Назад
Company hidden
6 дней назад

Senior Product Security Engineer (AI)

226 000 - 283 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Product Security Engineer (AI): Designing and operating secure AI healthcare products and real-time clinical workflows with an accent on product security, threat modeling, vulnerability validation, and AWS cloud risk reduction. Focus on securing high-risk architectures, building scalable security automation, and reducing risk across IAM, network segmentation, workload isolation, secrets, and enterprise AI systems.

Location: Must be based in the Bay Area and able to work from the San Francisco office three days per week

Salary: $226,000–$283,000 per year plus equity

Company

hirify.global builds an AI intelligence platform for healthcare, providing real-time coding-aware documentation and clinical workflow support for health systems.

What you will do

  • Guide high-risk product changes from architecture and design through implementation and verification.
  • Define threat models and security requirements, review sensitive code paths, and contribute prototypes, automation, and pull requests.
  • Own findings from product reviews, bug bounty programs, penetration tests, audits, cloud tooling, and hands-on testing through verified remediation or explicit risk acceptance.
  • Build scalable security engineering practices through developer enablement, automation, and security tooling ownership.
  • Partner with Platform and Infrastructure Engineering to reduce AWS risks across IAM, network segmentation, workload isolation, secrets, logging, configuration, and CNAPP operations.
  • Help scope and remediate incidents across production, development, software delivery, enterprise AI, and internal systems.

Requirements

  • Senior or staff-level product security experience, typically developed through 8+ years of experience.
  • Production software engineering experience and strong skills in at least one backend or automation language such as Go, Python, Java, or TypeScript.
  • Expertise in authentication and authorization, including OAuth, OIDC, SAML, JWT, RBAC, and ReBAC, plus API security, threat modeling, secure code review, and vulnerability testing.
  • Experience securing multi-tenant SaaS applications handling sensitive data and working knowledge of cloud security concepts such as IAM, network architecture, workload isolation, secrets, and logging.
  • Ability to reproduce vulnerabilities, conduct dynamic testing, build proof-of-concept exploits, and distinguish exploitable risks from theoretical concerns.
  • Based in the Bay Area and able to work from the San Francisco office three days per week.

Nice to have

  • Experience securing healthcare systems, PHI, or similarly regulated data.
  • Experience designing or securing relationship-based or fine-grained authorization systems.
  • Offensive security or red-team experience.
  • Experience securing enterprise AI applications or AI-enabled products.
  • Deep AWS security experience, including IAM, network architecture, workload isolation, configuration management, and CNAPP operations.

Culture & Benefits

  • High-ownership, high-trust environment with direct access to leadership and meaningful autonomy.
  • Remote-friendly culture with a San Francisco headquarters and full equipment provisioning.
  • Medical, dental, and vision coverage for employees and dependents.
  • 401(k) with a company match of up to 3% of base salary.
  • Parental leave, flexible time off, company holidays, and an annual holiday shutdown.
  • Company and team off-sites, lunches, and all-hands gatherings with travel, lodging, and meals covered.

Hiring process

  • Candidate accommodations are available throughout the application and interview process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →