Job Role – AI Developer – Remote

  • Engineering
  • Anywhere

Info

Location: UK (Anywhere) Fully remote/ Spain

Type: Full-time

Salary: Competitive, plus equity – based on experience

Phoenix Security is looking for an Experienced Backend Developer to join an exciting project on application security.

Company Brief

Phoenix Security is a cybersecurity start-up that is working on an exciting new product and looking for a Backend Developer to join our team. You will be working on our new product, Phoenix Security, that is disrupting the world of vulnerability management, application security and cloud security. We are looking for a candidate who wants to work in a very dynamic and flexible way, can self-manage, and is comfortable working on a start-up.

Phoenix Security helps CIO/CTO/CISO and developers talk the same language when it comes to vulnerability management. The Phoenix Security platform enables a clear view on vulnerabilities and contextualization of those within applications, with enriched information like cost of the application and risk in relation to the importance level of the application.

We don’t work in a traditional way. Fully remote, fully distributed, fully around you. We are delivery-oriented and work around your life rather than the other way around.

Product Page: https://phoenix.security/

Overview: https://youtu.be/KMVwlyvNedc
Platform Overview: https://youtu.be/Uw8oLO8p6Z4
Why We created Phoenix: https://youtu.be/npluMSLy-lE

Perks

  • Fully remote
  • Work from anywhere
  • Flexible working hours
  • Great and relaxed work environment
  • Holidays
  • Travel to London and food fully expensed

Job brief

We are looking for a Senior Backend Developer / AI Platform Engineer to help take our application to the next level in Application Security Posture Management.

The ideal candidate is a strong backend developer with experience building APIs and services using Kotlin with Spring Boot, while also being comfortable working with other stacks such as Python, Go, Rust, or similar technologies.

This role is not just about integrating with an LLM API. We are looking for someone who understands how to build and operate production AI-powered backend services. You should be comfortable designing services that interact with models and LLMs, manage prompt workflows, track token usage, optimise AI costs, monitor model performance, and build reliable AI-assisted features.

You will work with the wider development team to implement functional changes and improvements to the Phoenix Security platform. Ultimately, you will create scalable, reliable, and useful features that address our clients’ needs, improve vulnerability management workflows, and help us grow our customer base.

Knowledge of cybersecurity, application security, vulnerability management, DevSecOps, or cloud security is highly welcomed.

Tech Stack

  • Kotlin, Go, Python, Rust or similar backend languages
  • Spring Boot and other backend frameworks
  • REST APIs, service-oriented architecture, and event-driven services
  • LLM APIs and ecosystems, including SDKs, streaming responses, tool/function calling, prompt engineering, and orchestration
  • AI platforms such as OpenAI, Anthropic Claude, Google Gemini, Vertex AI, Amazon Bedrock, Azure OpenAI or similar
  • Prompt management, prompt versioning, prompt testing, and response quality evaluation
  • Token usage tracking, cost monitoring, rate-limit handling, retries, caching, and observability
  • Retrieval Augmented Generation, embeddings, vector search, semantic retrieval, and context optimisation
  • AWS deployments, including ECS, EKS, containers, IAM, CloudWatch, queues, and serverless components
  • Cloud AI services such as Amazon Bedrock, Google Vertex AI, Gemini APIs, Azure AI Services or Azure OpenAI
  • Databases, especially PostgreSQL
  • GCP and Azure exposure useful
  • GitHub, Jira, Confluence and GitHub Projects

Responsibilities

  • Work independently on defined requirements, stories, and technical deliverables
  • Design and implement backend services for AI and LLM-powered features
  • Build APIs and services using Kotlin, Spring Boot, and other appropriate backend technologies
  • Integrate with LLM providers and AI platforms such as OpenAI, Claude, Gemini, Vertex AI, Bedrock, or Azure OpenAI
  • Design AI workflows that manage prompt execution, context, model responses, validation, and fallback logic
  • Build systems to track and optimise token usage, latency, throughput, model costs, and provider reliability
  • Fine-tune and continuously improve prompts, prompt chains, and response quality
  • Implement prompt versioning, AI observability, logging, evaluation, and regression testing
  • Design safe and auditable AI workflows with clear human oversight and security controls
  • Support AI-assisted vulnerability analysis, remediation recommendations, contextualisation, and prioritisation workflows
  • Collaborate with the wider team to improve implementation velocity and engineering effectiveness
  • Propose functional and technical alternatives relevant to the work at hand
  • Identify, troubleshoot, and resolve backend, API, AI integration, and production issues
  • Collaborate in architectural discussions and technical decisions
  • Contribute to the long-term AI platform and backend architecture of Phoenix Security

Requirements

  • Demonstrable backend development experience in production environments
  • Strong experience building APIs, services, integrations, and backend systems
  • Experience with Kotlin and Spring Boot preferred
  • Experience with Python, Go, Rust, or similar backend languages useful
  • Practical experience integrating with LLM APIs or AI platforms
  • Understanding of LLM workflows, prompt engineering, prompt optimisation, and response validation
  • Experience managing token usage, API limits, retries, latency, throughput, and operational cost
  • Experience with cloud-native deployments, containers, and production observability
  • Familiarity with AWS services such as ECS, EKS, IAM, CloudWatch, queues, or serverless workloads
  • Exposure to cloud AI platforms such as Amazon Bedrock, Google Vertex AI, Gemini APIs, Azure AI Services, or Azure OpenAI
  • Familiarity with RAG, embeddings, vector databases, semantic search, or AI orchestration patterns
  • Experience with AI coding tools and techniques such as Claude Code, Codex, Cursor, agents, skills, or similar
  • Excellent client-facing and internal communication skills
  • Approachable, pragmatic, and comfortable working in a fast-moving start-up environment
  • Portfolio of implemented projects
  • Familiar with API design and production-grade integration patterns
  • Team spirit and strong communication skills to collaborate with various stakeholders
  • Excellent time-management skills and ability to self-manage
  • BSc in Computer Science or relevant field, or equivalent practical experience
  • Knowledge of Jira, Confluence, GitHub, and GitHub Projects

Nice to Have

  • Knowledge of cybersecurity, application security, DevSecOps, vulnerability management, ASPM, cloud security, or supply chain security
  • Experience building AI copilots, AI agents, or AI-assisted developer/security workflows
  • Experience with model routing, multi-model architectures, semantic caching, or prompt compression
  • Experience with open-source models such as Llama, Mistral, Qwen, DeepSeek, BERT, or RoBERTa
  • Experience with AI evaluation frameworks, benchmarking, hallucination testing, or quality scoring
  • Familiarity with OWASP Top 10 for LLM Applications and secure AI development practices
  • Experience working with security-sensitive data, regulated environments, or audit-heavy workflows
  • Experience with graph databases, knowledge graphs, or dependency/risk graph modelling

What Success Looks Like

  • Backend services are reliable, scalable, observable, and maintainable
  • LLM integrations are production-ready, secure, and cost-controlled
  • Token usage is tracked, measured, and optimised
  • Prompts are versioned, tested, and continuously improved
  • AI responses are evaluated for accuracy, consistency, and usefulness
  • AI workflows include validation, fallback logic, and human oversight where needed
  • AI-assisted features help customers reduce noise, prioritise risk, and accelerate remediation
  • The engineering team can ship AI-powered features faster without losing control of quality, cost, or security

 

 

To apply for this job email your details to fc@appsecphoenix.com.

Benefits to work with us

Discuss this blog with our community on Slack

Join our AppSec Phoenix community on Slack to discuss this blog and other news with our professional security team

Derek

Derek Fisher

Head of product security at a global fintech

Derek Fisher – Head of product security at a global fintech. Speaker, instructor, and author in application security.

Derek is an award winning author of a children’s book series in cybersecurity as well as the author of “The Application Security Handbook.” He is a university instructor at Temple University where he teaches software development security to undergraduate and graduate students. He is a speaker on topics in the cybersecurity space and has led teams, large and small, at organizations in the healthcare and financial industries. He has built and matured information security teams as well as implemented organizational information security strategies to reduce the organizations risk.

Derek got his start in the hardware engineering space where he learned about designing circuits and building assemblies for commercial and military applications. He later pursued a computer science degree in order to advance a career in software development. This is where Derek was introduced to cybersecurity and soon caught the bug. He found a mentor to help him grow in cybersecurity and then pursued a graduate degree in the subject.

Since then Derek has worked in the product security space as an architect and leader. He has led teams to deliver more secure software in organizations from multiple industries. His focus has been to raise the security awareness of the engineering organization while maintaining a practice of secure code development, delivery, and operations.

In his role, Jeevan handles a range of tasks, from architecting security solutions to collaborating with Engineering Leadership to address security vulnerabilities at scale and embed security into the fabric of the organization.

Jeevan Singh

Jeevan Singh

Founder of Manicode Security

Jeevan Singh is the Director of Security Engineering at Rippling, with a background spanning various Engineering and Security leadership roles over the course of his career. He’s dedicated to the integration of security practices into software development, working to create a security-aware culture within organizations and imparting security best practices to the team.
In his role, Jeevan handles a range of tasks, from architecting security solutions to collaborating with Engineering Leadership to address security vulnerabilities at scale and embed security into the fabric of the organization.

James

James Berthoty

Founder of Latio Tech

James Berthoty has over ten years of experience across product and security domains. He founded Latio Tech to help companies find the right security tools for their needs without vendor bias.

christophe

Christophe Parisel

Senior Cloud Security Architect

Senior Cloud Security Architect

Chris

Chris Romeo

Co-Founder
Security Journey

Chris Romeo is a leading voice and thinker in application security, threat modeling, and security champions and the CEO of Devici and General Partner at Kerr Ventures. Chris hosts the award-winning “Application Security Podcast,” “The Security Table,” and “The Threat Modeling Podcast” and is a highly rated industry speaker and trainer, featured at the RSA Conference, the AppSec Village @ DefCon, OWASP Global AppSec, ISC2 Security Congress, InfoSec World and All Day DevOps. Chris founded Security Journey, a security education company, leading to an exit in 2022. Chris was the Chief Security Advocate at Cisco, spreading security knowledge through education and champion programs. Chris has twenty-six years of security experience, holding positions across the gamut, including application security, security engineering, incident response, and various Executive roles. Chris holds the CISSP and CSSLP certifications.

jim

Jim Manico

Founder of Manicode Security

Jim Manico is the founder of Manicode Security, where he trains software developers on secure coding and security engineering. Jim is also the founder of Brakeman Security, Inc. and an investor/advisor for Signal Sciences. He is the author of Iron-Clad Java: Building Secure Web Applications (McGraw-Hill), a frequent speaker on secure software practices, and a member of the JavaOne Rockstar speaker community. Jim is also a volunteer for and former board member of the OWASP foundation.

Join our Mailing list!

Get all the latest news, exclusive deals, and feature updates.

The IKIGAI concept
Protected By
Shield Security PRO