Назад
Company hidden
8 часов назад

Senior Application Security Engineer

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US/Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (AWS/Java/TypeScript): Building security tooling and automation while protecting applications handling customer data, payments, and multi-tenant authorization boundaries with an accent on threat modeling, secure design, and vulnerability remediation. Focus on strengthening AWS IAM and cloud-native security, preventing authorization flaws, and establishing secure engineering standards and developer guardrails.

Location: Austin, Texas — hybrid, with in-office work on Monday, Wednesday, and Friday. U.S.-based candidates must reside in one of hirify.global’s approved states; hiring is also available in Canada.

Company

hirify.global operates an AI-native platform for charter transportation, shuttle, transit, and emerging autonomous vehicle operations.

What you will do

  • Own security tooling and vulnerability management across SAST, dependency and container scanning, secret detection, and penetration testing.
  • Lead security design reviews, threat modeling, and targeted manual code reviews for authentication, authorization, payment, and customer-data systems.
  • Identify and prevent multi-tenant authorization vulnerabilities across quoting, booking, and trip workflows.
  • Strengthen AWS security through IAM, account boundaries, secrets management, workload protection, and comprehensive logging.
  • Build secure defaults, reusable libraries, automation, developer guardrails, and a security champions practice.

Requirements

  • 5+ years of experience in software engineering or security, including 3+ years in application or product security.
  • Strong software engineering skills in Java and/or TypeScript, including production-grade security tooling and automation.
  • Deep knowledge of threat modeling, secure system design, authentication, authorization, access control, injection, SSRF, and manual code review.
  • Hands-on AWS and cloud-native security experience, including IAM, multi-account architecture, containerized workloads, CI/CD security, and vulnerability management.
  • Strong technical judgment and influence, with the ability to define standards, prioritize risk, and drive remediation without direct authority.

Nice to have

  • Familiarity with SOC 2, PCI DSS, and GDPR.

Culture & Benefits

  • Remote-first company with role-specific in-office requirements.
  • Medical, dental, and vision insurance, mental health support, virtual care, gym discounts, and family-building benefits.
  • Paid time off and paid holidays; policies vary by country.
  • Life and disability insurance where available, plus region-specific financial planning programs.
  • Mac or PC with a monitor, keyboard, and mouse.

Hiring process

  • Talent Acquisition video interview.
  • Technical video interview followed by team interviews.
  • Offer and reference check.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →