Назад
Company hidden
3 дня назад

Product Security Engineer (AI)

231 900 - 318 250$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product Security Engineer (AI): Building security tooling, automation, and code-level controls for a platform that handles sensitive customer data and executes arbitrary code, with an accent on application security, secure code review, threat modeling, and AI-assisted development. Focus on designing static analysis rules, finding systemic vulnerabilities, driving durable remediation, and adapting security practices to higher-volume AI-generated code.

Location: San Francisco, United States; hybrid work location

Base salary: $231,900–$318,250 per year. Additional compensation may include equity and benefits.

Company

hirify.global builds a platform for creating, deploying, and governing internal software connected to business data, with enterprise policies and reusable components.

What you will do

  • Identify systemic security gaps in the codebase and engineering workflows, then design and ship durable solutions with engineering teams.
  • Build security tooling, automation, custom linters, static analysis rules, and automated checks for vulnerability classes.
  • Conduct in-depth code reviews and security design reviews for major product initiatives.
  • Lead threat modeling and security assessments, translating requirements into practical engineering guidance.
  • Adapt application security practices to AI-assisted development and higher-volume code production.
  • Triage and drive vulnerability remediation while contributing to penetration testing and bug bounty programs.

Requirements

  • 5+ years of hands-on application security and security engineering experience.
  • Experience shipping security tooling or automation used by multiple teams.
  • Ability to read, reason about, and review code deeply enough to identify root causes and real vulnerabilities.
  • Strong application security fundamentals, including threat modeling, secure code review, and durable remediation of common vulnerability classes.
  • Productive working knowledge of TypeScript and Python.
  • Independent judgment, effective communication with engineers, and a pragmatic approach to AI security tooling.

Nice to have

  • Offensive security experience in bug bounty, CTFs, red teaming, or penetration testing.
  • Experience with SAST pipelines, custom static analysis rules, or automated security testing infrastructure.
  • Experience at a startup or high-growth scaleup.

Culture & Benefits

  • Hybrid work location.
  • Medical, dental, and vision coverage.
  • 401(k) plan.
  • Additional equity may be included depending on the position offered.
  • hirify.global is currently set up to employ all roles in the US and specific roles in the UK.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →