Назад
Company hidden
25 дней назад

Senior Application Security Engineer (AI Security)

60 000 - 75 000GBP
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (AI Security): Embedding application security across the software development lifecycle for cloud-native and AI-enabled products with an accent on secure-by-default standards, threat modelling, and practical risk reduction. Focus on governing security requirements, improving SAST/DAST triage, reviewing C# code, and guiding teams on LLM, SLM, and MCP security.

Location: Cambridge, United Kingdom; flexible hybrid working with office attendance once every two weeks

Salary: £60,000–£75,000 per year, subject to experience

Company

hirify.global builds software that helps data professionals securely manage the data and databases their organisations depend on, with a focus on cloud-native technologies and AI-enabled development.

What you will do

  • Partner with engineering and product teams to define and operationalise security requirements across the full software development lifecycle.
  • Own or co-own application security governance, including secure-by-default standards, patterns, guardrails, and risk exceptions.
  • Lead threat modelling for new features and architectural changes, translating findings into practical engineering work.
  • Drive SAST and DAST adoption, tool tuning, severity calibration, and developer-facing triage guidance.
  • Support product teams adopting AI technologies, including LLMs, SLMs, and MCP.
  • Review code and make independent security decisions based on practical risk rather than automated scanner output.

Requirements

  • Hands-on product or application security experience across a modern software development lifecycle.
  • Ability to review code and communicate security issues clearly to developers, primarily in a C# ecosystem, with exposure to Java or Python.
  • Strong knowledge of the OWASP Top 10 and practical mitigation patterns.
  • Experience implementing or improving SAST and DAST processes, including tool tuning, triage workflows, and reducing signal to noise.
  • Working understanding of cloud and container security fundamentals, ideally with AWS and Docker.
  • Ability to work in a flexible hybrid arrangement based in Cambridge, with office attendance once every two weeks.

Culture & Benefits

  • Environment based on trust, accountability, collaboration, respect, and fairness.
  • Monthly wellbeing allowance and generous paid time off.
  • Private health insurance.
  • Investment in learning, development, and career progression.
  • Access to AI tools including Claude.
  • Human-reviewed applications and feedback for candidates who reach the interview stage.

Hiring process

  • Submit a CV or LinkedIn profile and covering letter.
  • Initial conversation followed by a skills alignment interview, which may include a technical assessment or competency-based questions.
  • Values alignment interview followed by an offer discussion if successful.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →