Назад
Company hidden
4 дня назад

Senior Application Security Engineer (Red Team) (Fintech)

200 000 - 240 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (Red Team) (Fintech): Penetrating web applications, APIs, infrastructure, and mobile applications while conducting cloud and identity-focused offensive testing with an accent on authorization, exploitability, and adversary simulation. Focus on developing offensive tooling, running purple-team exercises, and producing reproducible proofs of concept and actionable remediation guidance.

Location: Hybrid, with three days per week onsite in the San Francisco FiDi or Culver City office, United States

Salary: $200,000–$240,000 USD per year

Company

hirify.global is building an AI platform for wealth professionals and partnering with financial advisors to improve access to financial advice.

What you will do

  • Conduct penetration tests of web applications, APIs, infrastructure, Android applications, and iOS applications.
  • Assess authorization controls, exploitability, cloud environments, identity systems, and high-risk attack paths.
  • Run purple-team exercises with Detection & Response and help develop detections from offensive tradecraft.
  • Develop offensive security tooling, repeatable testing playbooks, and phishing and social-engineering assessments.
  • Document findings with reproducible proofs of concept, risk ratings, and actionable remediation guidance.

Requirements

  • 4+ years of experience as an Application or Product Security Engineer.
  • Penetration-testing experience across web, API, and mobile targets, including extensive security assessments.
  • Experience with Burp Suite and the ability to work independently.
  • Familiarity with modern technologies such as Java, Spring, Terraform, and Kubernetes.
  • B.A. or B.S. in Computer Science, Computer Engineering, Information Security, or relevant equivalent experience.
  • Ability to work onsite three days per week in San Francisco or Culver City.

Nice to have

  • Experience in regulated environments, fintech, or financial services.
  • Mobile application penetration testing using OWASP MASVS.
  • Cloud red-team or adversary-emulation experience.
  • Certifications such as OSCP, OSWE, or GXPN.

Culture & Benefits

  • Kindness, brilliance, and grit are core working principles.
  • Premium healthcare, dental, and vision insurance plans.
  • 401(k) plan with a 4% match and immediate vesting.
  • Sixteen weeks of paid parental leave after one year of employment.
  • Professional development opportunities, employee mobility support, and an annual learning and development budget.
  • One month of work-from-anywhere flexibility, except for a few countries.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →