Назад
Company hidden
33 минуты назад

Sr. Application Security Engineer (AI)

104 300 - 193 700$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Sr. Application Security Engineer (AI): Building and governing secure cloud-native infrastructure, CI/CD pipelines, API security controls, and automated application security scanning with an accent on DevSecOps, cloud security, and AI-assisted coding risks. Focus on designing security guardrails for agentic AI tools, integrating SAST/DAST/SCA and container scanning, and managing compliance, threat modeling, and security metrics.

Location: United States; remote position

Salary: $104,300–$193,700 annual base salary, plus eligibility for a discretionary annual bonus.

Company

hirify.global operates in the corporate travel industry, helping organizations manage business travel and related services.

What you will do

  • Design, implement, and maintain secure CI/CD pipelines with security testing throughout the software development lifecycle.
  • Configure and tune SAST, DAST, SCA, container scanning, API security, WAF, SIEM, vulnerability management, and secrets management tools.
  • Partner with DevOps and development teams to promote secure coding, provide application security guidance, and govern cloud-native security.
  • Establish guardrails and detection strategies for agentic AI coding tools, addressing hallucinated dependencies, code injection, vulnerabilities, and governance gaps.
  • Support PCI-DSS, GDPR, SOC 2, and CCPA compliance; build KPI and metrics reporting for application security initiatives.
  • Mentor junior engineers and communicate security risks to technical and non-technical stakeholders.

Requirements

  • 5+ years of professional software development experience and 3+ years of hands-on application security or DevSecOps experience.
  • Experience with three or more programming languages, such as Python, Go, Java, C#, Ruby, JavaScript/TypeScript, Bash, or PowerShell.
  • Strong knowledge of OWASP Top 10, secure coding, API security, authentication protocols, threat modeling, and risk assessment.
  • Cloud security expertise with AWS, Azure, or GCP, including IAM, network security, encryption, secrets management, and compliance.
  • Experience with CI/CD, infrastructure as code, containers, orchestration, and network security; technologies include Jenkins, GitHub Actions, Terraform, Docker, Kubernetes, Helm, and Ansible.
  • Background in penetration testing or red team operations, MLSecOps, AI/ML supply chain security, and professional security certifications such as CISSP, GIAC, OSCP, or cloud security certifications.

Nice to have

  • Experience in travel, hospitality, or e-commerce.
  • Open-source contributions or security research publications.
  • Multi-cloud experience across AWS, Azure, and GCP.

Culture & Benefits

  • Inclusive and collaborative culture with opportunities to contribute to company-wide security practices.
  • Country-tailored health and welfare insurance, retirement programs, parental leave, adoption assistance, and wellbeing resources.
  • Travel discounts on flights, hotels, cruises, car rentals, and other travel services.
  • Access to more than 20,000 learning courses, leadership development, and internal career opportunities.
  • Inclusion groups and workplace accommodation support are available.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →