Назад
Company hidden
12 дней назад

Senior Product Security Engineer (Contract)

Формат работы
remote (только USA)
Тип работы
project
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Product Security Engineer (Contract) (Application Security/AI): Embedding security into the product development lifecycle through architecture reviews, threat modeling, penetration testing, vulnerability remediation, and secure development practices with an accent on web, API, cloud-native, and AI-enabled applications. Focus on testing prompt injection, data leakage, insecure tool use, and authorization weaknesses while automating security controls across CI/CD.

Location: USA Remote

Company

hirify.global is an AI-powered security and IT platform that unifies identity and access, endpoint security and management, and compliance automation.

What you will do

  • Perform security architecture reviews, threat modeling, application security reviews, and secure code reviews.
  • Conduct manual penetration testing for web, API, thick-client, and mobile applications.
  • Partner with engineering teams to prioritize vulnerabilities, verify remediation, and improve secure coding practices.
  • Define product security standards, engineering guardrails, reusable security patterns, and reference architectures.
  • Assess AI-enabled products and LLM workflows for prompt injection, data leakage, insecure tool use, model abuse, and authorization weaknesses.
  • Automate security testing and integrate security tooling into CI/CD and developer workflows.

Requirements

  • USA-based remote work.
  • 5+ years of experience in product security or application security.
  • Experience securing web applications, APIs, microservices, and cloud-native applications.
  • Experience with threat modeling, penetration testing, OWASP Top 10, OWASP API Top 10, authentication, authorization, OAuth/OIDC, and secure SDLC.
  • Experience with SAST, DAST, SCA, container security, and direct collaboration with engineering teams.

Nice to have

  • Experience securing AI and LLM applications.
  • Experience with Kubernetes, containers, AWS, Azure, GCP, GitHub Actions, or CI/CD security.
  • Experience with Snyk, Burp Suite Pro, Semgrep, Wiz, or GitHub Advanced Security.
  • OSCP, GWAPT, GWEB, CSSLP, or CISSP certification.

Culture & Benefits

  • Six-month contract at 40 hours per week.
  • 100% individual and dependent medical, dental, and vision coverage.
  • 401(k) with a 4% company match.
  • 20 days of paid time off and a wellness week in July.
  • Paid parental, family, and medical leave, plus opportunities for career growth.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →