# Senior Security Engineer (AI/Cloud)

[Enhesa](https://gurify.com/jobs?q=Enhesa) · Lisbon, Portugal · Posted 6 weeks ago

Senior

[AI & ML](https://gurify.com/jobs/ai-ml)

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://job-boards.greenhouse.io/enhesa/jobs/4307257009)

## Job description

### Who We Are:

Enhesa is the leading provider of regulatory and sustainability intelligence worldwide. As a trusted partner, we empower the global business community with the insight to act today and prepare for tomorrow to create a more sustainable future - positively impacting our environment, our health, our safety, and our future. Navigating the fast-changing compliance and sustainability landscapes, we help them understand not just what they should do (first) but also how to do it. Both in their unique business and anywhere in the world. Now and in the future.

### Our Mission:

- Identify EHS requirements for the industry

- Provide EHS compliance tools to companies

- Advise companies in developing and implementing corporate EHS strategies

Enhesa’s core clients include Fortune 500 multinational companies. For more information, visit www.enhesa.com

### As part of our highly dynamic team, we offer:

- A competitive salary package & benefits with a flexible home-working policy

- Work/life balance and a fast-paced and driven environment

- Accountability and pride for your projects

### Overview of the position

Support the Enhesa’s cybersecurity infrastructure by implementing robust security controls, deploying innovative security solutions, and investigating security incidents. This role is central to Enhesa’s application and cloud security posture, with growing exposure to securing AI/ML systems and generative AI tools as adoption expands across the organization. This role is pivotal in maintaining the security posture through meticulous incident analysis and effective mitigation strategies. Beyond technical responsibilities, the position requires excellent collaboration and communication with various departments to align security policies and procedures with overall business objectives and compliance regulations. The role works closely with Application Engineering and Cloud Platform teams, and increasingly with AI teams, to embed security throughout the software development lifecycle and cloud infrastructure environments. The successful candidate will provide guidance on secure design patterns, conduct comprehensive security reviews of application code and cloud architectures, and, as AI adoption grows, contribute to securing AI-powered features and managed AI services.

### Main tasks and responsibilities

- Secure the SDLC and Cloud Infrastructure: Conduct security reviews of application code and cloud architectures (AWS, Azure, GCP), and integrate security controls, automated testing, and vulnerability management into CI/CD pipelines and DevSecOps workflows.

- Partner with Engineering Teams: Act as a hands-on security partner to Application Engineering and Cloud Platform teams, reviewing designs and providing guidance on secure design patterns throughout the development lifecycle.

- Champion Security Culture: Collaborate with Tech Leads and the Security Champions network to share secure coding practices, run awareness sessions, and raise the security bar across engineering teams.

- Contribute to AI Security Practices: Support security reviews of AI/ML systems and pipelines as they are introduced, helping assess risks such as prompt injection, data poisoning, and model supply chain vulnerabilities (OWASP LLM Top 10), and grow this expertise over time.

- Investigate Security Incidents: Lead investigation, mitigation, and recovery efforts for security incidents, including those affecting cloud infrastructure and, as relevant, AI/ML services and inference endpoints.

- Monitor Emerging Threats: Track emerging cybersecurity trends and vulnerabilities — including in the AI/ML space — and help evolve Enhesa’s security controls to address new risks.

### Key requirements

### Education Level

Bachelor’s or advanced degree in computer science, artificial intelligence, mathematics, or related field or professional cybersecurity certifications in lieu of a formal degree.

### Experience

At least 5 years of experience as a cybersecurity professional, with a strong background in application security and/or cloud security. Hands-on exposure to AI/ML security, LLM security, or securing AI-driven systems is a strong plus.

### Technical Skills:

- Application Security (AppSec) and Secure Software Development Lifecycle (SSDLC): familiarity with integrating security practices into CI/CD pipelines, code review processes, DevSecOps and MLSecOps workflows.

- OWASP Top 10: solid understanding of common web application vulnerabilities. Familiarity with the OWASP LLM Top 10 (e.g. prompt injection, insecure output handling, model supply chain risks) is a plus.

- AI/ML Security (plus): exposure to threat vectors specific to AI systems, such as adversarial attacks, data poisoning, model inversion, or securing inference endpoints, is valued but not required — Enhesa will support your growth in this area.

- Knowledge of networks (TCP/IP, LAN/WAN) Must possess a solid understanding of networking basics, including TCP/IP protocols, and the configuration and operation of both Local Area Networks (LAN) and wide Area Networks (WAN). Awareness of how these networks facilitate communication and the potential security implications is essential.

- Basic familiarity with the OSI (Open Systems Interconnection) model, including the understanding of its seven layers and how they contribute to network communications and cybersecurity practices.

- Security protocols, for example: (HTTPS, DNS, SMTP, FTP, SSH).

- Firewalls (IDS/IPS) familiar with the concepts and purposes of these tools.

- Understanding of information security principles, such as confidentiality, integrity, and availability.

- Familiarity with operating systems, especially Windows, Linux or Unix, and MacOS.

- Knowledge and familiarity with incident investigation and response processes.

- Specific Knowledge and Skills such as programming languages (Python, PowerShell); familiarity with API security testing and secure coding practices in web application stacks

- Knowledge of securing cloud environments (AWS, Azure, GCP); exposure to securing AI/ML workloads and managed AI services (e.g. Azure OpenAI, AWS Bedrock, GCP Vertex AI) is a plus

- Familiarity with concepts like IAM (Identity and Access Management), encryption in transit and at rest, and shared responsibility models.

- Understanding of securing virtual machines and containerized environments.

### Certifications

Relevant security certifications (e.g. CISSP, CEH, CCSP, OSCP) are a plus. Enhesa will sponsor and support the successful candidate in obtaining an AI security certification (e.g. AAISM or CompTIA SecAI+) as part of their growth in this role.

### Other Skills:

- Fluency in English. Any additional language skills are an asset.

- In order to fit in Enhesa’s collaborative and international environment, creativity, dynamics, and ability to work independently yet transparently towards colleagues.

- Strong teamwork skills, both with colleagues as well as with external partners.

- Both individual and team problem-solving skills are crucial in this position.

If you are ready to join our journey, please apply!

Equal Opportunity Employer
Enhesa is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, or any other legally protected characteristic.

**Live in Enhesa’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- PM [Product Manager - AI](https://gurify.com/job/product-manager-ai-e12bfd6b8e64) Lisbon, Portugal · last week
- NI [Cloud & AI Security Operations Engineer](https://gurify.com/job/cloud-ai-security-operations-engineer-at-nice-47f323349d60) Nice · 3 weeks ago
- AT [AI - TransPerfect](https://gurify.com/job/ai-transperfect-45d59b3264a4) Lisbon, Portugal · 3 weeks ago
- TH [AI & Data Engineer (all genders)](https://gurify.com/job/ai-data-engineer-all-genders-at-thorit-df61f361b443) Thorit · Lisboa, Portugal · 8 weeks ago
- NI [Cloud & AI Security Operations Engineer](https://gurify.com/job/cloud-ai-security-operations-engineer-at-nice-c27abd0eda1c) Nice · Israel - Raanana · 5 weeks ago
- LI [Product & AI Security Engineer](https://gurify.com/job/product-ai-security-engineer-at-linkedin-dde4a2718339) Linkedin · Berlin · 6 days ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Senior Security Engineer (AI/Cloud)","description":"\u003Ch3\u003EWho We Are:\u003C/h3\u003E\u003Cp\u003EEnhesa is the leading provider of regulatory and sustainability intelligence worldwide. As a trusted partner, we empower the global business community with the insight to act today and prepare for tomorrow to create a more sustainable future - positively impacting our environment, our health, our safety, and our future. Navigating the fast-changing compliance and sustainability landscapes, we help them understand not just what they should do (first) but also how to do it. Both in their unique business and anywhere in the world. Now and in the future.\u003C/p\u003E\u003Ch3\u003EOur Mission:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EIdentify EHS requirements for the industry\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EProvide EHS compliance tools to companies\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAdvise companies in developing and implementing corporate EHS strategies\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EEnhesa\u2019s core clients include Fortune 500 multinational companies. For more information, visit www.enhesa.com\u003C/p\u003E\u003Ch3\u003EAs part of our highly dynamic team, we offer:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EA competitive salary package \u0026amp; benefits with a flexible home-working policy\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWork/life balance and a fast-paced and driven environment\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAccountability and pride for your projects\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EOverview of the position\u003C/h3\u003E\u003Cp\u003ESupport the Enhesa\u2019s cybersecurity infrastructure by implementing robust security controls, deploying innovative security solutions, and investigating security incidents. This role is central to Enhesa\u2019s application and cloud security posture, with growing exposure to securing AI/ML systems and generative AI tools as adoption expands across the organization. This role is pivotal in maintaining the security posture through meticulous incident analysis and effective mitigation strategies. Beyond technical responsibilities, the position requires excellent collaboration and communication with various departments to align security policies and procedures with overall business objectives and compliance regulations. The role works closely with Application Engineering and Cloud Platform teams, and increasingly with AI teams, to embed security throughout the software development lifecycle and cloud infrastructure environments. The successful candidate will provide guidance on secure design patterns, conduct comprehensive security reviews of application code and cloud architectures, and, as AI adoption grows, contribute to securing AI-powered features and managed AI services.\u003C/p\u003E\u003Ch3\u003EMain tasks and responsibilities\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ESecure the SDLC and Cloud Infrastructure: Conduct security reviews of application code and cloud architectures (AWS, Azure, GCP), and integrate security controls, automated testing, and vulnerability management into CI/CD pipelines and DevSecOps workflows.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPartner with Engineering Teams: Act as a hands-on security partner to Application Engineering and Cloud Platform teams, reviewing designs and providing guidance on secure design patterns throughout the development lifecycle.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EChampion Security Culture: Collaborate with Tech Leads and the Security Champions network to share secure coding practices, run awareness sessions, and raise the security bar across engineering teams.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EContribute to AI Security Practices: Support security reviews of AI/ML systems and pipelines as they are introduced, helping assess risks such as prompt injection, data poisoning, and model supply chain vulnerabilities (OWASP LLM Top 10), and grow this expertise over time.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EInvestigate Security Incidents: Lead investigation, mitigation, and recovery efforts for security incidents, including those affecting cloud infrastructure and, as relevant, AI/ML services and inference endpoints.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMonitor Emerging Threats: Track emerging cybersecurity trends and vulnerabilities \u2014 including in the AI/ML space \u2014 and help evolve Enhesa\u2019s security controls to address new risks.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EKey requirements\u003C/h3\u003E\u003Ch3\u003EEducation Level\u003C/h3\u003E\u003Cp\u003EBachelor\u2019s or advanced degree in computer science, artificial intelligence, mathematics, or related field or professional cybersecurity certifications in lieu of a formal degree.\u003C/p\u003E\u003Ch3\u003EExperience\u003C/h3\u003E\u003Cp\u003EAt least 5 years of experience as a cybersecurity professional, with a strong background in application security and/or cloud security. Hands-on exposure to AI/ML security, LLM security, or securing AI-driven systems is a strong plus.\u003C/p\u003E\u003Ch3\u003ETechnical Skills:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EApplication Security (AppSec) and Secure Software Development Lifecycle (SSDLC): familiarity with integrating security practices into CI/CD pipelines, code review processes, DevSecOps and MLSecOps workflows.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EOWASP Top 10: solid understanding of common web application vulnerabilities. Familiarity with the OWASP LLM Top 10 (e.g. prompt injection, insecure output handling, model supply chain risks) is a plus.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAI/ML Security (plus): exposure to threat vectors specific to AI systems, such as adversarial attacks, data poisoning, model inversion, or securing inference endpoints, is valued but not required \u2014 Enhesa will support your growth in this area.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EKnowledge of networks (TCP/IP, LAN/WAN) Must possess a solid understanding of networking basics, including TCP/IP protocols, and the configuration and operation of both Local Area Networks (LAN) and wide Area Networks (WAN). Awareness of how these networks facilitate communication and the potential security implications is essential.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBasic familiarity with the OSI (Open Systems Interconnection) model, including the understanding of its seven layers and how they contribute to network communications and cybersecurity practices.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESecurity protocols, for example: (HTTPS, DNS, SMTP, FTP, SSH).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFirewalls (IDS/IPS) familiar with the concepts and purposes of these tools.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EUnderstanding of information security principles, such as confidentiality, integrity, and availability.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with operating systems, especially Windows, Linux or Unix, and MacOS.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EKnowledge and familiarity with incident investigation and response processes.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESpecific Knowledge and Skills such as programming languages (Python, PowerShell); familiarity with API security testing and secure coding practices in web application stacks\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EKnowledge of securing cloud environments (AWS, Azure, GCP); exposure to securing AI/ML workloads and managed AI services (e.g. Azure OpenAI, AWS Bedrock, GCP Vertex AI) is a plus\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with concepts like IAM (Identity and Access Management), encryption in transit and at rest, and shared responsibility models.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EUnderstanding of securing virtual machines and containerized environments.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ECertifications\u003C/h3\u003E\u003Cp\u003ERelevant security certifications (e.g. CISSP, CEH, CCSP, OSCP) are a plus. Enhesa will sponsor and support the successful candidate in obtaining an AI security certification (e.g. AAISM or CompTIA SecAI\u002B) as part of their growth in this role.\u003C/p\u003E\u003Ch3\u003EOther Skills:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EFluency in English. Any additional language skills are an asset.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIn order to fit in Enhesa\u2019s collaborative and international environment, creativity, dynamics, and ability to work independently yet transparently towards colleagues.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong teamwork skills, both with colleagues as well as with external partners.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBoth individual and team problem-solving skills are crucial in this position.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EIf you are ready to join our journey, please apply!\u003C/p\u003E\u003Cp\u003EEqual Opportunity Employer\u003Cbr /\u003EEnhesa is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, or any other legally protected characteristic.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"senior-security-engineer-ai-cloud-at-enhesa-460616ef8acb"},"url":"https://gurify.com/job/senior-security-engineer-ai-cloud-at-enhesa-460616ef8acb","datePosted":"2026-07-10","validThrough":"2026-10-11T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Enhesa","sameAs":"https://job-boards.greenhouse.io/enhesa"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"PT","addressLocality":"Lisbon"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"Portugal","item":"https://gurify.com/jobs/portugal"},{"@type":"ListItem","position":3,"name":"Senior Security Engineer (AI/Cloud)","item":"https://gurify.com/job/senior-security-engineer-ai-cloud-at-enhesa-460616ef8acb"}]}
```
