Назад
Company hidden
16 часов назад

Sr. Engineer, Application Security - USA Remote

150 000 - 200 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Sr. Engineer, Application Security (SAST/DAST/SCA): Engineering application security testing and secure-by-design guardrails across product and platform teams with an accent on SDLC integration, CI/CD automation, and vulnerability remediation. Focus on threat modeling, policy-as-code, software supply chain security, and securing cloud-native, API, mobile, and containerized applications.

Location: USA - Remote; approximately 15% overnight travel within the territory or to other hirify.global locations.

Annual salary: $150,000–$200,000.

Company

hirify.global is a global science and technology company operating across life sciences, diagnostics, and biotechnology businesses.

What you will do

  • Engineer application security testing at scale, including SAST, DAST, SCA, secret scanning, IaC scanning, API and mobile security, and container/cloud-native application security.
  • Integrate security testing and controls into CI/CD pipelines.
  • Contribute secure-by-design patterns, paved roads, and release risk gates for product engineering teams.
  • Build automation, pipeline integrations, and policy-as-code guardrails to increase security coverage.
  • Support secure-coding standards, SBOM and open-source risk processes, and vulnerability disclosure or bug-bounty intake workflows.

Requirements

  • 9+ years of experience in application or product security, or security-focused software engineering.
  • Hands-on experience with secure design reviews, threat modeling, code reviews, and application security testing.
  • Experience with tools such as Snyk, Veracode, Checkmarx, Semgrep, or GitHub Advanced Security in CI/CD pipelines.
  • Ability to work independently with product engineering teams to remediate vulnerabilities and adopt secure-by-design patterns.

Nice to have

  • Bachelor’s degree in Cybersecurity, Computer Science, Software Engineering, or a related field.
  • Cloud-native or Kubernetes security, API security, software supply chain security, or SBOM experience.
  • CSSLP, GWAPT, GWEB, OSWE, OSCP, or cloud security certification.
  • Experience with AI/LLM application security.

Culture & Benefits

  • Fully remote work arrangement from the employee’s home.
  • Medical, dental, and vision insurance.
  • Paid time off.
  • 401(k) benefits for eligible employees.
  • Culture focused on continuous improvement, belonging, and internal career development.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →