Назад
Company hidden
4 дня назад

Senior Application Security Engineer (Red Team)

170 000 - 225 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (Red Team) (Fintech): Pentesting web applications, APIs, infrastructure, and mobile applications while continuously attacking security controls with an accent on authorization, exploitability, cloud, and identity-focused offensive testing. Focus on purple-team exercises, developing offensive tooling and repeatable testing playbooks, and documenting reproducible findings with actionable remediation guidance.

Location: Hybrid schedule with three days per week onsite in the San Francisco FiDi or Culver City office.

Salary: $170,000–$225,000 USD per year

Company

hirify.global is building an AI platform for wealth professionals and partnering with financial advisors to improve the delivery of financial advice.

What you will do

  • Perform penetration testing of web applications, APIs, infrastructure, Android applications, and iOS applications.
  • Assess authorization controls, exploitability, cloud environments, and identity-focused attack paths.
  • Run purple-team exercises with Detection & Response and help develop detections from offensive tradecraft.
  • Develop offensive security tooling and repeatable testing playbooks, including support for phishing and social-engineering assessments.
  • Document findings with reproducible proofs of concept, clear risk ratings, and actionable remediation guidance.

Requirements

  • 4+ years of experience as an Application or Product Security Engineer.
  • Experience pentesting web, API, and mobile targets and conducting security assessments.
  • Experience with Burp Suite and the ability to work independently.
  • A B.A. or B.S. in Computer Science, Computer Engineering, Information Security, or a related field, or equivalent experience.
  • Ability to quickly understand modern technology stacks such as Java, Spring, Terraform, and Kubernetes.
  • Strong communication, ownership, resilience, assurance, and creative problem-solving skills.

Nice to have

  • Experience in regulated environments, fintech, or financial services.
  • Mobile application pentesting using OWASP MASVS.
  • Cloud red-team or adversary-emulation experience.
  • Relevant certifications such as OSCP, OSWE, or GXPN.

Culture & Benefits

  • Premium healthcare, dental, and vision insurance plans.
  • 401(k) savings plan with a 4% match and immediate vesting.
  • 16 weeks of paid parental leave after one year of employment.
  • Professional development opportunities, an employee mobility program, and an annual learning and development budget.
  • One month of work-from-anywhere flexibility, except for a few countries.
  • Office spaces are available in Culver City, San Francisco, and Dallas.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →