Назад
Company hidden
3 дня назад

Manager - Application Security (AI)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Manager - Application Security (AI): Leading application security strategy and operations for applications, websites, APIs, services, and AI-enabled systems with an accent on threat modeling, secure development, and security automation. Focus on managing a distributed AppSec team, integrating controls across CI/CD and cloud-native environments, and addressing complex application risks through code reviews, architectural assessments, and penetration testing.

Location: Dallas, Texas, United States — headquarters

Company

hirify.global operates a global online vehicle auction platform connecting vehicle sellers with more than 750,000 buyers across over 190 countries.

What you will do

  • Define the application security strategy, roadmap, operating model, and team objectives.
  • Lead, hire, mentor, and develop a globally distributed application security team.
  • Partner with Development, DevOps, Architecture, Infrastructure, and other technology teams.
  • Lead security reviews and threat modeling for AI-enabled applications, agents, models, APIs, data integrations, and development pipelines.
  • Conduct code audits, architectural reviews, technical security assessments, penetration testing, and application-security automation.
  • Integrate application security controls, findings, workflows, and reporting throughout the software delivery lifecycle.

Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related discipline, or equivalent practical experience.
  • At least 5 years of progressive cybersecurity experience, including 3 or more years in application or product security.
  • At least 2 years of direct people-management experience.
  • Strong knowledge of the OWASP Top 10 and experience communicating security methodologies to development teams.
  • Experience with Java, Python, JavaScript, secure code review, threat modeling, architectural assessments, and penetration testing.
  • Experience implementing security automation across source control, CI/CD, cloud-native, and infrastructure-as-code environments.

Nice to have

  • OSCP, CSSLP, CISSP, GIAC, or cloud-security certification.
  • Experience with SAST, DAST, IAST, SCA, secrets detection, ASPM, API security, container security, WAF/CDN controls, and penetration-testing platforms.
  • Knowledge of threat-modeling methodologies such as STRIDE.

Culture & Benefits

  • Medical, dental, and vision coverage.
  • 401(k) plan with company match and employee stock purchase plan.
  • Vacation, sick pay, and paid company holidays.
  • Life and AD&D insurance, employee assistance program, and employee discounts.
  • Workplace focused on diversity, inclusion, collaboration, and professional growth.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →