Назад
Company hidden
2 дня назад

Application Security / DevSecOps Engineer (AI)

120 000 - 150 000$
Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US/Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security / DevSecOps Engineer (AI): Driving application security and DevSecOps across the software delivery pipeline while monitoring, investigating, and responding to security incidents with an accent on secure-by-design practices, automated security testing, and AI-assisted development governance. Focus on threat modeling, CI/CD integrity, vulnerability remediation, Microsoft Sentinel investigations, and first-response incident containment.

Location: US - Boston; candidates must work in US or Canada Central or Eastern time zones. Remote and hybrid working options are available.

Base salary: $120,000–$150,000 USD annually, plus incentive pay and benefits.

Company

hirify.global provides an AI-powered SaaS platform that transforms critical insurance workflows through accurate, explainable, and secure technology.

What you will do

  • Drive application security and DevSecOps practices across the software delivery lifecycle, from code development through CI/CD deployment.
  • Define security policies, standards, guidelines, and secure-by-design practices while advising data scientists, engineers, and software delivery teams.
  • Lead threat modeling, automate SAST, DAST, SCA, vulnerability management, secret management, IaC security, SBOM, and software supply-chain controls.
  • Protect code and artifact integrity through automated signing and attestation, and establish governance for AI-generated code.
  • Monitor and triage alerts from Microsoft Sentinel, EDR platforms, cloud security tools, and other security technologies.
  • Investigate and contain incidents, coordinate remediation, document findings, and participate in post-incident reviews and purple team exercises.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent experience.
  • 7+ years of experience in security operations, incident response, cybersecurity monitoring, or a similar security role.
  • Experience with a SIEM platform, preferably Microsoft Sentinel, and at least one EDR platform such as Microsoft Defender for Endpoint, CrowdStrike, or Cortex XDR.
  • Experience with application vulnerability management tools such as GitHub Advanced Security or Tenable, plus knowledge of API, web application, and software supply-chain security.
  • Familiarity with Azure, GitHub, GitHub Actions, SaaS security, networking, MITRE ATT&CK, and security frameworks including ISO 27001, NIST CSF, SOC 2, HIPAA, or GDPR.
  • Proficiency in at least one scripting or programming language such as Python, PowerShell, JavaScript, or Go, with strong analytical, investigative, communication, and organizational skills.

Nice to have

  • Familiarity with KQL or similar query languages.
  • Experience with C#, Java, React, or Python frameworks.
  • Awareness of AI/ML security risks such as prompt injection.

Culture & Benefits

  • Flexible remote and hybrid working options.
  • Competitive salary with a variable component tied to personal and company performance.
  • Learning and development opportunities, including monthly Focus Fridays.
  • Generous paid time off and paid holidays.
  • Mental health benefits and two paid volunteering days per year.

Hiring process

  • Fit call with a Talent Acquisition Manager.
  • Team fit call with the Hiring Manager and technical round with the team.
  • Final interview with the CISO.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →