Назад
Company hidden
4 дня назад

Senior Security Engineer, Application (AI)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Singapore/Australia
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer, Application (AI): Securing the public APIs, multi-tenant services, control plane, and AI assistants behind Firmus AI Cloud with an accent on automated security delivery, application security architecture, and tenant isolation. Focus on threat modelling REST and gRPC APIs, governing agentic AI integrations, automating vulnerability management, and enforcing secure CI/CD controls.

Location: Sydney, New South Wales, Australia; Singapore or Australia

Company

hirify.global Technologies develops and operates energy-efficient AI infrastructure and hirify.global AI Cloud, a GPU cloud platform for training and deploying AI models.

What you will do

  • Own application security for hirify.global AI Cloud, its public APIs, internal services, control plane, and AI assistants and agents.
  • Build and operate CI/CD security gates covering SAST, DAST, SCA, secrets detection, and SBOM generation.
  • Develop reusable security libraries, service templates, developer tooling, automated triage, dependency uplift, evidence collection, and threat-modeling workflows.
  • Define standards for authentication, service authorization, tenant isolation, secret handling, logging, AI-agent integrations, and tool access.
  • Own vulnerability posture, prioritize remediation, support incident response, and extend SOC 2 Type 2 and ISO 27001 controls into software delivery.
  • Coach security champions, advise engineering leadership, and participate in customer conversations about application security.

Requirements

  • Bachelor’s degree in computer science or a related technical field.
  • 7+ years of experience in application security, product security, or software engineering with a security focus.
  • Experience securing public-cloud or multi-tenant platforms with public APIs, including REST and gRPC threat modeling.
  • Practical expertise in OWASP Top 10, OWASP API Security Top 10, OAuth, OIDC, JWT, RBAC or ABAC, application-layer cryptography, token handling, and software secrets.
  • Production experience with CI/CD security gates, automation, secure-by-default patterns, and production-quality code in Python, Go, or TypeScript.
  • Experience securing LLM-backed or agentic features, working under SOC 2 Type 2 or ISO 27001, participating in incident response, and communicating effectively in English.

Nice to have

  • Experience securing AI agents, sandboxed code execution, or AI-generated actions reaching production.
  • Experience running a vulnerability disclosure programme.
  • Application-security certifications such as CSSLP or OSWE.

Culture & Benefits

  • Work within an engineering and technology team building AI infrastructure and cloud services.
  • Occasional overseas travel may be required.
  • Security ownership is supported through automation, developer enablement, and measurable control evidence.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →