Назад
Company hidden
4 дня назад

Application Security Engineer (AI)

Формат работы
remote
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK/Singapore/US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (AI): Building mission-critical application security infrastructure and secure software development practices for AI-powered intelligence products with an accent on threat modeling, secure code review, vulnerability management, and automated security testing. Focus on embedding security into CI/CD pipelines, coordinating penetration testing, developing security tools and training, and protecting sensitive data across cloud environments.

Location: Remote within the United States. The team operates across EST, PST, and CET time zones.

Company

hirify.global provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime, trace illicit activity, and understand threat networks.

What you will do

  • Lead application security reviews and threat modeling, including secure code reviews, architectural assessments, and testing.
  • Develop automated security testing and mature the Secure SDLC across engineering.
  • Own vulnerability management, including triage and remediation of software package and library vulnerabilities.
  • Coordinate penetration testing engagements and maintain the bug bounty program.
  • Build platform security initiatives to protect TRM data and support secure cloud infrastructure.
  • Develop application security best practices, secure code training, and security champion programs for engineering teams.

Requirements

  • Minimum 8 years of experience in software development and testing.
  • BS or equivalent degree in Computer Science, Computer Engineering, or a related field.
  • Proficiency with Python, Node, and React.
  • Strong knowledge of encryption, authentication, authorization, OWASP, CWE, and software security testing methodologies.
  • Experience with AWS or GCP, secure software development lifecycles, threat modeling, SAST, DAST, SCA, Burp Suite, OWASP ZAP, and threat modeling tools.
  • Experience with code security reviews, penetration testing or red teaming, agile software development, and strong written and verbal communication.

Nice to have

  • Security certifications such as OSCP, CEH, or GWAPT.
  • Familiarity with security frameworks such as NIST SP 800-171 and SSDF.

Culture & Benefits

  • Remote work with collaboration across EST, PST, and CET time zones.
  • A culture based on mutual respect, transparency, flexibility, and efficient execution.
  • High ownership, frequent cross-functional communication, and a focus on measurable impact.
  • Work on complex problems at the intersection of AI, national security, and fighting crime.
  • AI fluency is expected and evaluated during the interview process.

Hiring process

  • Recruiter introduction followed by a hiring manager discussion and first-round interviews.
  • Case study, AI skills assessment, and Leadership Principles interview may be included.
  • Final panel, references, offer, and onboarding.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →