Назад
Company hidden
15 часов назад

Application Security Engineer (AI)

150 000 - 300 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (AI): Securing backend services, APIs, mobile apps, third-party integrations, and agentic AI systems with an accent on vulnerability remediation, identity security, and LLM attack surfaces. Focus on threat-modeling prompt injection and data exfiltration, building high-signal security scanning in CI, and embedding secure defaults into the development lifecycle.

Location: San Jose, United States

Salary: $150,000–$300,000 annually

Company

hirify.global builds personalized multimodal intelligence and next-generation AI hardware that interact with people and the real world through speech, text, vision, and persistent memory.

What you will do

  • Threat-model new features and services, focusing on agent and LLM attack surfaces such as prompt injection, tool misuse, data exfiltration, and cross-tenant access.
  • Review backend services, APIs, and mobile applications, primarily written in Go, and remediate vulnerabilities directly.
  • Secure authentication, authorization, session handling, and OAuth integrations across the consumer product.
  • Build and tune SAST, dependency, and secrets scanning in CI to produce actionable findings.
  • Triage and remediate penetration-test and vulnerability-disclosure findings.
  • Partner with engineering on secure defaults, reusable libraries, and security practices integrated into the development lifecycle.

Requirements

  • 4–8 years of hands-on application or product security engineering experience.
  • Strong software engineering skills and the ability to ship production code; Go is strongly preferred, with Python, TypeScript, Swift, or Kotlin also valuable.
  • Deep knowledge of web and API vulnerabilities, including OWASP Top 10, SSRF, IDOR/BOLA, authorization flaws, and injection.
  • Hands-on experience with OAuth 2.0, OIDC, session management, and securing multi-tenant systems.
  • Experience with secure code review, threat modeling, and converting scanner or runtime findings into fixes using SAST/SCA, CNAPP, and SIEM tools.
  • Curiosity about LLM and agent security and willingness to develop practices in this emerging area.

Nice to have

  • Experience at a security-focused product company or offensive security consultancy.
  • Mobile application security experience on iOS or Android.
  • Experience with LLM or agent threat modeling, prompt-injection defenses, or AI red teaming.
  • Bug bounty, CVE, or open-source security contributions.

Culture & Benefits

  • Hands-on individual contributor role focused on reading code, writing fixes, and building security tooling rather than managing or auditing.
  • Opportunity to define security practices for agentic systems with few established playbooks.
  • Full-time position with a US base salary range of $150,000–$300,000 annually.
  • Total compensation may include additional components and benefits depending on the role.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →