AI Product Security Engineer
Forescout Technologies Inc. · United States
About The Role
Shape the Future of Cybersecurity at Forescout
Every day cyberattacks threaten to disrupt hospitals, power grids, financial systems, and the infrastructure we all depend on. At Forescout, we build defenses that keep civilization running smoothly in an increasingly connected world.
For more than 25 years, Fortune 100 organizations, government agencies, and large enterprises have trusted Forescout as their foundation to manage cyber risk, ensure compliance, and mitigate threats. From power grids and healthcare systems to financial networks and transportation hubs, Forescout protects the critical infrastructure of our modern world.
What You Will Do
We are seeking an experienced
Product Security Engineer
to design, build, and scale security capabilities at the scale of AI. This is a highly technical, hands-on role focused on operating AI-assisted vulnerability management, product security automation, and secure-by-design engineering practices.
The ideal candidate combines deep expertise in application security, cloud security, DevSecOps, and AI technologies. This position focuses on building security into the SDLC and working with engineering teams develop, deploy, and operate secure products at scale. You will act as a force multiplier across Product Management, Engineering, Platform Engineering, Cloud Operations, Compliance, and Security teams by embedding security directly into the software development lifecycle and leveraging AI to increase both security coverage and engineering velocity.
AI-Powered Vulnerability Management for Secure SDLC
- Partner with Architects to define secure architecture patterns for Development, and Operate Product Security systems
- Build AI-driven solutions into CI/CD to accelerate
- Vulnerability discovery
- Triage and prioritization
- Root cause analysis
- Remediation recommendations
- Validation testing
- Penetration testing
- Security documentation
- Develop exploitability-aware prioritization models using business context, reachability, threat intelligence, and customer impact.
- Reduce false positives and improve signal-to-noise ratios across Development tooling.
- Implement automated workflows for CVE, KEV, SBOM, SAST, DAST, Dependency Management, EoL and SCA findings.
Product Security Operations
- Conduct threat modeling, design reviews, security assessments, and architecture reviews.
- Partner with development teams to identify and remediate security weaknesses.
- Participate in vulnerability response and incident response activities.
- Work with engineering teams to reduce critical vulnerability exposure and accelerate remediation timelines.
- Develop dashboards and metrics that measure risk reduction, security maturity, and remediation performance.
Compliance & Regulatory Support
Ensure security controls remain updated and align with customer, certification, and government requirements, ex.
NIST Secure Software Development Framework (SSDF)
FedRAMP
ISO 27001
SOC 2
Common Criteria
CRA/NIS2
Other regulatory requirements
What You Bring to Forescout
Security
5+ years of experience in
Product Security
Application Security
Cloud Security
DevSecOps
Security Engineering
- Demonstrated experience securing enterprise-scale software products and cloud services.
- Experience integrating security into modern SDLC pipelines.
Technical Skills
- Threat modeling
- Secure design reviews
- Vulnerability assessment
- Penetration testing
- Secure coding practices
- Incident response
- Software supply chain security
Penetration Testing
Security Tooling
Experience with several of the following
Snyk
Wiz
Burp Suite
Tenable
GitHub Advanced Security
Claude Security
OpenAI SCT
Open Source AI tooling / harnesses
Veracode
Semgrep
SonarQube
Cloud & Infrastructure
Azure
AWS
Kubernetes
Containers
Infrastructure-as-Code (Terraform)
- Identity and access management
- API security
Programming
Strong proficiency in one or more
Python
Java
Go
C/C++
JavaScript/TypeScript
AI-Specific Qualifications
Hands-on experience using AI/LLM technologies in engineering or security workflows.
Understanding of
- Prompt injection attacks
- RAG security risks
- AI model abuse
- Data poisoning
- Tool misuse
- Agent security
- AI governance controls
- Experience building or integrating AI-assisted automation solutions.
- Familiarity with AI coding agents, copilots, and autonomous security workflows.
Preferred Qualifications
- CISSP, CSSLP, OSCP, GIAC, or equivalent certification.
- Experience with AI red teaming and adversarial testing.
- Experience building developer security platforms.
- Experience securing SaaS products, APIs, and distributed systems.
- Familiarity with enterprise-scale software delivery organizations.
- Experience supporting FedRAMP or government cloud environments.
What Forescout Offers You
Competitive compensation and benefits, including coverage of 85% of employee and dependent health care premiums, 100% company-paid employee life and disability insurance premiums, a 401(k) match, generous flexible time off for U.S. employees, voluntary life, accident, and critical illness insurance options, employee assistance program, maternity and parental bonding leave, and more.
A collaborative, innovative environment where you can help advance global security while working with leading technology.
Leadership teams that take ownership of team growth, actively supporting development, career progression, and opportunities for employees to do their best work.
Learn more @
<www.forescout.com>
.
Our Mission -
Continuously identify, protect, and ensure the compliance of all cyber assets across the modern organization.
Our Values
One Team
– We all work together, and we all win together.
Cyber Obsessed
– We are curious about technology, and we are innovative and passionate about solving big programs.
Customer Driven
– We listen, we learn, and we make it right.
Relentless
– We're smart, determined, and find a way.
We
figure stuff out.
Collaborative, without Ego
– No one succeeds alone.
We strive to be the humble
person that people want to work with.
Thank you for taking the time to learn more about us.
If this opportunity intrigues you, we encourage you to apply!
At Forescout, we are “Cyber Obsessed”.
We are committed to maintaining a secure environment for our customers, employees, and business operations.
To support these efforts, candidates may be asked to complete job-related pre-employment screening and verification processes, to the extent permitted by applicable law.
Depending on the role and location, these measures may include identity verification, employment verification, background screening, work authorization verification, and other lawful security-related checks.
Forescout
- conducts
- these
- processes
in
accordance
with
- applicable
- laws
and
- regulations,
- i
- ncluding
- privacy
and
- data
- protection
- requirements,
and
- obtains
- any
- required
- notices,
- authorizations,
or
- consent
- before
- conducting
- such
- screenings
- .
Notice
Regarding
the
Use
of
Artificial
Intelligence
in
Recruitment
- As part of our recruitment process, we may use artificial intelligence ("AI") or automated decision-support tools to assist with reviewing applications, assessing
- job-related
- qualifications,
- matching
- candidates
to
- role
- requirements,
- scheduling
- interviews,
and
- supporting
- candidate
- evaluation.
These
- tools
- are
- designed
to
- assist
- our
- recruiters
and
- hiring
- managers
and
- are
- not
the
- sole
- basis
for
- hiring
- decisions.
- Qualified personnel review relevant candidate information and exercise
- human
- judgment
- throughout
the
- recruitment
- process.
We
- are
- committed
to
the
- responsible
- use
of
AI
and
seek
to
deploy
and
use
AI-enabled
- recruiting
- tools
in
accordance
with
- applicable
- laws,
- regulations,
and
- our
- internal
- governance standards.
NOTE TO EMPLOYMENT AGENCIES
We value the partnerships we have built with our preferred vendors. Forescout does not accept unsolicited resumes from employment agencies.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
