Назад
Company hidden
1 день назад

Staff Application Security Engineer

182 800 - 215 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Application Security Engineer (SIEM/Vulnerability Management): Building and operating application security programs, vulnerability management pipelines, and enterprise security tooling for an AI-native travel platform with an accent on threat detection, secure coding, and cloud-native infrastructure. Focus on analyzing complex vulnerabilities, performing security reviews and testing, leading incident response and forensic investigations, and strengthening security practices across engineering teams.

Location: Remote - US

Base pay range: $182,800–$215,000 USD annually

Company

hirify.global is an AI-native travel platform providing proprietary technology and infrastructure for business travel, group travel, human agents, and AI agents.

What you will do

  • Own the configuration, tuning, and management of the SIEM solution, including threat analysis and alert development.
  • Perform architecture, code, and infrastructure configuration reviews, along with light penetration testing for web and mobile applications.
  • Build and optimize vulnerability management pipelines within container and application delivery infrastructure.
  • Partner with development and infrastructure teams to promote secure coding practices and remediation strategies.
  • Build and maintain enterprise security frameworks and tooling, and contribute to incident response and forensic investigations.
  • Provide security guidance and training while helping hirify.globalering teams improve their overall security posture.

Requirements

  • Strong proficiency in one or more programming languages, such as Ruby, Java, Python, C#, or Node.
  • Expertise managing SIEM solutions and developing efficient, low-noise alerting.
  • Strong knowledge of Docker and Kubernetes, including automated container vulnerability management.
  • Experience with SAST, DAST, and IAST tools, plus manual validation testing.
  • Deep knowledge of the OWASP Top 10, MITRE Top 25, and secure coding practices.
  • Experience with cloud security concepts and compliance frameworks such as SOC 2 and PCI.

Culture & Benefits

  • Full-time employment with equity for all employees.
  • Some roles may include annual bonuses or commissions.
  • Hybrid-hub model supporting both office-based and fully remote work environments.
  • Benefits vary based on employment type, location, and other factors.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →