Назад
Company hidden
7 дней назад

Sr. Staff Security Engineer – AI, VMR, Offensive Security

120 000 - 260 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Sr. Staff Security Engineer – AI, VMR, Offensive Security (AI/Vulnerability Management): Leading vulnerability management, offensive security, and AI-augmented security across a complex hybrid technology ecosystem with an accent on risk-based vulnerability assessment, security automation, and scalable data pipelines. Focus on integrating scanning, asset, CI/CD, and monitoring systems, designing AI-assisted discovery and remediation, and advising executive leaders on measurable security improvements.

Location: Bethesda, MD, United States

Annual salary: $120,000–$260,000

Company

hirify.global is a large U.S. auto insurer and a member of the Berkshire Hathaway family of companies, focused on protecting customers through insurance and technology.

What you will do

  • Lead the strategy and technical execution of vulnerability management, offensive security, and AI-augmented security at scale.
  • Manage the full vulnerability lifecycle, including asset discovery, validation, risk analysis, prioritization, remediation measurement, and reporting.
  • Integrate scanning tools, asset inventories, CMDBs, ticketing systems, CI/CD workflows, and monitoring pipelines.
  • Evaluate and implement AI technologies and automation for vulnerability discovery, risk assessment, and remediation.
  • Define KPIs, SLAs, dashboards, playbooks, and scalable operational processes for vulnerability management.
  • Advise executive leaders and collaborate with cloud, infrastructure, DevOps, product engineering, risk, compliance, governance, and incident response teams.

Requirements

  • 10+ years of experience in cybersecurity or security engineering.
  • Deep expertise in vulnerability management tools, methodologies, and industry standards.
  • Hands-on experience with cloud services including AWS, Azure, or GCP, container platforms, modern infrastructure, and operating systems.
  • Proficiency in a modern programming language such as Python, Go, or Java, plus scripting for automation at scale.
  • Strong knowledge of security architecture, networking, identity, cloud services, and the NIST CSF.
  • Experience leading compliance initiatives involving PCI, SOX, NYDFS, or similar standards; a bachelor's degree in computer science, cybersecurity, or equivalent experience.

Nice to have

  • Experience with penetration testing, threat modeling, security research, or comprehensive security assessments.
  • Familiarity with SIEM, SOAR, and asset intelligence integrations.
  • Security certifications such as CISSP, GCSA, OSCP, or cloud security certifications.
  • Experience embedding security controls into CI/CD pipelines and DevSecOps workflows.

Culture & Benefits

  • Inclusive and collaborative culture centered on shared success.
  • Personalized development programs, mentorship, and certification assistance.
  • Competitive pay, benefits, and flexibility to support employee well-being.
  • Opportunity to influence cybersecurity strategy and strengthen digital resilience across a large enterprise.

Hiring process

  • Applicants are evaluated based on qualifications, experience, education, training, and work location.
  • hirify.global does not sponsor new applicants for employment authorization for this position.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →