Назад
Company hidden
6 дней назад

Sr. Security Engineer (Application Security)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Sr. Security Engineer (Application Security/AI): Securing SaaS products through architecture reviews, white-box penetration testing, SSDLC maturity, and CI/CD security automation with an accent on AWS, web application vulnerabilities, and emerging AI attack surfaces. Focus on designing practical risk-based controls, securing agentic systems and LLM-powered workflows, and building security partnerships across engineering, product, legal, and leadership.

Location: Hybrid role based in Salt Lake City, Utah, United States; employees may work remotely, from an office, or through a combination depending on role and team needs.

Company

hirify.global develops AI-driven work acceleration products, including Lucidchart, Lucidspark, and airfocus, for visual collaboration and organizational transformation.

What you will do

  • Conduct security architecture, product design, and feature reviews to identify risks early and recommend practical mitigations.
  • Partner with engineering and product teams throughout the software development lifecycle as an application security subject matter expert.
  • Mature the Secure Software Development Lifecycle through secure coding standards, security requirements, developer education, and security champions.
  • Develop scalable security tooling and automate security controls in CI/CD pipelines with a focus on reducing risk.
  • Assess AI tools, agentic systems, MCP, and LLM-powered workflows against emerging security threats.
  • Mentor engineers and communicate security risks in practical business terms to technical and leadership stakeholders.

Requirements

  • 5+ years of combined experience in software engineering, application security, product security, or a related field in a SaaS environment.
  • Experience securing web applications using modern frameworks and cloud-native architectures, particularly AWS.
  • White-box penetration testing experience and strong knowledge of OWASP Top 10, API security, authentication, and authorization vulnerabilities.
  • Strong understanding of SSDLC principles and experience implementing or maturing secure development programs.
  • Experience integrating security tooling into modern CI/CD pipelines and conducting meaningful security architecture reviews.
  • Strong written and verbal communication skills, with the ability to build trusted relationships across engineering, product, legal, and leadership teams.

Nice to have

  • Development experience with modern technology stacks.
  • Knowledge of OWASP ASVS, NIST 800-53, SOC 2, or GDPR.
  • Hands-on security certifications such as OSCP, BSCP, GWEB, or PNPT.
  • Bug bounty program management experience.
  • Bachelor’s degree in Computer Science, Information Security, or a related field.

Culture & Benefits

  • Hybrid workplace with remote and office-based work options depending on role and team needs.
  • Focus on work-life balance, individual empowerment, initiative, ownership, and teamwork.
  • Inclusive environment that values diverse perspectives and respectful collaboration.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →