Назад
6 дней назад

Staff Security Engineer, Applications (AI)

204 000 - 240 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Security Engineer, Applications (AI): Building security foundations for enterprise AI platforms, including threat modeling, automated application security controls, and defenses for LLM architectures, data pipelines, and customer-facing AI agents with an accent on application security, AI infrastructure, and developer enablement. Focus on designing scalable DevSecOps controls, identifying novel generative AI attack vectors, and securing production systems across applications, APIs, and model training environments.

Location: Hybrid from the New York City, San Francisco, or Seattle offices

Base compensation: $204,000–$240,000 in San Francisco and New York City; $183,000–$216,000 in other US locations, plus equity.

Company

Writer develops an enterprise AI platform that enables companies to build and deploy AI agents grounded in company data and powered by enterprise-grade large language models.

What you will do

  • Conduct threat modeling with product teams and design secure architectures for new AI platform features.
  • Own and evolve the application security program, including SAST and DAST scanning in CI/CD pipelines, security code reviews, and vulnerability automation.
  • Establish secure coding standards, reusable security patterns, and libraries that support secure-by-default development.
  • Design security features and controls for customer environments, data pipelines, model training environments, and customer-facing AI agents.
  • Lead security assessments and penetration testing for applications, AI services, and APIs, coordinating remediation at scale.
  • Research LLM and generative AI attack vectors and use AI agents to improve security team velocity and proactive risk reduction.

Requirements

  • At least 4 years of hands-on application security engineering experience securing large-scale production systems.
  • Expertise in at least two of Python, Java, Go, and JavaScript/TypeScript, with the ability to review code across multiple languages.
  • Knowledge of SAST/DAST, vulnerability management, security testing frameworks, and DevSecOps practices.
  • Understanding of developer workflows and the ability to reduce security risk without slowing product delivery.
  • Strong communication skills for explaining security concepts to technical and non-technical audiences.
  • Hybrid work from the New York City, San Francisco, or Seattle offices.

Nice to have

  • Experience in fast-growing startups or high-growth environments.
  • Experience securing AI systems, LLM architectures, model training pipelines, or generative AI applications.

Culture & Benefits

  • Generous paid time off and company holidays.
  • Medical, dental, and vision coverage for employees and families.
  • Sixteen weeks of paid parental leave for all parents, plus fertility and family planning support.
  • Flexible spending accounts, dependent FSAs, eligible-plan HSAs with company contributions, and early-detection cancer testing.
  • Wellness and learning and development stipends, company and team off-sites, equity, and 401(k).

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →