Назад
Company hidden
3 дня назад

Senior Security Engineer - Product (AI)

149 500 - 224 500$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer - Product (AI): Securing a multi-tenant investment management platform through security reviews, vulnerability remediation, secure-by-default systems, and AI-driven security automation with an accent on authentication, authorization, tenant isolation, and sensitive financial data. Focus on building LLM- and agent-based security pipelines, evaluating prompt injection and data leakage risks, and creating reliable feedback loops for automated security decisions.

Location: Reno, Nevada or San Ramon, California, United States

Salary: $149,500–$224,500 per year

Company

hirify.global builds cloud-native investment management technology for investment firms, with a strategic focus on AI adoption.

What you will do

  • Perform security code reviews and hands-on testing focused on authentication, authorization, tenant isolation, and sensitive financial data.
  • Own the product vulnerability lifecycle, including triage, impact assessment, penetration-test validation, and remediation.
  • Build secure-by-default libraries, frameworks, guardrails, and automated systems for product engineering teams.
  • Design and operate LLM- and agent-based pipelines for security reviews, threat modeling, vulnerability triage, and remediation.
  • Assess AI-powered product features for prompt injection, data leakage, model misuse, and tool misuse risks.
  • Mentor engineers, lead secure-coding education, and translate emerging threats into product improvements.

Requirements

  • 5+ years of experience in product security, application security, or software engineering.
  • Bachelor’s degree in Computer Science or a related field, or equivalent practical experience.
  • Proficiency in one or more of Kotlin, Java, TypeScript, Python, or Go.
  • Hands-on experience with threat modeling, security design reviews, manual security testing, and code review for web applications, APIs, and distributed services.
  • Strong knowledge of OAuth 2.0, OIDC, SAML, RBAC/ABAC, OWASP vulnerabilities, and practical mitigation strategies.
  • Experience building production automation with LLMs or agents, including prompt and tool design, evaluation, and failure-mode handling.

Nice to have

  • Experience securing multi-tenant SaaS platforms in financial services or another regulated industry.
  • Familiarity with AWS, including IAM, container services, and Lambda.
  • Experience with bug bounty programs, third-party penetration-test findings, agent frameworks, retrieval pipelines, or LLM evaluation tooling.
  • Security research, CVEs, bug bounty participation, open-source contributions, or community involvement.

Culture & Benefits

  • Employee position with opportunities for career advancement and product impact.
  • Company stock plan, subject to the applicable agreement.
  • Unlimited vacation and educational and wellness reimbursements.
  • $0-cost employee insurance plans.
  • Collaborative environment focused on learning, teaching, and trust.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →