EngineerJobs.io
← Back to all jobs

Job Description

McKesson is hiring a Sr Product Security Engineer, AI & DevSecOps for an onsite role in Columbus, OH. This position focuses on embedding security across the software development lifecycle for AI-enabled products, cloud-native platforms, and DevSecOps practices. You will partner with engineering and platform teams to translate security requirements into reusable patterns and automated guardrails that help teams ship securely and efficiently.

What you’ll do

  • Collaborate with development teams to incorporate security requirements across design, development, testing, deployment, and operations
  • Lead security architecture reviews, threat modeling, secure design reviews, and security assessments for applications, APIs, cloud services, and AI-enabled systems
  • Write and review code to identify vulnerabilities, attack vectors, and improvement opportunities to strengthen secure development practices
  • Build reusable security patterns, shared services, and automated guardrails that support secure delivery
  • Assess and secure AI, machine learning, generative AI, and large language model solutions, including secure use of AI-assisted development tools
  • Integrate automated security testing into CI/CD pipelines, including SAST, DAST, software composition analysis, secrets detection, container scanning, and infrastructure scanning
  • Design security controls for cloud-native applications, containers, Kubernetes, serverless platforms, and infrastructure-as-code deployments
  • Work with engineering and cybersecurity teams to assess risk, remediate vulnerabilities, respond to security concerns, and support a security-first engineering culture

What you bring

  • Degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent professional experience
  • Typically 7+ years of relevant experience in application security, product security, software development, security engineering, DevSecOps, or a related discipline
  • Hands-on experience writing, reviewing, and deploying application code using TypeScript, Java, Ruby, Python, or comparable languages
  • Strong understanding of application attack vectors, secure coding practices, software vulnerabilities, and modern application architectures
  • Experience with threat modeling, security architecture reviews, secure design reviews, and vulnerability remediation
  • Experience implementing DevSecOps practices and integrating automated security controls into CI/CD
  • Experience securing AI/ML platforms, generative AI solutions, large language model applications, or AI-assisted development workflows
  • Experience with cloud platforms, containers, Kubernetes, infrastructure-as-code, security automation, and application security testing tools

Technologies you’ll work with

TypeScript, Java, Ruby, Python; SAST, DAST, software composition analysis, secrets detection, container scanning, infrastructure scanning; cloud-native applications, containers, Kubernetes, serverless platforms, infrastructure-as-code; AI, machine learning, generative AI, large language model, AI-assisted development tools; CI/CD pipelines; threat modeling, security architecture reviews, secure design reviews, and vulnerability remediation.

Benefits

  • Medical, Dental, and Vision
  • Health Spending Accounts
  • Flexible Spending Accounts
  • 401(k) (U.S.)
  • Pension (Canada)
  • Employee Stock Purchase Plan
  • Mental Health Programs
  • Flexible Schedules
  • Paid Time Off
  • Wellness Program
  • Education Reimbursement
  • Volunteer Opportunities
  • Flexible Work Environment

Preferred skills and experience

  • Knowledge of AI security frameworks and controls, including OWASP Top 10 for LLM Applications and the NIST AI Risk Management Framework
  • Experience creating reusable security services, secure development patterns, engineering guardrails, or policy-as-code solutions
  • Experience with CI/CD and infrastructure technologies such as GitHub Actions, Azure DevOps, GitLab, Jenkins, or Terraform
  • Experience supporting frameworks such as SOC 2, HIPAA, SOX, NIST CSF, or ISO 27001
  • Ability to translate complex security requirements and technical risks into practical guidance for development teams
  • Strong collaboration and influencing skills, with the ability to advance security without unnecessarily slowing product delivery

Salary: USD 140,300 - 233,800 per year.

Similar Jobs