24 ΡΠ°ΡΠ° Π½Π°Π·Π°Π΄
Application Security Engineer (AI)
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
Π’Π΅ΠΊΡΡ:
TL;DR
Application Security Engineer (AI/Vulnerability Management): Building and improving an engineering-driven vulnerability management program across applications, dependencies, containers, operating systems, cloud infrastructure, and externally exposed services with an accent on risk-based prioritization, validation, and remediation. Focus on automating security workflows, integrating SAST/SCA and related controls into CI/CD, investigating exploitability, and addressing recurring vulnerability classes.
Location: Sunnyvale, California, United States; hybrid
Company
builds large-scale AI hardware and platforms designed to deliver high-speed model training and inference.
What you will do
- Own and continuously improve vulnerability management across applications, software dependencies, containers, operating systems, cloud infrastructure, and externally exposed services.
- Analyze vulnerabilities using exploitability, exposure, asset criticality, mitigations, threat intelligence, and business impact rather than scanner severity alone.
- Partner with engineering, infrastructure, IT, and security teams to triage findings, define remediation, and meet risk-based SLAs.
- Build automation for vulnerability ingestion, deduplication, enrichment, prioritization, assignment, tracking, and reporting.
- Operate application security capabilities including SAST, SCA, secrets detection, container and infrastructure scanning, and external attack-surface monitoring.
- Validate findings through technical investigation and hands-on testing, conduct targeted security reviews, and support incident response for actively exploited vulnerabilities.
Requirements
- Strong application or product security fundamentals and hands-on vulnerability management experience.
- Understanding of vulnerability classes and exploitation techniques across web applications, APIs, authentication systems, cloud services, containers, and software supply chains.
- Ability to read and reason about code and work with software engineers on practical remediation.
- Experience with SAST, SCA, DAST, secrets scanning, container scanning, or CSPM tools.
- Ability to automate security workflows with Python, Go, or similar languages and integrate security tooling into CI/CD.
- Comfort working with Linux, Git, containers, cloud environments, and communicating security risk to technical teams.
Nice to have
- Experience securing AI/ML platforms, inference services, or large-scale compute infrastructure.
- Experience with AWS, Kubernetes, Docker, software supply-chain security, GitHub, and CI/CD security.
- Background in threat modeling, secure design reviews, penetration testing, offensive security, or vulnerability research.
- Experience with security data pipelines, APIs, workflow automation, external attack-surface management, or AI-assisted security tooling.
Culture & Benefits
- Work on an AI platform designed beyond the constraints of traditional GPU architectures.
- Opportunity to contribute to cutting-edge AI research and open-source projects.
- Startup vitality combined with job stability.
- Non-corporate work culture focused on individual beliefs, learning, growth, and inclusion.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β