Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Lead Application Security Engineer (AI): Designing and implementing application security controls for a conversational AI platform serving enterprise customers with an accent on secure coding, threat modeling, vulnerability management, and AI application testing. Focus on securing model integration points and sensitive customer data, automating vulnerability remediation, and responding to application security incidents at scale.
Location: In-office in San Francisco or New York City, United States
Salary: $170,000–$305,000 base salary plus equity
Company
Decagon develops a conversational AI platform that enables enterprise brands to deliver customer experiences through voice, chat, email, SMS, and other channels.
What you will do
- Lead application security strategy and implementation for the conversational AI platform.
- Design and implement secure coding practices, threat modeling, vulnerability management, and application security controls.
- Integrate security throughout the software development lifecycle, including design, coding, pull requests, and deployment.
- Establish SAST, DAST, and IAST programs tailored to AI applications.
- Lead security code reviews and architecture assessments, focusing on AI model integrations and customer data handling.
- Build security automation, support vulnerability remediation, and coordinate application security incident response.
Requirements
- 5+ years of hands-on application security engineering experience.
- Expertise in secure software development, threat modeling, secure code review, and vulnerability assessment.
- Strong software engineering background with the ability to review code across multiple languages and frameworks used in AI/ML applications.
- Experience implementing application security testing tools and integrating security into CI/CD pipelines.
- Knowledge of the OWASP Top 10, common application vulnerabilities, and modern application security frameworks.
- Track record of working with engineering teams to remediate security findings while balancing security and business requirements.
Nice to have
- Experience securing AI/ML applications, including prompt injection, model extraction, and adversarial input protections.
- Experience with large-scale, multi-tenant SaaS applications handling sensitive customer data.
- Familiarity with Google Cloud application security services and container security best practices.
- Knowledge of SOC 2, ISO 27001, and GDPR compliance requirements from an application security perspective.
- Experience with Semgrep, CodeQL, Cursor Bug Bot, XBOW, or similar security tools.
Culture & Benefits
- In-office work environment focused on excellence and velocity.
- Medical, dental, vision, life insurance, and disability benefits for employees and families.
- Retirement plan, parental leave, and fertility and family-building benefits.
- Monthly wellness and lifestyle stipend, daily office lunches and snacks, and flexible vacation.
- Full-time employees receive benefits subject to applicable local policies and requirements.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
11 дней назад
Application Security Engineer (AI)
100 000 - 130 000$
12 дней назад
Application Security Engineer (AI)
180 000 - 280 000$
BitGo Prime
9 дней назад
Senior Security Application Engineer (AI Security)
200 000 - 235 000$
13 дней назад
Senior Application Security Engineer
140 000 - 145 000$
11 дней назад
Staff Security Engineer (AI)
56 - 77$
14 дней назад
Senior Product Security Engineer (AI)
148 000 - 247 000$