Назад
Company hidden
6 дней назад

Senior Security Engineer, Application

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Singapore/Australia
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer, Application (AI Cloud and Application Security): Securing the public APIs, services, tenant isolation, and AI assistants behind Firmus AI Cloud with an accent on automated secure delivery, threat modelling, and application security architecture. Focus on building CI/CD security gates, governing agent and tool integrations, automating vulnerability management, and protecting multi-tenant systems from complex application and API attacks.

Location: Singapore or Australia; occasional overseas travel may be required.

Company

hirify.global Technologies develops and operates energy-efficient AI infrastructure and the hirify.global AI Cloud GPU platform across Asia Pacific.

What you will do

  • Own application security for public APIs, platform services, tenant isolation, and AI assistants and agents.
  • Build and maintain CI/CD security gates covering SAST, DAST, SCA, secrets detection, and SBOM generation.
  • Develop reusable security libraries, service templates, developer tooling, automated triage, dependency uplift, evidence collection, and threat-modeling workflows.
  • Define standards for authentication, service authorization, secrets, logging, application-layer controls, and secure AI integrations.
  • Lead threat modeling, secure design reviews, vulnerability prioritization, remediation, and security assurance under SOC 2 Type 2 and ISO 27001.
  • Coach security champions, support incident response, and communicate application risk and release readiness to engineering leadership and customers.

Requirements

  • 7+ years of experience in application security, product security, or software engineering with a security focus.
  • Bachelor's degree in computer science or a related technical field.
  • Experience securing public-cloud or multi-tenant platforms with public APIs, including REST and gRPC.
  • Deep practical knowledge of OWASP Top 10, OWASP API Security Top 10, threat modeling, OAuth, OIDC, JWT, RBAC or ABAC, cryptography, token handling, and secrets management.
  • Production coding experience in at least one of Python, Go, or TypeScript, plus experience owning CI/CD security gates and automation.
  • Hands-on experience securing LLM-backed or agentic features, including prompt injection, tool misuse, delegated credentials, cross-tenant data leakage, and generated code reaching production.
  • Experience with SOC 2 Type 2 or ISO 27001 and clear written and verbal communication in English.

Nice to have

  • Experience securing AI agents, sandboxed code execution, or automated actions triggered by AI-generated output.
  • Experience running a vulnerability disclosure programme.
  • Application-security certifications such as CSSLP or OSWE.

Culture & Benefits

  • Founder-led environment with fast decisions, accessible leadership, and limited bureaucracy.
  • Early ownership and direct exposure to AI infrastructure, energy systems, and next-generation compute.
  • Opportunities to grow into new technical domains and take on broader challenges.
  • Work connected to sustainable AI infrastructure designed to support energy-grid resilience.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →