4 дня назад
Senior Security Engineer, Application (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Security Engineer, Application (AI): Securing the public APIs, multi-tenant services, control plane, and AI assistants behind Firmus AI Cloud with an accent on automated security delivery, application security architecture, and tenant isolation. Focus on threat modelling REST and gRPC APIs, governing agentic AI integrations, automating vulnerability management, and enforcing secure CI/CD controls.
Location: Sydney, New South Wales, Australia; Singapore or Australia
Company
Technologies develops and operates energy-efficient AI infrastructure and AI Cloud, a GPU cloud platform for training and deploying AI models.
What you will do
- Own application security for AI Cloud, its public APIs, internal services, control plane, and AI assistants and agents.
- Build and operate CI/CD security gates covering SAST, DAST, SCA, secrets detection, and SBOM generation.
- Develop reusable security libraries, service templates, developer tooling, automated triage, dependency uplift, evidence collection, and threat-modeling workflows.
- Define standards for authentication, service authorization, tenant isolation, secret handling, logging, AI-agent integrations, and tool access.
- Own vulnerability posture, prioritize remediation, support incident response, and extend SOC 2 Type 2 and ISO 27001 controls into software delivery.
- Coach security champions, advise engineering leadership, and participate in customer conversations about application security.
Requirements
- Bachelor’s degree in computer science or a related technical field.
- 7+ years of experience in application security, product security, or software engineering with a security focus.
- Experience securing public-cloud or multi-tenant platforms with public APIs, including REST and gRPC threat modeling.
- Practical expertise in OWASP Top 10, OWASP API Security Top 10, OAuth, OIDC, JWT, RBAC or ABAC, application-layer cryptography, token handling, and software secrets.
- Production experience with CI/CD security gates, automation, secure-by-default patterns, and production-quality code in Python, Go, or TypeScript.
- Experience securing LLM-backed or agentic features, working under SOC 2 Type 2 or ISO 27001, participating in incident response, and communicating effectively in English.
Nice to have
- Experience securing AI agents, sandboxed code execution, or AI-generated actions reaching production.
- Experience running a vulnerability disclosure programme.
- Application-security certifications such as CSSLP or OSWE.
Culture & Benefits
- Work within an engineering and technology team building AI infrastructure and cloud services.
- Occasional overseas travel may be required.
- Security ownership is supported through automation, developer enablement, and measurable control evidence.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 дня назад
Security Engineer (AI/LLM Security)
134 000 - 168 000$
4 дня назад
Senior Application Security Analyst (Cybersecurity)
100 000 - 130 000CAD
5 дней назад
Security Engineer (AI)
6 дней назад
Senior Security Platform Engineer - DevSecOps
11 дней назад
Senior Security Engineer - DevSecOps (AWS/AI)
11 дней назад