McKesson

Sr Product Security Engineer, AI & DevSecOps

McKesson
Apply
1 day ago
Remote, United States +4 moreSenior
H1B sponsor

Base Salary

$140k - $234k/yr

Responsibilities

  • Conduct security architecture reviews, threat modeling, security assessments, and secure design reviews for applications, APIs, cloud services, and AI-enabled systems.
  • Define and implement security requirements, standards, reusable design patterns, and security guardrails throughout the software development lifecycle.
  • Partner with engineering teams to identify and remediate vulnerabilities and strengthen secure coding practices.
  • Assess and secure AI, machine learning, generative AI, large language model, and data science solutions.
  • Design and implement security controls for cloud-native applications, containers, Kubernetes, serverless platforms, and infrastructure-as-code deployments.
  • Integrate SAST, DAST, software composition analysis, secrets detection, container scanning, and infrastructure scanning into CI/CD pipelines.
  • Develop security automation using scripting, infrastructure-as-code, policy-as-code, and compliance-as-code technologies.
  • Support identity and access management, secrets management, cloud security monitoring, vulnerability management, and incident response activities.
  • Contribute to compliance initiatives, security metrics, risk reporting, and continuous improvement.
  • Provide technical guidance on secure development practices and promote a security-first engineering culture.

Requirements

  • Bachelor’s degree or equivalent experience in Computer Science, Information Security, Engineering, or a related technical field.
  • Typically 7+ years of relevant experience in application security, product security, security engineering, or a related cybersecurity discipline.
  • Experience with security architecture reviews, threat modeling, secure design reviews, and vulnerability remediation.
  • Experience implementing DevSecOps practices and integrating security controls into CI/CD pipelines.
  • Experience securing AI/ML platforms, generative AI solutions, large language model applications, or data science workflows.
  • Experience with secure software development lifecycle practices, vulnerability management, and Agile development methodologies.
  • Experience with Microsoft Azure, AWS, or Google Cloud Platform and cloud-native technologies including containers and Kubernetes.
  • Experience with Terraform and CI/CD technologies such as GitHub Actions, Azure DevOps, GitLab, Jenkins, or similar tools.
  • Proficiency in Python, PowerShell, Bash, or comparable scripting languages.
  • Experience with SAST, DAST, software composition analysis, container security, secrets detection, and infrastructure scanning.
  • Preferred experience includes OWASP Top 10 for LLM Applications, the NIST AI Risk Management Framework, policy-as-code, compliance-as-code, SOAR platforms, and frameworks such as SOC 2, HIPAA, SOX, NIST Cybersecurity Framework, or ISO 27001.
  • Ability to communicate technical risks and tradeoffs, influence across teams, contribute to technical standards, and promote secure engineering practices.

Tech Stack

Categories

McKesson

About McKesson

10,000+ employees

McKesson is a public healthcare company that distributes pharmaceuticals and medical‑surgical supplies and provides pharmacy and provider technology and services. It sells to pharmacies, hospitals, health systems, and biopharma manufacturers through logistics, specialty and oncology support, pharmacy management, and healthcare IT/analytics offerings. Founded in 1833 and headquartered in Irving, Texas, it trades on the NYSE under the ticker MCK.

Contact me