Назад
Company hidden
50 минут назад

DevSecOps and AI/Automation Engineer

149 100 - 215 925$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
DevSecOps and AI/Automation Engineer (Application Security): Strengthening secure software development and software supply chain security across enterprise applications, cloud services, and engineering platforms with an accent on automated security testing, CI/CD controls, and risk-based assessments. Focus on building reusable security integrations, conducting threat modeling and vulnerability analysis, and improving AI-assisted triage, remediation, and secure development metrics.

Location: San Jose, California, United States. Shift 1, United States of America.

Salary: $149,100–$215,925 USD annually for the Bay Area, California.

Company

hirify.global is a global semiconductor organization with enterprise applications, engineering platforms, cloud services, intellectual property systems, and customer-facing digital services.

What you will do

  • Define and maintain secure SDLC standards, security requirements, developer guidance, security gates, and risk-based release controls.
  • Implement and operate SAST, DAST, SCA, secrets detection, container scanning, API security, and infrastructure-as-code scanning across CI/CD pipelines.
  • Conduct threat modeling, architecture and code reviews, vulnerability analysis, application security assessments, and penetration-test coordination.
  • Secure Azure, AWS, hybrid, Kubernetes, serverless, container, API, and software supply chain environments.
  • Develop reusable integrations, scripts, dashboards, workflow automation, and AI-assisted vulnerability triage and remediation capabilities.
  • Partner with developers, architects, DevOps, cloud, infrastructure, product, and enterprise technology teams through training, workshops, and remediation guidance.

Requirements

  • 6+ years of experience in AppSec, DevSecOps, secure SDLC, cloud security, cybersecurity engineering, software security, or a related discipline.
  • Bachelor’s degree in computer science, cybersecurity, information technology, engineering, information systems, or a related technical field, or equivalent experience.
  • Hands-on experience with secure SDLC, application security, CI/CD, and at least three security capabilities such as SAST, DAST, SCA, secrets scanning, IaC scanning, container security, API security, threat modeling, or vulnerability management.
  • Experience with Azure, AWS, Kubernetes, or container-based application environments and with platforms such as Azure DevOps, GitHub, GitLab, Jenkins, Jira, or ServiceNow.
  • Ability to conduct or support application security assessments, translate security standards into technical controls, and communicate findings to technical and nontechnical stakeholders.
  • Applicants must be eligible for any required U.S. export authorizations.

Nice to have

  • Experience with application security tools such as Checkmarx, Fortify, Veracode, Semgrep, CodeQL, SonarQube, Snyk, Mend, or Black Duck.
  • Experience with Burp Suite, OWASP ZAP, Invicti, or comparable DAST and API security tools.
  • Knowledge of SBOM, SLSA, software provenance, artifact integrity, code signing, PKI, HSM, and dependency governance.
  • Familiarity with OWASP, NIST SSDF, BSIMM, CIS Controls, ISO/IEC 27001, or related frameworks.
  • Experience with AI-enabled cybersecurity, secure AI development, or AI-assisted security automation.

Culture & Benefits

  • Regular full-time employment with incentive opportunities based on individual and company performance.
  • Cross-functional collaboration across geographically distributed development, security, cloud, infrastructure, engineering, and product teams.
  • Opportunity to improve secure development maturity, developer enablement, automation, and software supply chain security.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →