Red Teaming.
- Experience in Security Research.
- Security-related certifications (e.g., OSCP, OSWE, CISSP, GWAPT, GWEB, CARTA, etc.).
Additional Information
What we offer:
- BENEFITS (UoP): Luxmed, Medicover Sport, Worksmile, educational platforms, languages learning platform, referral bonus, life insurance, certifications (paid by the company), conferences, Tech Lunches, possibility to join our Communities (Project Management, Architecture, Security, Process Management, Leadership, AI and Cloud), local kindergarten.
- DEVELOPMENT OPPORTUNITIES (B2B): Tech Lunches, Worksmile, possibility to join our Communities (Project Management, Architecture, Security, Process Management, Leadership, AI and Cloud).
ADDITION: free parking, fresh fruits, workation.
In case of questions, please contact the HR team.
The recruitment process in our company consists of 3 stages:
- a short phone call with a recruiter (30 min max)
- one-hour long interview on Teams (with both general and technical questions)
- final interview (30 min)
Salary range:
UOP: 13000-17000 PLN gross/month.
B2B: 100-140 PLN net/h
All information about salary range and its additional components will be provided during the 1st stage of recruitment process.
At our organization, we are committed to fighting against all forms of discrimination. We foster a work environment that is inclusive and respectful of all differences.