Назад
Company hidden
3 дня назад

Senior Application Security Engineer (Application Security)

172 000 - 200 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (Application Security): Building and operating application security scanning programs for a healthcare price transparency platform with an accent on SAST, DAST, dependency scanning, threat modeling, and secure software development. Focus on triaging vulnerabilities, guiding code-level remediation, coordinating penetration testing, and measuring security posture across US-based applications and data.

Location: Fully remote in the United States; US-based candidates only. Work follows US business hours. Current US work authorization is required; visa sponsorship is not available.

Salary: $172,000–$200,000 per year, plus equity.

Company

hirify.global is a Series C healthcare price transparency platform that provides infrastructure for a more open and efficient healthcare marketplace and serves more than 300 enterprise organizations.

What you will do

  • Build and operate application security scanning across SAST, DAST, dependency/SCA, container, and infrastructure-as-code tools.
  • Triage findings from scans, penetration tests, and bug bounty reports, prioritizing risk and tracking remediation to closure.
  • Partner with engineering teams on vulnerability remediation, debugging, architecture reviews, and secure coding.
  • Drive threat modeling, secure development practices, and security integration throughout CI/CD pipelines.
  • Support application-layer incident response and coordinate third-party penetration tests.
  • Track security posture metrics, including open vulnerabilities, remediation SLAs, and scan coverage.

Requirements

  • 5+ years of experience in application security, security engineering, or security-focused software engineering.
  • Hands-on experience with SAST, DAST, and dependency/SCA scanning, including distinguishing real risk from noise.
  • Strong knowledge of OWASP Top 10, authentication and authorization flaws, injection, SSRF, code review, and secure architecture.
  • Experience securing cloud environments, preferably AWS, and modern CI/CD pipelines.
  • Strong communication skills and a collaborative, pragmatic approach to balancing security with delivery speed.
  • Current authorization to work in the United States; US-based location and US business-hours availability required.

Nice to have

  • Experience in healthcare, fintech, or another regulated industry.
  • Experience with HIPAA, SOC 2, or GDPR compliance frameworks.
  • OSCP, GWAPT, CSSLP, or another security certification.
  • Experience building or maturing an application security program from an early stage.
  • Scripting or automation with Python, Go, Terraform, or similar infrastructure-as-code tools, plus red team experience.

Culture & Benefits

  • Fully remote work with flexible working hours.
  • Equity options and competitive compensation.
  • Medical, dental, vision, FSA, DCFSA, and HSA options.
  • Unlimited PTO, paid family leave, disability and life insurance, and a 401(k) with 4% matching.
  • $750 home-office setup budget, $1,200 annual learning and development stipend, and health and wellness benefits.
  • Paid biannual company summits and quarterly coworking meetups.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →