Product Security Engineer, Agentic AI
Lenovo · Bengaluru
- Experience7–8 yrs
- SalaryNot disclosed
- Work modeonsite
- Posted26 Sept 2026
About Lenovo
Lenovo is hiring in Bengaluru in technology software. This role looks for around 7+ years of experience.
Skills
- Python
- Go
- CISSP
- OWASP LLM Top Ten
- MITRE ATLAS
- NIST AI Risk Management Framework
- AI threat modeling
- Prompt injection
- Agentic AI
- Application security
- Cloud security
- API gateways
- Access controls
- Infrastructure as Code
- CI/CD
- Containers
- Authentication
- Secrets management
- Observability
- Incident response
- Vulnerability management
- Threat modeling
The role
A product security engineer at a technology company designs and secures agentic AI products using AI threat modeling, cloud security, and application security. The role builds production systems with access controls and AI governance.
Full job description
We are Lenovo. We do what we say. We own what we do. We WOW our customers.
Lenovo is a US$83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world’s largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo’s continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).
This transformation together with Lenovo’s world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.
In this role, you will
Own security architecture and threat modeling for the agentic AI offering as a core part of the product roadmap, from early design through general availability and sustaining engineering.Build guardrails, sandboxing, and hardening directly into the product: agent tool-calling, prompt handling, and data access paths engineered in, not audited after the fact.Participate in design reviews and sprint planning alongside the engineers building agent orchestration, integrations, and platform features; security is planned and estimated like any other engineering work, not a separate gate.Write and maintain the product’s living threat model, using frameworks including OWASP’s LLM Top 10, MITRE ATLAS, and the NIST AI Risk Management Framework, updated every release rather than once a year.Review teammates’ code and architecture for security issues, including tool-calling risk, prompt injection, excessive agency, and data exfiltration, as a standard part of the team’s engineering process.Build the product’s governance and access control features, including agent identity, least-privilege permissions, and audit logging, as shippable capabilities of the product itself rather than side tooling.Own production security for the shipped product in managed services: monitoring, incident response, and vulnerability management for live deployments.Publish reference architectures and paved-road patterns that let pre-sales and delivery teams field the product safely, extending OAE’s mission of arming field teams with field-ready IP.Contribute to product roadmap and prioritization decisions from a security and reliability lens, the same way any senior engineer on the team would.
Qualifications
7+ years of experience as a product or platform engineer with a security specialization, or as a security engineer who has shipped production features as part of a product engineering team, with strong coding proficiency (for example, Python or Go).We are looking for a CISSP certification with a specialization in Agentic AI. We care about what you have built and what you can do; self-taught practitioners and career changers are welcome. A genuine AI builder: you have shipped agents, tools, or automations with large language models as part of a real product and can walk through the hard parts.Experience building real backends and infrastructure, not just demos: APIs, data pipelines, authentication and secrets management, hosting and deployment (containers, Infrastructure-as-Code, CI/CD), and systems integration, made reliable with observability, evaluations, and graceful failure handling. Deep knowledge of the AI threat landscape, including frameworks such as OWASP’s LLM Top 10, MITRE ATLAS, and the NIST AI Risk Management Framework, with practical experience addressing prompt injections, excessive agency, and related agentic AI risks.Experience securing or auditing agentic frameworks and tool-calling or MCP-style integrations operating in sandboxed environments.Proven ability to design scalable cloud infrastructure, API gateways, proxy architecture, and access controls for enterprise systems.Comfortable working within a product team’s sprint cadence, design review process, and release cycle, contributing as a shipping engineer rather than an embedded auditor.Enough software and security foundation to build and secure production systems, with sound judgment on data handling and safe AI usage.
Preferred Skills
Experience as a product or feature engineer who happens to specialize in security, rather than a security specialist who occasionally writes code. Experience with AI governance, data loss prevention, monitoring and logging, or guardrail tooling for AI usage at product scale.Experience building and hosting AI solutions in the cloud.A security background in application security, cloud security, or data protection.Experience with agentic frameworks such as LangChain, LlamaIndex, CrewAI, AutoGen, or Semantic Kernel.Track record building developer-first security tools and platform controls that preserve engineering velocity.Experience mentoring engineers or driving technical alignment across security, platform, and product teams.Experience enabling field or partner teams, such as pre-sales, delivery, or professional services, to safely adopt a shipped product.
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.