18 дней назад
Principal Cloud Application Security Engineer (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Principal Cloud Application Security Engineer (AI): Shaping application and cloud security for a multi-tenant AWS SaaS platform with an accent on vulnerability triage, detection engineering, exploitability assessment, and AI-assisted security automation. Focus on evaluating tenant isolation, attack paths, data exposure, and cloud risks while leading technical direction for a small security team.
Location: Ireland
Company
provides an AI-powered experience orchestration platform connecting people, systems, data, and AI for more than 8,000 organizations worldwide.
What you will do
- Lead the technical direction of a small Application Security team through hands-on leadership and mentoring.
- Own the application security operating model, detection coverage, security metrics, vulnerability intake, and engineering investment priorities.
- Expand security coverage across web and mobile applications, APIs, cloud environments, AI-powered capabilities, and software supply chains using SAST, SCA, DAST, secrets scanning, and cloud security posture management.
- Assess exploitability and severity across automated findings, bug bounty submissions, customer penetration tests, internal assessments, and AI-generated analysis.
- Investigate and escalate high-risk issues involving cross-tenant access, authentication and authorization bypasses, sensitive data exposure, production secrets, and externally reachable cloud resources.
- Develop AI-assisted automation, establish human validation controls, and coordinate vulnerability workflows with security, engineering, product, customer-facing, and penetration-testing teams.
Requirements
- 10+ years of experience in application security, product security, penetration testing, vulnerability management, cloud security, or related security engineering disciplines.
- Deep expertise in web and API security, including authorization flaws, authentication weaknesses, injection, SSRF, business logic abuse, sensitive data exposure, and multi-tenant isolation.
- Experience implementing or tuning SAST, SCA, DAST, secrets scanning, mobile application security testing, or cloud security posture management.
- Strong understanding of cloud-hosted, multi-tenant architectures, attack paths, trust boundaries, identity, authorization, data isolation, and exposed services.
- Strong cloud security experience, preferably with AWS, and demonstrated ability to build automation while identifying decisions that require human oversight.
- Technical leadership, mentoring, cross-functional collaboration, clear security communication, and discretion when handling sensitive vulnerability and customer security data.
Nice to have
- Experience with Azure or Google Cloud Platform, OWASP API Security Top 10, OWASP Web Security Testing Guide, or mobile application security testing.
- Knowledge of secure SDLC, CI/CD security integration, threat modeling, secure design review, or security architecture.
- Experience designing AI or LLM-assisted security workflows and securing software supply chains, including SBOMs, dependency risk, build integrity, or provenance.
- Proficiency with Python, TypeScript, Bash, Go, or another language for security tooling and automation.
- Experience with bug bounty programs, customer penetration testing, vulnerability disclosure, or remediation workflows.
Culture & Benefits
- Flexible-first ways of working within a global organization.
- Mentorship, learning programs, leadership development, and education support.
- Paid volunteer time, August Free Fridays, well-being resources, and regionally tailored employee and family programs.
- Opportunity to build and operate AI-powered technology at enterprise scale.
Hiring process
- Application review by the Talent Acquisition team and hiring team.
- Zoom interview followed by meetings with the hiring manager and interview team.
- Typically no more than five interviews, followed by final-step communication.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →