Назад
Company hidden
11 дней назад

Engineer II, Cybersecurity - Application Security

80 600 - 120 900$
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Engineer II, Cybersecurity - Application Security (SAST/DAST, API Security, Container Security): Implementing, operating, and improving application security capabilities for a national automotive retail brand with an accent on static and dynamic analysis, API protection, and container security. Focus on integrating security into cloud and container lifecycles, troubleshooting complex security issues, and supporting DevSecOps capabilities through cross-functional projects and on-call operations.

Location: Richmond, Virginia; onsite at the hirify.global West Creek Home Office four days per week. Applicants must be currently authorized to work full-time in the United States.

Annual salary: $80,600–$120,900, with possible bonus and equity.

Company

hirify.global is a national used-car retailer with more than 200 locations and over 25,000 associates.

What you will do

  • Implement, develop, operate, and improve application security capabilities, including static and dynamic analysis, API security, and container security.
  • Provide functional and technical expertise on projects with application security implications.
  • Understand how hirify.global cybersecurity capabilities work together to protect the enterprise.
  • Drive security tasks and projects to completion through planning, customer interaction, and cross-functional collaboration.
  • Triage support issues and respond with the appropriate urgency.
  • Participate in a scheduled 24/7 on-call rotation, currently approximately three weeks per year.

Requirements

  • Strong foundations in cybersecurity and at least two years of relevant cybersecurity experience.
  • Bachelor’s degree in computer science, engineering, cybersecurity, or a related field, or equivalent practical experience.
  • Functional knowledge of at least one coding or scripting language, such as PowerShell, Python, .NET, JavaScript, or C#.
  • Experience with developer tools such as GitHub, Azure DevOps, and TeamCity.
  • Experience with public cloud platforms such as Azure, AWS, or GCP, plus knowledge of DevSecOps practices.
  • Current full-time U.S. work authorization and the ability to work onsite in Richmond four days per week are required.

Nice to have

  • Experience with DAST using open-source or commercial tools.
  • Experience with SAST and communicating remediation recommendations to stakeholders.
  • Experience integrating security into container lifecycles, including image assurance, Kubernetes posture management, secrets management, and runtime threat detection.
  • CISSP certification.

Culture & Benefits

  • Collaborative environment focused on solving complex security challenges and supporting product innovation.
  • Inclusive workplace committed to training, diversity, and career development.
  • Paid sick, vacation, and holiday time for eligible full-time associates.
  • Potential bonus and equity eligibility.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →