Назад
Company hidden
5 дней назад

Security Engineer (Application Security)

120 000 - 140 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Engineer (Application Security) (AWS/DevSecOps): Securing application development across the SDLC, including APIs, mobile ecosystems, CI/CD pipelines, and AI-enabled product integrations with an accent on secure design, threat modeling, and vulnerability management. Focus on building developer security tooling, establishing secure API and coding patterns, and prioritizing systemic risks across web, mobile, cloud, and infrastructure environments.

Location: Remote throughout the United States, or onsite from the Manhattan, New York office. Hiring is unavailable in Alaska, Delaware, Hawaii, Iowa, Louisiana, Mississippi, Montana, Oklahoma, and South Carolina.

Salary: $120,000–$140,000 per year, plus potential incentive compensation, equity, and benefits.

Company

hirify.global is a remote-first technology company building products that help families, coaches, parents, and volunteers experience and manage youth sports.

What you will do

  • Embed application security and security-by-design practices throughout the software development lifecycle.
  • Review new features, APIs, platform initiatives, and infrastructure changes, and provide actionable secure-code guidance.
  • Establish secure REST and GraphQL API patterns, coding guidelines, and reusable security architecture standards.
  • Securely integrate GenAI and agentic AI tools into the product stack.
  • Integrate and operate security tooling across CI/CD pipelines, including vulnerability management and findings triage.
  • Track security KPIs, communicate risk to engineering and business leaders, and participate in the weekly on-call rotation.

Requirements

  • 3+ years of application security engineering experience, including work with iOS and Android ecosystems.
  • Experience building internal security developer platforms or tooling that reduces developer friction.
  • Hands-on experience with threat modeling, secure-by-design practices, and security tooling integration into CI/CD pipelines.
  • Working knowledge of OWASP Top 10 for web, mobile, API, and LLM security.
  • Experience securing AWS deployments with containers, Kubernetes, IaC scanning, and policy-as-code approaches.
  • Security-by-design expertise in TypeScript, Swift, and/or Kotlin, plus the ability to communicate technical risk to engineering and business audiences.

Nice to have

  • AWS Certified Security Specialty, CKS, GWEB, GMOB, or equivalent certification.

Culture & Benefits

  • Remote-first work environment with a modern Manhattan office option.
  • Unlimited vacation and paid volunteer opportunities.
  • $4,000 technology stipend every two years and a $500 annual work-from-home stipend.
  • Monthly physical, mental, wellness, learning, and lifestyle stipends.
  • Medical, dental, vision, prescription, FSA, HRA, HSA, family coverage, retirement plans with immediate company matching, life insurance, and disability leave.
  • Company-paid parental leave of up to 20 weeks for birthing parents and 12 weeks for non-birthing parents, plus family-building benefits.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →