Qualcomm
San Diego, CA

Product Security Engineer – AI Software Development

Onsite$141,000 - $211,000/yrPosted 2 weeks agoVisa Sponsorship

We tailor your resume to this role and apply for you in seconds.

Apply to Product Security Engineer – AI Software Development at Qualcomm

Job details

Location
San Diego, CA
Work type
Onsite
Compensation
$141,000 - $211,000/yr
Visa
Sponsorship available
Posted
2 weeks ago
Apply on
qualcomm.eightfold.ai

About this role

Qualcomm is a global technology innovator enabling next-generation experiences through its AI software engineering engine. The Product Security Engineer will evaluate system architectures for security gaps, conduct security assessments, and build automated security tools to ensure the resilience and trustworthiness of AI software.

What you'll do:

  • Evaluate AISW Team’s products for security gaps early in the development lifecycle, partnering with engineering teams from ideation through release
  • Conduct security design reviews, threat modeling sessions, and architecture assessments to surface attack surfaces and trust-boundary risks
  • Monitor the threat landscape to identify newly disclosed vulnerabilities, adversarial techniques, and emerging attack patterns relevant to AISW products
  • Leverage threat intelligence to inform adversary emulation scenarios, including campaign design, TTP selection aligned with MITRE ATT&CK, and operational sequencing
  • Develop and maintain automated solutions for threat emulation, improving accuracy and efficiency in detection validation
  • Analyze telemetry generated from simulations to assess detection coverage, identify gaps, and recommend improvements
  • Develop and maintain security guidance documentation including policies, procedures, and best practices as a living reference for the AISW organization
  • Systematically discover, validate, triage, and track security vulnerabilities from internal teams, automated scanners, and external security researchers
  • Manage the full vulnerability lifecycle; from initial report through rescan validation, applying concepts such as severity scoring (CVSS), KEV prioritization, risk acceptance, ownership assignment, and aging governance
  • Support zero-day escalation events: rapidly iterate through the VM lifecycle, produce custom impact reports, and drive time-sensitive remediation decisions
  • Apply working knowledge of DevSecOps tooling including SAST, SCA, DAST, container scanning, secrets scanning, and SBOM generation
  • Continuously hunt for exploitable vulnerabilities across applications, infrastructure, developer toolchains, and AI model pipelines

What they're looking for:

  • Bachelor's degree in Computer Science, Engineering, Information Systems, or related field and 2+ years of Hardware Engineering, Software Engineering, Systems Engineering, or related work experience
  • OR Master's degree in Computer Science, Engineering, Information Systems, or related field and 1+ year of Hardware Engineering, Software Engineering, Systems Engineering, or related work experience
  • OR PhD in Computer Science, Engineering, Information Systems, or related field
  • Master's degree in Computer Science, Cybersecurity, Electrical Engineering, or a related field
  • 2+ years of experience in offensive or product security roles, inclusive of software development experience
  • 2+ years of hands-on penetration testing, product security assessment, application security, cloud security, or equivalent offensive security experience
  • Experience performing security activities across one or more SDLC phases: security design review, threat modeling, secure code review, and security testing
  • Experience building or evaluating AI-driven vulnerability discovery pipelines
  • Experience with reverse engineering and low-level systems analysis (IDA Pro, Ghidra, LLDB)
  • Proficiency in Python and/or C/C++; experience with scripting for security automation and code review
  • Familiarity with DevSecOps tooling: SAST, SCA, DAST, container scanning, secrets scanning, and SBOM tooling
  • Working knowledge of vulnerability management concepts: CVSS, KEV, false positives, rescan validation, risk acceptance, and dependency management

Benefits:

  • Competitive annual discretionary bonus program
  • Opportunity for annual RSU grants (employees on sales-incentive plans are not eligible for our annual bonus)
  • Highly competitive benefits package is designed to support your success at work, at home, and at play
Ready to apply to Qualcomm?
We tailor your resume to this role and apply for you.

About Qualcomm

Qualcomm
San Diego, CA