Назад
Company hidden
5 дней назад

Senior Software Engineer (Application Security Engineering)

170 000 - 230 000$
Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Software Engineer (Application Security Engineering/AI): Building and operating a production AI vulnerability platform that discovers vulnerabilities, validates findings, and proposes tested fixes with an accent on agent orchestration, secure execution, and evidence-backed analysis. Focus on durable workflows, repository context, vulnerability validation, patch and regression-test automation, and reliable operation across a cloud platform and endpoint agents.

Location: Remote work is available only for candidates located in the USA and residing in CA, CO, CT, FL, GA, IL, KS, MA, MD, ME, NJ, NC, NY, OH, OR, TN, TX, VA, or WA. Hybrid work is available through offices in Austin, Texas, and Tampa, Florida. Onsite interviews may be required. hirify.global cannot hire for this role within the city limits of Chicago.

Base salary: $170,000–$230,000 per year for roles based in California, Colorado, Maryland, New Jersey, Washington, and New York.

Company

hirify.global provides a unified IT operations platform for endpoint management, autonomous patching, backup, and remote access.

What you will do

  • Build and operate an AI vulnerability platform with resumable workflows, bounded agent execution, model routing, and repository-level budgets.
  • Develop repository context, threat models, coverage tracking, and code-path analysis for entry points, trust boundaries, and tenant isolation.
  • Build independent finding validation, stable finding identity, deduplication, and evidence-based exploitability analysis.
  • Develop patch and regression-test workflows that verify fixes and require human review before merging.
  • Secure agent execution through sandboxing, least-privilege access, protection against prompt injection, and safe handling of secrets and sensitive data.
  • Partner with security and product engineering teams, deliver findings through SARIF, and measure quality, coverage, reliability, and cost.

Requirements

  • 5+ years of software engineering experience owning production services or automation platforms.
  • Hands-on experience building LLM-backed applications or agent workflows.
  • Strong Python skills, including asynchronous concurrency, typing, testing, packaging, and profiling.
  • Experience with durable workflows, idempotent retries, task queues, observability, termination conditions, and resource limits.
  • Experience with LLM APIs, tool calling, structured outputs, context management, evaluation, AWS or comparable cloud infrastructure, and distributed systems.
  • Working knowledge of application security, including authentication, authorization, vulnerability classes, and trust boundaries; a degree in computer science, information technology, or equivalent practical experience.

Nice to have

  • Experience in vulnerability discovery, static analysis, syntax trees, call graphs, code retrieval, threat modeling, or sandboxed proof-of-concept execution.
  • Experience in security triage, duplicate detection, benchmark design, ground-truth labeling, automated patching, or test infrastructure.
  • Experience with SARIF, SAST/SCA integrations, durable execution frameworks, LLM tracing and evaluation tools, or agent security.
  • Experience reading C or C++, security research, program repair, or open-source contributions.

Culture & Benefits

  • Full-time hybrid-remote work with flexibility.
  • Medical, dental, and vision insurance.
  • 401(k) plan and life insurance coverage.
  • Unlimited paid time off.
  • Opportunities for growth and advancement in a collaborative engineering community.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →