Назад
Company hidden
4 дня назад

Senior Application Security Engineer (Blue Team) (Fintech)

200 000 - 240 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (Blue Team) (Fintech): Securing financial technology products from design and code through CI/CD pipelines with an accent on Java/Spring services, threat modeling, and automated security tooling. Focus on building secure development guardrails, closing service authentication and authorization gaps, and driving SAST, DAST, and SCA findings to remediation.

Location: Hybrid, with three days per week onsite in San Francisco FiDi or Culver City, California

Salary: $200,000–$240,000 USD annually

Company

hirify.global is building an AI platform for wealth professionals and modernizing the wealth management industry for financial advisors.

What you will do

  • Educate development teams on secure coding practices and emerging security threats.
  • Perform security assessments, design reviews, threat modeling, and secure code reviews across Java/Spring services.
  • Build reusable security libraries, patterns, paved-road components, and developer security guardrails.
  • Own and tune SAST, DAST, SCA, secrets-scanning, and other security tooling in CI/CD pipelines.
  • Triage findings, prioritize remediation, and address service-to-service authentication and authorization gaps.
  • Partner with Detection & Response and offensive security teams to create durable detections and prevention measures.

Requirements

  • 4+ years of experience as an Application Security or Product Security Engineer.
  • Extensive experience with security assessments, security design reviews, or threat modeling.
  • Hands-on secure code review experience with Java/Spring or similar technologies.
  • Experience operating SAST, DAST, SCA, and secrets-scanning tools in CI/CD pipelines.
  • Knowledge of modern technologies such as Java, Spring, Terraform, and Kubernetes.
  • B.A./B.S. in Computer Science, Computer Engineering, Information Security, or equivalent relevant experience.

Nice to have

  • Experience in regulated environments, fintech, or financial services.
  • Experience building AppSec automation or paved roads for developers.
  • Cloud security, AWS, and API security experience.
  • CSSLP, GWAPT, OSCP, or other relevant certifications.

Culture & Benefits

  • Kindness, brilliance, and grit are core working values.
  • Premium healthcare, dental, and vision insurance plans.
  • 401(k) savings plan with a 4% match and immediate vesting.
  • 16 weeks of paid parental leave after one year of employment.
  • Professional development opportunities, an employee mobility program, and an annual learning and development budget.
  • One month of work from anywhere per year, with exceptions for a few countries.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →