Назад
Company hidden
1 день назад

Engineering-L2-Warsaw-Vice President-Secure SDLC Lead (AI)

Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US/Poland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Secure SDLC Lead (AI): Leading the firm's Secure Software Development Lifecycle strategy and embedding application security controls across global engineering teams with an accent on SAST, DAST, CI/CD integration, and security-by-design. Focus on threat modelling, application risk assessment, AI-enabled security testing, and mentoring security engineers.

Location: Warsaw, Mazowieckie, Poland

Company

hirify.global is a global investment banking, securities, and investment management firm with offices around the world.

What you will do

  • Lead and evolve the firm's Secure Software Development Lifecycle strategy across global engineering teams.
  • Drive application security controls and security-by-design practices across SDLC, CI/CD pipelines, and modern engineering workflows.
  • Lead application security reviews, threat modelling, security testing programmes, and application risk assessments.
  • Oversee SAST, DAST, and emerging AI-enabled security testing capabilities.
  • Partner with engineering, product, and technology stakeholders to improve developer security practices and remediation prioritization.
  • Mentor security engineers and promote an application security culture across the firm.

Requirements

  • 7+ years of experience in Application Security, Secure SDLC, DevSecOps, or Product Security.
  • Strong understanding of Secure SDLC principles, software development practices, threat modelling, vulnerability management, and application risk assessment.
  • Hands-on experience with application security and security testing methodologies, including SAST and DAST.
  • Experience integrating security controls into CI/CD pipelines and modern engineering workflows.
  • Excellent communication and stakeholder management skills.

Nice to have

  • Experience leading Secure SDLC initiatives in large-scale engineering environments.
  • Knowledge of OWASP Top 10, CWE, and NIST frameworks and standards.
  • Familiarity with AI-enabled security tooling, AI security concepts, cloud-native application security, and modern software architectures.
  • Background in financial services, FinTech, or another highly regulated industry.
  • Security certifications such as CISSP, CSSLP, GIAC, or cloud security certifications.

Culture & Benefits

  • Training and development opportunities and firmwide professional networks.
  • Benefits, wellness, personal finance offerings, and mindfulness programs.
  • Commitment to diversity, inclusion, and reasonable accommodations during the recruiting process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →