Назад
Company hidden
24 часа Π½Π°Π·Π°Π΄

Application Security Engineer (AI)

Π€ΠΎΡ€ΠΌΠ°Ρ‚ Ρ€Π°Π±ΠΎΡ‚Ρ‹
hybrid
Π’ΠΈΠΏ Ρ€Π°Π±ΠΎΡ‚Ρ‹
fulltime
Английский
b2
Π‘Ρ‚Ρ€Π°Π½Π°
US
Вакансия ΠΈΠ· списка Hirify.GlobalВакансия ΠΈΠ· Hirify Global, списка ΠΌΠ΅ΠΆΠ΄ΡƒΠ½Π°Ρ€ΠΎΠ΄Π½Ρ‹Ρ… tech-ΠΊΠΎΠΌΠΏΠ°Π½ΠΈΠΉ
Для мэтча ΠΈ ΠΎΡ‚ΠΊΠ»ΠΈΠΊΠ° Π½ΡƒΠΆΠ΅Π½ Plus

ΠœΡΡ‚Ρ‡ & Π‘ΠΎΠΏΡ€ΠΎΠ²ΠΎΠ΄

Для мэтча с этой вакансиСй Π½ΡƒΠΆΠ΅Π½ Plus

ОписаниС вакансии

ВСкст:
/
TL;DR
Application Security Engineer (AI/Vulnerability Management): Building and improving an engineering-driven vulnerability management program across applications, dependencies, containers, operating systems, cloud infrastructure, and externally exposed services with an accent on risk-based prioritization, validation, and remediation. Focus on automating security workflows, integrating SAST/SCA and related controls into CI/CD, investigating exploitability, and addressing recurring vulnerability classes.

Location: Sunnyvale, California, United States; hybrid

Company

hirify.global builds large-scale AI hardware and platforms designed to deliver high-speed model training and inference.

What you will do

  • Own and continuously improve vulnerability management across applications, software dependencies, containers, operating systems, cloud infrastructure, and externally exposed services.
  • Analyze vulnerabilities using exploitability, exposure, asset criticality, mitigations, threat intelligence, and business impact rather than scanner severity alone.
  • Partner with engineering, infrastructure, IT, and security teams to triage findings, define remediation, and meet risk-based SLAs.
  • Build automation for vulnerability ingestion, deduplication, enrichment, prioritization, assignment, tracking, and reporting.
  • Operate application security capabilities including SAST, SCA, secrets detection, container and infrastructure scanning, and external attack-surface monitoring.
  • Validate findings through technical investigation and hands-on testing, conduct targeted security reviews, and support incident response for actively exploited vulnerabilities.

Requirements

  • Strong application or product security fundamentals and hands-on vulnerability management experience.
  • Understanding of vulnerability classes and exploitation techniques across web applications, APIs, authentication systems, cloud services, containers, and software supply chains.
  • Ability to read and reason about code and work with software engineers on practical remediation.
  • Experience with SAST, SCA, DAST, secrets scanning, container scanning, or CSPM tools.
  • Ability to automate security workflows with Python, Go, or similar languages and integrate security tooling into CI/CD.
  • Comfort working with Linux, Git, containers, cloud environments, and communicating security risk to technical teams.

Nice to have

  • Experience securing AI/ML platforms, inference services, or large-scale compute infrastructure.
  • Experience with AWS, Kubernetes, Docker, software supply-chain security, GitHub, and CI/CD security.
  • Background in threat modeling, secure design reviews, penetration testing, offensive security, or vulnerability research.
  • Experience with security data pipelines, APIs, workflow automation, external attack-surface management, or AI-assisted security tooling.

Culture & Benefits

  • Work on an AI platform designed beyond the constraints of traditional GPU architectures.
  • Opportunity to contribute to cutting-edge AI research and open-source projects.
  • Startup vitality combined with job stability.
  • Non-corporate work culture focused on individual beliefs, learning, growth, and inclusion.

Π‘ΡƒΠ΄ΡŒΡ‚Π΅ остороТны: Ссли Ρ€Π°Π±ΠΎΡ‚ΠΎΠ΄Π°Ρ‚Π΅Π»ΡŒ просит Π²ΠΎΠΉΡ‚ΠΈ Π² ΠΈΡ… систСму, ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡ iCloud/Google, ΠΏΡ€ΠΈΡΠ»Π°Ρ‚ΡŒ ΠΊΠΎΠ΄/ΠΏΠ°Ρ€ΠΎΠ»ΡŒ, Π·Π°ΠΏΡƒΡΡ‚ΠΈΡ‚ΡŒ ΠΊΠΎΠ΄/ПО, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡ‚Π΅ этого - это мошСнники. ΠžΠ±ΡΠ·Π°Ρ‚Π΅Π»ΡŒΠ½ΠΎ ΠΆΠΌΠΈΡ‚Π΅ "ΠŸΠΎΠΆΠ°Π»ΠΎΠ²Π°Ρ‚ΡŒΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡˆΠΈΡ‚Π΅ Π² ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΡƒ. ΠŸΠΎΠ΄Ρ€ΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β†’