Назад
Company hidden
18 часов назад

Application Security Engineer

90 000 - 130 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (SAST/DAST/SCA, Python, AI): Operating application security vulnerability management and bug bounty programs while building automation for secure mobile and backend software, with an accent on vulnerability triage, remediation, and developer partnership. Focus on automating security workflows with Python, SOAR, and agentic AI tooling, reviewing cloud microservices and integrations, and securing CI/CD development practices.

Location: Remote - US

Salary: $90,000–$130,000 per year

Company

hirify.global provides tools, resources, and support that help users reach their health and fitness goals.

What you will do

  • Own application security vulnerability management, including triage of SAST, SCA, DAST, and mobile security findings.
  • Operate and expand the bug bounty program, including engagement scoping, submission triage, validation, and vendor coordination.
  • Build security automation with Python and SOAR platforms for vulnerability intake, notifications, SLAs, metrics, and reporting.
  • Use AI and agentic tooling to accelerate vulnerability triage, enrichment, remediation support, and secure AI-assisted development.
  • Partner with product engineering teams on remediation, feature reviews, third-party integrations, secure coding, documentation, and training.
  • Administer application security tooling across the SDLC and support identity and access management automation.

Requirements

  • Must be based in the United States for this remote role.
  • 2–4 years of experience in security engineering, application security, software engineering, or a related field.
  • Knowledge of SAST, DAST, SCA, penetration testing, vulnerability triage, investigation, and remediation.
  • Understanding of secure development for web and mobile applications, including OWASP Top 10 and OWASP MASVS.
  • Experience with AI or agentic-assisted tooling and familiarity with cloud microservices, containers, Kubernetes, and infrastructure as code.
  • Strong cross-functional communication and technical documentation skills; equivalent education or certifications may include a computer science or information systems degree.

Nice to have

  • Security process automation using Python, SOAR platforms, or workflow automation.
  • Security scanning in CI/CD pipelines and orchestration tools such as GitHub Actions.
  • Experience operating or triaging a bug bounty program.
  • GIAC, OSCP, CSSLP, Security+, or vendor-specific certifications.

Culture & Benefits

  • Full-time employment with healthcare, dental, vision, retirement savings, and a 401(k) match.
  • Responsible Time Off, two paid volunteer days per year, and opportunities for in-person team connections.
  • Paid parental leave, fertility support, mental health benefits, and a monthly wellness allowance.
  • Annual performance bonus, monthly technology allowance, learning resources, mentorship, and access to hirify.global Premium.
  • Collaborative, inclusive environment guided by empathy, continuous improvement, data-informed decisions, and accountability.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →