Back to jobs

Senior Security Engineer (AI/Cloud)

Lisbon, Portugal

Who We Are:

Enhesa is the leading provider of regulatory and sustainability intelligence worldwide. As a trusted partner, we empower the global business community with the insight to act today and prepare for tomorrow to create a more sustainable future - positively impacting our environment, our health, our safety, and our future. Navigating the fast-changing compliance and sustainability landscapes, we help them understand not just what they should do (first) but also how to do it. Both in their unique business and anywhere in the world. Now and in the future.

Our Mission:

  • Identify EHS requirements for the industry
  • Provide EHS compliance tools to companies
  • Advise companies in developing and implementing corporate EHS strategies

Enhesa’s core clients include Fortune 500 multinational companies. For more information, visit www.enhesa.com

As part of our highly dynamic team, we offer:

  • A competitive salary package & benefits with a flexible home-working policy
  • Work/life balance and a fast-paced and driven environment
  • Accountability and pride for your projects

Overview of the position

Support the Enhesa’s cybersecurity infrastructure by implementing robust security controls, deploying innovative security solutions, and investigating security incidents. This role is central to Enhesa’s application and cloud security posture, with growing exposure to securing AI/ML systems and generative AI tools as adoption expands across the organization. This role is pivotal in maintaining the security posture through meticulous incident analysis and effective mitigation strategies. Beyond technical responsibilities, the position requires excellent collaboration and communication with various departments to align security policies and procedures with overall business objectives and compliance regulations. The role works closely with Application Engineering and Cloud Platform teams, and increasingly with AI teams, to embed security throughout the software development lifecycle and cloud infrastructure environments. The successful candidate will provide guidance on secure design patterns, conduct comprehensive security reviews of application code and cloud architectures, and, as AI adoption grows, contribute to securing AI-powered features and managed AI services.

Main tasks and responsibilities

  • Secure the SDLC and Cloud Infrastructure: Conduct security reviews of application code and cloud architectures (AWS, Azure, GCP), and integrate security controls, automated testing, and vulnerability management into CI/CD pipelines and DevSecOps workflows.
  • Partner with Engineering Teams: Act as a hands-on security partner to Application Engineering and Cloud Platform teams, reviewing designs and providing guidance on secure design patterns throughout the development lifecycle.
  • Champion Security Culture: Collaborate with Tech Leads and the Security Champions network to share secure coding practices, run awareness sessions, and raise the security bar across engineering teams.
  • Contribute to AI Security Practices: Support security reviews of AI/ML systems and pipelines as they are introduced, helping assess risks such as prompt injection, data poisoning, and model supply chain vulnerabilities (OWASP LLM Top 10), and grow this expertise over time.
  • Investigate Security Incidents: Lead investigation, mitigation, and recovery efforts for security incidents, including those affecting cloud infrastructure and, as relevant, AI/ML services and inference endpoints.
  • Monitor Emerging Threats: Track emerging cybersecurity trends and vulnerabilities — including in the AI/ML space — and help evolve Enhesa’s security controls to address new risks.

Key requirements

Education Level

Bachelor’s or advanced degree in computer science, artificial intelligence, mathematics, or related field or professional cybersecurity certifications in lieu of a formal degree.

Experience

At least 5 years of experience as a cybersecurity professional, with a strong background in application security and/or cloud security. Hands-on exposure to AI/ML security, LLM security, or securing AI-driven systems is a strong plus.

Technical Skills:

  • Application Security (AppSec) and Secure Software Development Lifecycle (SSDLC): familiarity with integrating security practices into CI/CD pipelines, code review processes, DevSecOps and MLSecOps workflows.
  • OWASP Top 10: solid understanding of common web application vulnerabilities. Familiarity with the OWASP LLM Top 10 (e.g. prompt injection, insecure output handling, model supply chain risks) is a plus.
  • AI/ML Security (plus): exposure to threat vectors specific to AI systems, such as adversarial attacks, data poisoning, model inversion, or securing inference endpoints, is valued but not required — Enhesa will support your growth in this area.
  • Knowledge of networks (TCP/IP, LAN/WAN) Must possess a solid understanding of networking basics, including TCP/IP protocols, and the configuration and operation of both Local Area Networks (LAN) and wide Area Networks (WAN). Awareness of how these networks facilitate communication and the potential security implications is essential.
  • Basic familiarity with the OSI (Open Systems Interconnection) model, including the understanding of its seven layers and how they contribute to network communications and cybersecurity practices.
  • Security protocols, for example: (HTTPS, DNS, SMTP, FTP, SSH).
  • Firewalls (IDS/IPS) familiar with the concepts and purposes of these tools.
  • Understanding of information security principles, such as confidentiality, integrity, and availability.
  • Familiarity with operating systems, especially Windows, Linux or Unix, and MacOS.
  • Knowledge and familiarity with incident investigation and response processes.
  • Specific Knowledge and Skills such as programming languages (Python, PowerShell); familiarity with API security testing and secure coding practices in web application stacks
  • Knowledge of securing cloud environments (AWS, Azure, GCP); exposure to securing AI/ML workloads and managed AI services (e.g. Azure OpenAI, AWS Bedrock, GCP Vertex AI) is a plus
  • Familiarity with concepts like IAM (Identity and Access Management), encryption in transit and at rest, and shared responsibility models.
  • Understanding of securing virtual machines and containerized environments.

Certifications

Relevant security certifications (e.g. CISSP, CEH, CCSP, OSCP) are a plus. Enhesa will sponsor and support the successful candidate in obtaining an AI security certification (e.g. AAISM or CompTIA SecAI+) as part of their growth in this role.

Other Skills:

  • Fluency in English. Any additional language skills are an asset.
  • In order to fit in Enhesa’s collaborative and international environment, creativity, dynamics, and ability to work independently yet transparently towards colleagues.
  • Strong teamwork skills, both with colleagues as well as with external partners.
  • Both individual and team problem-solving skills are crucial in this position.

 

If you are ready to join our journey, please apply!

 

Equal Opportunity Employer
Enhesa is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, or any other legally protected characteristic.

 

Apply for this job

*

indicates a required field

Phone
Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...