Senior Product Security Engineer, AI & DevSecOps

McKesson Corporation

Confirmed live today Low trust
Remote

Quick summary

Work type
Remote
Location
Columbus, OHIrving, TXOverland Park, KSAtlanta, GAAlpharetta, GA
Salary
$140,300–$233,800 / yr
Posted
1 day ago
Freshness
Confirmed live today

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $182k
This role $187k
$125k most similar roles pay here $245k

This role pays more than 60% of similar roles. Most pay $147,981–$215,178 — the shaded band above. At the midpoint, this role pays about $187k versus about $182k for comparable roles.

Based on 240 similar postings.

Employer

About McKesson Corporation

McKesson Corporation is a premier American healthcare services company that distributes pharmaceuticals, medical-surgical supplies, and provides technology to the healthcare industry.

McKesson Corporation currently has 63 open roles on FindRole.

Listed pay typically runs $126,000–$206,900 across 63 roles with salary data.

Most-posted roles

View all roles at McKesson Corporation

At a glance

TL;DR · Senior Product Security Engineer, AI & DevSecOps

Sr Product Security Engineer, AI & DevSecOps joins the team to embed security throughout the software development lifecycle with a specific focus on AI-enabled products, cloud-native platforms, and DevSecOps practices. This hands-on technical role involves partnering with engineering and product teams to translate security requirements into reusable patterns, shared services, and automated controls. The engineer will conduct threat modeling, architecture reviews, and vulnerability remediations while building automated guardrails for CI/CD pipelines. Key responsibilities include securing machine learning models, generative AI solutions, and large language model applications. Required skills include proficiency in TypeScript, Java, Ruby, or Python, along with experience in Kubernetes, infrastructure-as-code, and tools like Terraform or GitHub Actions. The role addresses the critical challenge of securing modern application architectures and cloud services while ensuring rapid, secure product delivery within a complex technical environment.

What you'll do

  • Conduct security architecture reviews, threat modeling, and secure design assessments for applications, APIs, and cloud services.
  • Assess and secure AI, machine learning, generative AI, and large language model solutions.
  • Write and review code to identify vulnerabilities and strengthen secure development practices.
  • Develop reusable security patterns, shared services, and automated guardrails for engineering teams.
  • Integrate automated security testing tools like SAST, DAST, and container scanning into CI/CD pipelines.
  • Design security controls for cloud-native applications, including Kubernetes, serverless platforms, and infrastructure-as-code.
  • Partner with engineering teams to remediate vulnerabilities and promote a security-first culture.

What we're looking for

  • Degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent professional experience.
  • Relevant experience in application security, product security, software development, security engineering, DevSecOps, or a related discipline.
  • Hands-on experience writing, reviewing, and deploying application code using TypeScript, Java, Ruby, Python, or comparable languages.
  • Experience conducting threat modeling, security architecture reviews, secure design reviews, and vulnerability remediation.
  • Experience implementing DevSecOps practices and integrating automated security controls into CI/CD pipelines.
  • Experience securing AI/ML platforms, generative AI solutions, large language model applications, or AI-assisted development workflows.
  • Experience with cloud platforms, containers, Kubernetes, infrastructure-as-code, security automation, and application security testing tools.
  • Authorized to work.

More like this

Similar roles

Senior Engineer, Product/AI Security

GEICO

Bethesda, MD +3 2 days ago $100,000–$215,000
Python AI Security Product Security RAG PostgreSQL GitHub Git CI/CD API Security Threat Modeling Pydantic Cloud Services Infrastructure Automation Cursor Claude Code GitHub Copilot MCP

Cloud Product Security Engineer

Allstate

Remote (IL) 9 days ago $90,700–$195,700
Python Java JavaScript AWS Azure CI/CD Infrastructure as Code CSPM DLP SIEM SDLC Security Engineering Cloud Security Automated Testing Data Loss Prevention Encryption Logging
Remote

Senior Staff Product Security Engineer, AI

PayPal

Chicago, IL +1 14 days ago $178,500–$265,100
AI Security SAST DAST SCA WAF Burp Suite Ruby Java Python JavaScript Swift Kubernetes Terraform Git AWS Azure GCP OAuth 2.0 SAML CI/CD
8+ yrs exp Hybrid

Senior Staff Product Security Engineer, AI

PayPal

Chicago, IL +1 14 days ago $178,500–$265,100
AI Security SAST DAST SCA WAF Burp Suite Python Java Ruby JavaScript Swift Kubernetes Terraform Git AWS Azure GCP OAuth 2.0 SAML CI/CD
8+ yrs exp Hybrid

Distinguished Engineer, Application Security

CVS Health

Remote (AZ) 1 day ago $175,100–$334,750
SAST DAST SCA IAST RASP ASPM CI/CD Kubernetes Python Go Java TypeScript JavaScript C# REST GraphQL gRPC eBPF OWASP ASVS NIST SSDF SBOM SLSA GitHub Actions GitLab CI Jenkins Argo
10+ yrs exp Remote

DevSecOps Engineer

Booz Allen Hamilton

Washington, DC 38 days ago $77,600–$176,000
DevSecOps CI/CD AWS Azure GCP Terraform CloudFormation CDK Docker Kubernetes Python Bash Go GitLab CI GitHub Actions PostgreSQL MySQL MongoDB Oracle Ansible Prometheus Grafana ELK Helmfile Flux Argo CD IaC SAST SCA
8+ yrs exp