Назад
Company hidden
7 дней назад

Staff Security Engineer, Detection & Response (AI)

221 000 - 299 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Security Engineer, Detection & Response (AI): Owns incident detection and response, threat modeling, SDLC hardening, and detection engineering for a virtual healthcare platform with an accent on application security, SIEM ownership, and AI risk management. Focus on leading hands-on investigations, finding systemic weaknesses in production code and development workflows, tuning AI-assisted detection, and securing LLM-powered systems against prompt injection and agentic tool abuse.

Location: Remote within the US through hub cities, including New York, San Francisco/Bay Area, Seattle, Boston, Washington, DC, and Chicago. New York City employees must work onsite three days per week; employees in Boston, DC, Chicago, Seattle, and San Francisco must attend monthly Work Together Days.

Salary: $221,000–$299,000 per year, plus equity and benefits.

Company

hirify.global is a virtual healthcare platform providing women’s and family health programs through employer, health plan, and consumer services.

What you will do

  • Own the incident detection and response program and lead hands-on investigations, including log analysis, incident reconstruction, and recommendations for business and engineering leaders.
  • Threat-model systems and codebases, assess attack surfaces, trust boundaries, and data flows, and identify exploitable weaknesses.
  • Hunt for bugs and SDLC control gaps, implement fixes, and coordinate broader remediation with engineering and product security teams.
  • Own and tune detection logic through 7AI, validate investigations and escalations, define alert criteria, and improve logging and visibility.
  • Assess and manage security risks in internally adopted and externally developed LLM, AI-generated code, and agentic systems.

Requirements

  • 6+ years of security experience combining hands-on software or application security with detection and SIEM engineering ownership.
  • Ability to read production code across multiple languages and stacks and determine whether findings are exploitable.
  • Experience building threat models and reasoning about attack surfaces, trust boundaries, and data flows.
  • Track record of finding and fixing systemic weaknesses through incident response or proactive review.
  • Strong communication skills and the ability to direct investigations and influence peers.
  • Must be based in the US hub-city network and meet the applicable onsite or monthly in-person attendance requirements.

Nice to have

  • Experience with AI-assisted security operations, LLM-based triage, or agentic escalation systems.
  • Experience securing AI and LLM-powered systems against prompt injection, model misuse, or agentic tool abuse.
  • Exposure to secure-by-default infrastructure, golden paths, container or image security, and patching lifecycles.
  • Certifications such as GCIH, GCFA, GCDA, OSCP, or CISSP.

Culture & Benefits

  • Flexible hybrid work model with remote work through US hub cities and structured in-person collaboration.
  • Employer-covered health, dental, and insurance plan options.
  • Access to Maven healthcare services, including mental health, reproductive health, family planning, and pediatrics.
  • Wellness partnerships, in-office meals, and Work Together Days.
  • 16 weeks of fully paid parental leave and a new parent stipend after one year of employment.
  • Annual professional development stipend, career coaching, equity, and 401(k) matching for US-based employees.

Hiring process

  • Submit an application describing relevant security experience and transferable background.
  • Interview requests and offers are sent only from an official @mavenclinic.com email address.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →