Назад
Company hidden
4 часа назад

Lead Security Engineer (AI)

180 000 - 350 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead Security Engineer (AI): Securing the 8090 Software Factory and customer applications across application security, AWS cloud security, compliance, and incident response with an accent on DevSecOps automation, regulated data, and AI agent controls. Focus on building security gates and infrastructure guardrails, leading penetration testing and audits, designing tenant isolation, and handling complex customer security engagements.

Location: On-site five days a week from the Redwood City, California office. Applicants must provide documentation establishing employment eligibility in the United States. New work visa sponsorship is not provided.

Salary: $180,000–$350,000 annual salary, plus stock and/or stock options and benefits.

Company

hirify.global is building a Software Factory that delivers fully managed, hosted software purpose-built for enterprise customers.

What you will do

  • Own application security and DevSecOps for the Software Factory and customer applications, including SAST, DAST, dependency scanning, secrets detection, and infrastructure-as-code security gates.
  • Secure production environments across AWS, GCP, and Azure through IAM, network segmentation, encryption, secrets management, logging, detection, backups, and compliance baselines.
  • Perform internal penetration testing and direct external penetration testers, bounty programs, auditors, assessors, and managed security providers.
  • Lead security architecture, threat modeling, tenant isolation, regulated-data protection, customer-specific deployments, and AI-agent controls.
  • Own SOC 1 Type II and SOC 2 Type II controls, compliance roadmaps, incident response, vendor risk, and customer security reviews.
  • Build AI-assisted security workflows, secure defaults, developer tooling, reusable libraries, and infrastructure-as-code directly in the codebase.

Requirements

  • 7–10 years of professional IT, DevOps, or application development experience, including at least 3 years with application, cloud, or infrastructure security as a primary responsibility.
  • Experience leading security and compliance at a Series A, B, or C technology startup, preferably as the first security hire.
  • Hands-on experience building web applications, DevSecOps pipelines, security tooling, and infrastructure-as-code with Python, TypeScript, React, GitHub Actions, Docker, AWS CDK, Terraform, and AWS.
  • Strong application security, cloud security, networking, systems architecture, IAM, secrets and key management, detection, and incident response experience.
  • Direct experience operating SOC 2 controls and working with GDPR, HIPAA, FedRAMP, or another regulated or government environment.
  • Ability to communicate with customer CISOs, CIOs, security teams, system architects, engineers, auditors, and executives.

Nice to have

  • Experience securing LLM-based applications and AI agents, including prompt injection defenses, tool-use permissions, sandboxing, OWASP Top 10 for LLM Applications, and MITRE ATLAS.
  • FedRAMP 20x, GovRAMP, TX-RAMP, HITRUST, ISO 27001, or ISO 42001 experience.
  • Experience with Vanta, Drata, Secureframe, customer-facing trust centers, or SOC 1 and SOX-related controls.
  • Offensive security credentials or evidence such as OSCP, CISSP, CCSP, CISM, bug bounty findings, CVEs, or published research.

Culture & Benefits

  • Work closely with lean engineering teams, sales, the CTO, and the CEO.
  • Direct ownership of the security roadmap, risk register, budget, metrics, and hiring decisions.
  • Medical, dental, vision, and 401(k) benefits.
  • Stock and/or stock option awards.
  • Hands-on environment focused on automation and reducing manual security work.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →