Назад
Company hidden
22 часа назад

Security Engineer (AI)

150 000 - 180 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Engineer (AI): Owning hands-on security engineering across vulnerability management, application security, AI/LLM security, cloud hardening, detection, and automation for a FedRAMP-authorized SaaS platform. Focus on securing Azure/AKS and GCP infrastructure, model integrations and RAG pipelines, CI/CD controls, incident response, and automated compliance evidence for government contracting customers.

Location: Remote in the United States; US citizenship required. The role is associated with Lehi, Utah and supports FedRAMP and defense customers.

Salary: $150,000–$180,000 annually, plus equity and performance-based incentives.

Company

hirify.global is a venture-backed SaaS company using AI to help businesses succeed in government contracting.

What you will do

  • Own vulnerability management, penetration testing, CSPM/CWPP tooling, MTTR tracking, and risk reporting.
  • Lead application security practices including SAST, DAST, SCA, secret scanning, threat modeling, secure code review, and developer training.
  • Secure AI and LLM integrations, RAG pipelines, and provider APIs from prompt injection, data exfiltration, model abuse, and unsafe outputs.
  • Harden Azure/AKS and GCP infrastructure through IAM, network segmentation, encryption, Kubernetes runtime protection, IaC scanning, WAF, and zero-trust design.
  • Build CI/CD security gates, detection-as-code, SOAR workflows, custom tooling, and automated compliance evidence collection.
  • Lead or support incident response and maintain technical controls, monitoring, SSPs, POA&Ms, and customer security-assessment responses.

Requirements

  • 5+ years of hands-on security engineering experience with depth in at least three areas including vulnerability management, application security, cloud security, security automation, or detection engineering.
  • Strong cloud-native security experience in Azure and/or GCP, including Kubernetes, container hardening, and infrastructure-as-code security.
  • Experience operating vulnerability scanners, SAST/DAST/SCA, CSPM/CWPP, EDR, SIEM, and secret-scanning tools.
  • Ability to use Python, Go, TypeScript, or Bash for automation and custom tooling.
  • Clear communication with developers and customers.
  • US citizenship is required.

Nice to have

  • Experience securing AI/ML systems and LLM applications, including OWASP Top 10 for LLM and MITRE ATLAS.
  • SaaS security experience in a B2B or GovTech company.
  • Knowledge of FedRAMP, CMMC, NIST 800-53, NIST 800-171, SOC 2, GCC High, Azure Government, or AWS GovCloud.
  • Experience with DFARS, CUI, ITAR/EAR, or FedRAMP and CMMC assessments.
  • OSCP, GIAC, cloud security, or CISSP certifications; prior experience as an early security hire.

Culture & Benefits

  • Full remote work with flexible work arrangements.
  • Competitive salary, performance-based incentives, and stock options.
  • Comprehensive health coverage.
  • Professional development opportunities and career advancement support.
  • Background check required, including credit, criminal-record, and employment verification checks.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →