Назад
Company hidden
4 дня назад

Application Security Engineer (AI)

4 000 - 6 000€
Формат работы
remote (Global)
Тип работы
fulltime
Грейд
senior
Английский
b2
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (AI): Securing application and product systems across design reviews, CI/CD controls, cloud infrastructure, and vulnerability management with an accent on multitenant B2B SaaS, AWS, Kubernetes, and AI-powered features. Focus on threat modelling, secure code and architecture reviews, tenant isolation, DevSecOps controls, and mitigating prompt injection, data leakage, and untrusted model output.

Location: Fully remote

Salary: €4,000–€6,000 gross per month

Company

hirify.global develops digital learning products focused on measurable student success.

What you will do

  • Own application and product security from design reviews and threat modelling through vulnerability remediation and follow-up.
  • Embed security into the software development lifecycle and build CI/CD controls for SAST, dependency, secrets, container, and IaC scanning.
  • Review application architecture and production code, converting recurring findings into secure defaults, shared libraries, lint rules, and CI gates.
  • Manage application and cloud vulnerabilities through risk-based triage, prioritisation, remediation timelines, and external penetration-test findings.
  • Strengthen security for multitenant B2B systems, AWS environments, and Kubernetes workloads, including tenant isolation, IAM, authentication, authorization, secrets, and network boundaries.
  • Translate GDPR, SOC 2, and ISO 27001 requirements into engineering controls, support the security champions programme, and address risks in AI and LLM-powered features.

Requirements

  • 5+ years of engineering experience, including at least 2 years in Application Security or Product Security.
  • Strong software engineering background with the ability to read, review, and write production code; Python experience is highly preferred.
  • Practical expertise in web application security, OWASP Top 10, ASVS, authentication, session management, OAuth2, OIDC, SAML, IDOR, and broken access control.
  • Experience securing multitenant or B2B SaaS products, including tenant isolation, RBAC, ABAC, and access-control models.
  • Hands-on experience with CI/CD security, threat modelling, secure design reviews, secure code reviews, vulnerability prioritisation, AWS security, and Kubernetes security.
  • Fluent Russian and English at B2 level or above are required.

Nice to have

  • Experience building a DevSecOps practice or running a Security Champions programme.
  • Hands-on penetration testing experience.
  • Experience securing LLM-powered or AI products.
  • Experience with SOC 2 or ISO 27001 from an engineering perspective.
  • Knowledge of software supply chain security, including SBOMs, SLSA, and image signing.

Culture & Benefits

  • Supportive and proactive work environment.
  • Fully remote, full-time collaboration.
  • Modern digital tools for seamless collaboration.
  • Results measured through student success.
  • Competitive gross monthly compensation.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →