Назад
Company hidden
3 дня назад

Senior Application Security Engineer (AI)

104 300 - 193 700$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (AI): Building and governing secure cloud-native software delivery with an accent on CI/CD security testing, API security, cloud controls, and agentic AI coding tools. Focus on mitigating AI-specific vulnerabilities, implementing application security metrics, ensuring PCI-DSS/GDPR/SOC 2 compliance, and mentoring engineers.

Location: Remote within the United States

Salary: $104,300–$193,700 annual base salary, plus eligibility for a discretionary annual bonus.

Company

hirify.global operates in the corporate travel industry, providing travel-related products and services.

What you will do

  • Design, implement, and maintain secure CI/CD pipelines with integrated SAST, DAST, SCA, and container scanning.
  • Deploy and support API security tools and centralize security findings and reporting.
  • Partner with development and DevOps teams on secure coding, cloud-native security, threat modeling, and risk assessment.
  • Evaluate and govern agentic AI coding tools by establishing guardrails and detection strategies for hallucinated dependencies, injected vulnerabilities, and insufficient oversight.
  • Support PCI-DSS, GDPR, SOC 2, and related compliance requirements while building application security KPIs and presenting findings to leadership.
  • Mentor junior engineers and promote a security-first culture across engineering teams.

Requirements

  • 5+ years of professional software development experience and 3+ years of application security or DevSecOps experience.
  • Experience with three or more programming languages, including options such as Python, Go, Java, JavaScript/TypeScript, C#, Ruby, Bash, or PowerShell.
  • Strong knowledge of OWASP Top 10, API security, authentication protocols, secure API design, network security, and cloud security across AWS, Azure, or GCP.
  • Practical experience with CI/CD, infrastructure as code, containers, orchestration, vulnerability scanning, secrets management, and security tooling.
  • Experience with agentic AI programming and AI security risks, including insecure code injection, hallucinated dependencies, governance gaps, and AI/ML supply chain security.
  • Knowledge of PCI-DSS, GDPR, CCPA, penetration testing or red team operations, threat modeling, and security certifications such as CISSP, GIAC, OSCP, or cloud security certifications.

Nice to have

  • Experience in travel, hospitality, or e-commerce.
  • Multi-cloud experience across AWS, Azure, and GCP.
  • Open-source contributions or security research publications.

Culture & Benefits

  • Inclusive and collaborative work environment with an emphasis on employee voice and belonging.
  • Health and welfare insurance, retirement programs, parental leave, adoption assistance, and wellbeing resources.
  • Travel discounts on flights, hotels, cruises, car rentals, and other travel services.
  • Access to more than 20,000 learning courses, leadership development, and internal career opportunities.
  • Inclusion groups and programs supporting connection, awareness, and professional development.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →